Bengaluru, India · he/him

ClintJosy

AI Security Researcher & Leader

Hi, I am Clint. I work on AI and security, usually both at the same time. I break things with permission, help fix them, and write about what I learn along the way.

name
Clint Josy
role
AI security researcher, leader
location
Bengaluru, India
focus
offensive security, exposure management, AI-driven defense

Pushing AI further. Engineering security differently.

Portrait of Clint Josy

01 About

Attacker's view, defender's job

OSCP · CRTO · CHFI · C-AI/MLPen · SC-200

I have spent the last several years getting into systems with permission, then helping the people who own them fix what I found. These days most of my attention goes to AI: how it can make security teams faster, and how it opens up new ways for things to go wrong.

I like clear answers. A lot of security work is noise, so I try to work out what actually matters, explain it plainly, and get it fixed. That is most of the job.

Outside of work I am usually tinkering with a homelab, reading papers I only half understand, or writing up something I learned the hard way.

background
authorized offensive security, then remediation with the owners
current focus
AI for security teams, and the security of AI systems
approach
identify what matters, explain it plainly, get it fixed
scope
applications, infrastructure, cloud, APIs, models

02 Focus

What I work on

offensive security
  • Red team operations
  • Web, API and cloud assessments
  • Active Directory security
  • Social engineering awareness
  • Vulnerability research
ai security
  • AI and ML penetration testing
  • LLM security
  • AI risk management (NIST AI RMF)
  • AI-assisted detection
exposure management
  • Attack-surface mapping
  • Threat modelling
  • Cyber threat intelligence
  • Risk prioritization
  • Digital forensics
platforms
  • Microsoft Azure and Entra ID
  • Proxmox and self-hosted LLMs
  • Linux, Docker, NVIDIA
  • Python, Bash, TypeScript

03 Selected work

Research, disclosures, and builds

A few things I have published or built that show how I think.

research

A forgotten certificate authority

A look at how one overlooked certificate authority quietly undermined a Zero Trust setup in Active Directory. The fix is less about new tools and more about looking at the right things.

Active Directory; ungoverned certificate authority; Zero Trust blind spot; defender priorities

Active DirectoryZero Trust
disclosure

CVE-2019-8920: XAMPP 1.7.0 reflected XSS

A reflected cross-site scripting bug I found in XAMPP 1.7.0 and reported. It got CVE-2019-8920 and a CVSS score of 6.1. Small bug, good lesson in doing disclosure properly.

Reflected XSS; XAMPP 1.7.0; CVE-2019-8920; CVSS 6.1 Medium; NVD listed

CVEWeb security
build

Local LLM with GPU acceleration on Proxmox

How I got a local model from 3 tokens per second to 21 on a modest GPU inside a Proxmox container, with every wrong turn included so you can skip them.

Proxmox LXC; NVIDIA passthrough; MoE model; 3 tok/s to 21 tok/s; full guide

LLMProxmoxSelf-hosted
write-up

OpenMythos teardown

I read the OpenMythos code so you do not have to: the architecture, the training pipeline, and what a locally runnable reasoning model means for people who do security.

Recurrent-depth transformer; architecture + training pipeline; security implications of local reasoning models

Deep learningAI security

04 Experience

Where I have worked

  1. Jul 2023 to Aug 2026 · Bengaluru, India

    Offensive Security Lead, Security Strategist

    Cyderes

    Led the offensive security practice and ran exposure-management engagements for enterprise clients. Worked with the Howler Cell research team on identity and cloud access research, some of which is linked below.

    Lead offensive security practice; exposure management engagements; Howler Cell research (identity, cloud access)

  2. Feb 2021 to Jul 2023 · Kuala Lumpur, Malaysia (remote)

    Senior Security Engineer

    Axiata

    Security engineering for a telecom group operating across several countries. Mostly application security, web architecture reviews, and data privacy work, all of it remote.

    Application security; web architecture review; data privacy; telecom group, multi-country

  3. Sep 2018 to Jan 2021 · New Delhi, India

    Security Analyst

    Safe Security

    Started as an intern and stayed on as an analyst. Network and application testing, vulnerability research, and the early days of cyber risk quantification.

    Intern then analyst; network and application testing; vulnerability research; cyber risk quantification

05 Credentials

Certifications

The full list is on LinkedIn.

2019Offensive Security Certified Professional (OSCP)OffSec
2020Certified Red Team Operator (CRTO)Zero-Point Security
2025Computer Hacking Forensic Investigator (CHFI)EC-Council
2025Certified AI/ML Pentester (C-AI/MLPen)The SecOps Group
2025Security Operations Analyst Associate (SC-200)Microsoft
2025Foundations of AI SecurityAttackIQ
2023Certified AppSec Practitioner (CAP)The SecOps Group
2023Certified Network Security Practitioner (CNSP)The SecOps Group
2022Azure Fundamentals (AZ-900)Microsoft
2020Social Engineering ExpertRedTeam Security Training

06 Writing

Recent posts

All posts4

07 Contact

Get in touch

Working on something at the edge of AI and security?

If you want to talk about AI security, research, or something you are building, I would like to hear from you. LinkedIn is the fastest way to reach me.

topics
AI security, research, collaboration
channel
LinkedIn
also
dev.to, GitHub