# Clint Josy AI Security Researcher & Leader. AI-driven security · offensive security · exposure management. Pushing AI further. Engineering security differently. ## Profile - name: Clint Josy - role: AI security researcher, leader - location: Bengaluru, India - focus: offensive security, exposure management, AI-driven defense ## About - background: authorized offensive security, then remediation with the owners - current focus: AI for security teams, and the security of AI systems - approach: identify what matters, explain it plainly, get it fixed - scope: applications, infrastructure, cloud, APIs, models ## Focus - offensive security: Red team operations, Web, API and cloud assessments, Active Directory security, Social engineering awareness, Vulnerability research - ai security: AI and ML penetration testing, LLM security, AI risk management (NIST AI RMF), AI-assisted detection - exposure management: Attack-surface mapping, Threat modelling, Cyber threat intelligence, Risk prioritization, Digital forensics - platforms: Microsoft Azure and Entra ID, Proxmox and self-hosted LLMs, Linux, Docker, NVIDIA, Python, Bash, TypeScript ## Selected work - [One Password, No Device, Full Tenant](https://www.cyderes.com/howler-cell/azure-ad-conditional-access-device-identity-abuse) (research): Entra ID Conditional Access; device identity trust assumptions; hardening guidance - [A forgotten certificate authority](https://www.linkedin.com/feed/update/urn:li:activity:7476270373144182785/) (research): Active Directory; ungoverned certificate authority; Zero Trust blind spot; defender priorities - [CVE-2019-8920: XAMPP 1.7.0 reflected XSS](https://medium.com/@0xm4rv/exploit-title-xampp-1-7-0-reflected-cross-site-scripting-782ddb02d312) (disclosure): Reflected XSS; XAMPP 1.7.0; CVE-2019-8920; CVSS 6.1 Medium; NVD listed - [nvd entry](https://nvd.nist.gov/vuln/detail/cve-2019-8920) - [Local LLM with GPU acceleration on Proxmox](https://clintjosy.pages.dev/blog/2026-05-01-your-ai-your-rules-running-a-local-llm-with-gpu-acceleration-on-proxmox) (build): Proxmox LXC; NVIDIA passthrough; MoE model; 3 tok/s to 21 tok/s; full guide - [OpenMythos teardown](https://clintjosy.pages.dev/blog/2026-04-23-openmythos-teardown-dissecting-the-open-source-reconstruction-of-claude-mythos) (write-up): Recurrent-depth transformer; architecture + training pipeline; security implications of local reasoning models ## Experience - Jul 2023 to Aug 2026: Offensive Security Lead, Security Strategist, Cyderes, Bengaluru, India. Lead offensive security practice; exposure management engagements; Howler Cell research (identity, cloud access) - Feb 2021 to Jul 2023: Senior Security Engineer, Axiata, Kuala Lumpur, Malaysia (remote). Application security; web architecture review; data privacy; telecom group, multi-country - Sep 2018 to Jan 2021: Security Analyst, Safe Security, New Delhi, India. Intern then analyst; network and application testing; vulnerability research; cyber risk quantification ## Certifications - 2019: Offensive Security Certified Professional (OSCP) (OffSec) - 2020: Certified Red Team Operator (CRTO) (Zero-Point Security) - 2025: Computer Hacking Forensic Investigator (CHFI) (EC-Council) - 2025: Certified AI/ML Pentester (C-AI/MLPen) (The SecOps Group) - 2025: Security Operations Analyst Associate (SC-200) (Microsoft) - 2025: Foundations of AI Security (AttackIQ) - 2023: Certified AppSec Practitioner (CAP) (The SecOps Group) - 2023: Certified Network Security Practitioner (CNSP) (The SecOps Group) - 2022: Azure Fundamentals (AZ-900) (Microsoft) - 2020: Social Engineering Expert (RedTeam Security Training) ## Writing - 2026-05-01: [Your AI, Your Rules: Running a Local LLM with GPU Acceleration on Proxmox](https://clintjosy.pages.dev/blog/2026-05-01-your-ai-your-rules-running-a-local-llm-with-gpu-acceleration-on-proxmox) - 2026-04-23: [OpenMythos Teardown: Dissecting the Open-Source Reconstruction of Claude Mythos](https://clintjosy.pages.dev/blog/2026-04-23-openmythos-teardown-dissecting-the-open-source-reconstruction-of-claude-mythos) ## Contact - topics: AI security, research, collaboration - channel: LinkedIn - also: dev.to, GitHub - [LinkedIn](https://www.linkedin.com/in/clintjosy/) - [dev.to](https://dev.to/clintjosy) - [GitHub](https://github.com/m4rvxpn)