Currently building Flowtriq En train de construire FlowTriq

I build, break,
and scale critical
systems.

Je construis, teste
et fais grandir les
systèmes critiques.

Cybersecurity and operations practitioner building, securing, and scaling production platforms. I work at the intersection of security, infrastructure, and execution. Most people only pick one.

Praticien en cybersécurité et opérations qui construit, sécurise et fait grandir les plateformes de production. Je travaille à l'intersection de la sécurité, l'infrastructure et l'exécution. La plupart des gens n'en choisissent qu'un.

jacob@operator ~
$ whoami --verbose
role: Founder · Consultant
focus: Security + Infrastructure + Ops
cves: 6 discovered
shipped: 4 products, 1 acquired
certs: eCPPT, PenTest+, CySA+, ITIL
building: flowtriq.com
$
What I do Ce que je fais

Four things, done at a high level.

Quatre disciplines, maîtrisées à haut niveau.

🛡

Break & Secure Systems

Tester et sécuriser

Offensive and defensive security. Penetration testing, vulnerability research, and infrastructure hardening. I've found CVEs in production systems and helped Fortune 500 companies patch before attackers found them.

Sécurité offensive et défensive. Tests de pénétration, recherche de vulnérabilités et renforcement d'infrastructure. J'ai découvert des CVE dans des systèmes en production.

Security Research · Pentesting · CVE Discovery

Build & Ship Products

Construire et livrer

From zero-to-one product builds to scaling existing platforms. I write code, design architecture, and lead teams through the messy middle of getting real products to market.

Du concept au produit fini. J'écris du code, conçois l'architecture et dirige les équipes pour mettre de vrais produits sur le marché.

Full-Stack · SaaS · Product Engineering

Operate & Scale Platforms

Opérer et faire grandir

Operations leadership, delivery management, and compliance. I've directed teams of 15+, managed SOC 2 audits, owned platform reliability at millions of requests/day, and made sure things ship.

Leadership opérationnel, gestion de livraison et conformité. J'ai dirigé des équipes de 15+, géré des audits SOC 2 et assuré la fiabilité de plateformes traitant des millions de requêtes par jour.

Operations Leadership · SOC 2 · Delivery · Compliance
🚀

Run Go-To-Market Systems

Piloter le go-to-market

The customer-facing side of getting products adopted, not just shipped. I build and run go-to-market systems, outbound infrastructure, product demos, and customer onboarding across international markets.

Le côté client de l'adoption des produits, pas seulement leur livraison. Je construis et pilote des systèmes go-to-market, infrastructure d'outbound, démos produit et onboarding client sur les marchés internationaux.

GTM · Outbound · Demos · Onboarding
Work with me Travailler avec moi

Consulting services for startups.

Services de conseil pour startups.

Canada-based, remote-friendly. Get secure, get compliant, and prove it to your customers and partners.

Basé au Canada, à distance. Sécurisez, mettez-vous en conformité et prouvez-le à vos clients et partenaires.

All services → Tous les services →
How I work Mon approche

Security-first. Execution-obsessed.

Sécurité d'abord. Obsession de l'exécution.

01

Understand the risk

Comprendre le risque

I start by mapping what actually matters. Not every system needs the same level of protection. I figure out where the real exposure is and what would actually hurt if it went wrong.

Je commence par identifier ce qui compte vraiment. Chaque système n'a pas besoin du même niveau de protection. Je détermine où se trouve l'exposition réelle.

02

Build the right thing

Construire la bonne chose

Architecture comes before code. I design systems that are secure by default, not bolted on after the fact. Security decisions get made at the design phase, not during the incident.

L'architecture passe avant le code. Je conçois des systèmes sécurisés par défaut. Les décisions de sécurité se prennent à la conception, pas pendant l'incident.

03

Ship with controls

Livrer avec des contrôles

Every delivery has guardrails. PR reviews, audit trails, compliance checks. I've built 5-layer approval flows and SOC 2 controls that don't slow teams down.

Chaque livraison a ses garde-fous. Revues de PR, pistes d'audit, contrôles de conformité. J'ai construit des flux d'approbation et des contrôles SOC 2 qui ne ralentissent pas les équipes.

04

Verify everything

Tout vérifier

Audit what you built. Pentest what you shipped. I run security audits across 60+ assets and don't sign off until the findings report is clean.

Auditer ce que vous avez construit. Tester ce que vous avez livré. Je lance des audits de sécurité sur plus de 60 actifs et ne signe pas avant que le rapport soit propre.

Tools and technologies I use daily

Outils et technologies que j'utilise au quotidien

AWS Azure Cloudflare Google Cloud DigitalOcean Linux Python PHP JavaScript Bash Docker Git / GitHub Burp Suite Nmap Metasploit Wireshark Nessus JIRA / Agile NIST / SOC 2 ITIL
Track Record Parcours

Not theory. Receipts.

Pas de théorie. Des preuves.

I don't talk about what I could do. Here's what I've actually done. The roles, the outcomes, and the things that shipped.

Je ne parle pas de ce que je pourrais faire. Voici ce que j'ai réellement accompli.

7 Vulnerabilities Discovered Vulnérabilités découvertes
1 Product Acquired Produit acquis
11 Industry Certs Certifications
4+ Products Shipped Produits livrés
Apr 2022 - Present
traztech
Principal

Principal

Security consulting for tech startups: SOC 2 and ISO 27001 readiness, compliance strategy, and infrastructure hardening across cross-border environments.

  • Led end-to-end SOC 2 and ISO 27001 readiness engagements for startups, SMBs, and complex industries including medtech and data centre operators
  • Advise clients on compliance strategy, control design, and remediation planning across SOC 2, ISO 27001, and NIST CSF
  • Built a compliance workspace platform (evidence register, risk register, policy management, remediation tracking) with pre-loaded SOC 2, ISO 27001, and ISO 42001 frameworks
  • Developed and launched AttackEngine, an anti-DDoS SaaS with real-time attack detection and multi-channel alerting. Acquired within one year of launch
  • Built and scaled a cloud server hosting initiative to $13,000 MRR in one quarter
Mar 2026 - Present
Flowtriq
Founder

Founder

Flowtriq runs directly on your servers, detects DDoS attacks in under a second, and automatically deploys BGP FlowSpec rules, RTBH blackholes, and cloud scrubbing to stop them. Full PCAP evidence and instant alerts on Slack, Discord, or PagerDuty.

  • Sub-second DDoS detection with automated BGP FlowSpec and RTBH mitigation
  • On-server deployment with cloud scrubbing failover and full PCAP evidence capture
  • Multi-channel alerting across Slack, Discord, and PagerDuty
June 2025 - Apr 2026
Humera, Inc
Leadership

Head of Technical Operations / Technical Project Manager

Running operations for a security startup building passive human-verification and anti-bot detection systems. Owning delivery, reliability, and compliance across distributed engineering teams.

  • Directed a team of 15 across technical execution of traffic scoring pipelines and abuse classification
  • Secured and managed $200K+ in cloud infrastructure partnerships across Google, AWS, Microsoft, DigitalOcean, and Cloudflare
  • Owned platform components processing millions of requests/day at 99.9% uptime and sub-100ms latency
  • Established SOC 2 Type II compliance across 76 controls with a 5-layer GitHub PR approval flow
  • Executed a company-wide security audit across 60+ assets including domains, servers, and API keys
2021 - 2025
Lorikeet Security

Technical Consultant / Lead AppSec Engineer / Full Stack Developer

Grew from intern to executive technical advisor across four years on a live cybersecurity training platform serving 5,000+ users.

  • Led application security across the full SDLC: vulnerability triage, remediation, and secure architecture
  • Identified and remediated 20+ vulnerabilities through static/dynamic analysis and pentesting
  • Designed and deployed intentionally vulnerable CTF environments including XXE, IDOR, and cryptography labs
  • Supported 3+ live CTF events as the technical safety net, scaling infrastructure for traffic spikes in real time
Rift Hosting

Technical Support Specialist

Resolved technical issues across Windows and Linux VPS environments covering networking, configuration, and performance.

Freelance

Freelance Software Developer

Delivered end-to-end full-stack development and security testing for clients as an independent contractor. This is where it all started.

  • Built full-stack web applications using Python, PHP, and JavaScript
  • Conducted penetration testing to identify and remediate client vulnerabilities
  • Managed projects end-to-end from scoping through delivery
Case Study
Étude de cas
From Zero to SOC 2 Type II at Humera
De zéro à SOC 2 Type II chez Humera
76 controls, 5-layer PR approval, 60+ asset audit. How I built compliance at a security startup.
76 contrôles, approbation PR en 5 couches, audit de 60+ actifs. Comment j'ai construit la conformité.
Security Research Recherche en sécurité

Vulnerabilities I've found in the wild.

Vulnérabilités que j'ai découvertes.

Real CVEs published under my name. Real systems secured before real attackers got there.

De vraies CVE publiées sous mon nom. De vrais systèmes sécurisés avant que les attaquants n'arrivent.

CVE-2024-45163 Remote unauthenticated DoS in Mirai botnet C&C infrastructure, enabling law enforcement to disable malicious hosts Critical
CVE-2024-44809 Remote code execution vulnerability in Raspberry Pi configuration service High
CVE-2024-44808 Privilege escalation via improper access control in embedded systems High
CVE-2024-48396 Information disclosure through insecure API endpoint configuration Medium
CVE-2026-42626 Denial of service vulnerability in HP ENVY 5000 series printer firmware Medium
Roblox Vulnerability disclosed and patched through responsible disclosure program Medium
Fortune 500 Confidential vulnerability discovery, disclosed under NDA High
Full advisories → Avis complets →
Live Product Produit en ligne

Flowtriq

A shipped product, live at flowtriq.com. Everything I've learned about security, infrastructure, and operations, built from the ground up and running in production.

Un produit lancé, en ligne sur flowtriq.com. Tout ce que j'ai appris en sécurité, infrastructure et opérations, construit de zéro et en production.

flowtriq.com →
What I brought to it
Ce que j'y ai apporté
  • Production security experience
  • Expérience en sécurité de production
  • SOC 2 and compliance architecture from day one
  • Architecture SOC 2 et conformité dès le premier jour
  • Infrastructure that scaled to millions of req/day
  • Infrastructure ayant géré des millions de req/jour
  • Lessons from building and selling AttackEngine
  • Leçons de la construction et vente d'AttackEngine
  • Bootstrapped founder mentality
  • Mentalité de fondateur bootstrap
Things I've Built Ce que j'ai construit

Products that shipped. Not side projects.

Des produits livrés. Pas des projets secondaires.

Live

SwiftSolvency

SaaS communication engine for the insolvency and financial services industry. AI-powered personalization, multi-channel outreach, and full analytics.

SaaS AI Personalization Email & SMS Analytics
Acquired

AttackEngine

Anti-DDoS SaaS platform with real-time attack detection, traffic fingerprinting, and multi-channel alerting. Acquired within one year of launch.

Linux Systems Traffic Fingerprinting Real-time Detection Multi-channel Alerts
Completed

Remimic

AI content repurposing platform using deepfake technology. Full backend, database architecture, and infrastructure design.

AI / Deepfake Backend Database Design Infrastructure
Completed

Snapchat AI Chatbot

Automated chatbot management system. Multi-server orchestration with personality AI and remote management capabilities.

Automation Multi-Server Personality AI Remote Mgmt
From People I've Worked With De ceux avec qui j'ai travaillé

Don't take my word for it.

Ne me croyez pas sur parole.

Jacob worked under me at Parrot Pentest on various projects, most notably Parrot-CTFs. He is proficient in PHP, MySQL, CloudOps, and DevOps pipelines. We were able to rely on Jacob for emergency code pushes, and he saved us from potential data breaches on multiple occasions with his cybersecurity background. I would recommend him to any DevOps or cybersecurity position.

Jacob a travaillé sous ma direction chez Parrot Pentest sur plusieurs projets, notamment Parrot-CTFs. Il maîtrise PHP, MySQL, le CloudOps et les pipelines DevOps. Nous avons pu compter sur lui pour des déploiements de code en urgence, et il nous a évité des fuites de données à plusieurs reprises grâce à son expertise en cybersécurité. Je le recommanderais pour tout poste DevOps ou cybersécurité.

Ryan Wilke
CEO & Founder, Lorikeet Security · Jacob's former manager
PDG et fondateur, Lorikeet Security · ancien responsable de Jacob

Jacob is without a doubt one of the most competent individuals I have worked with. His technical skills and management style are extremely efficient, he is extremely easy to work with, and he is an ideal partner for anyone who has a vision, or simply wants to scale an existing system and keep it stable.

Jacob est sans aucun doute l'une des personnes les plus compétentes avec qui j'ai travaillé. Ses compétences techniques et son style de gestion sont extrêmement efficaces, il est très facile à côtoyer, et c'est un partenaire idéal pour quiconque a une vision ou souhaite simplement faire évoluer un système existant tout en le gardant stable.

Luka Stankovic
Executive Consultant & Strategic Advisor · Jacob's mentor
Consultant exécutif et conseiller stratégique · mentor de Jacob

Jacob exhibits natural leadership, professionalism, and technical skill. His ability to tackle problems both in and outside of his job title is truly impressive. On multiple occasions when a task or deadline seemed daunting, he provided clear, actionable advice that made the issue trivial.

Jacob fait preuve d'un leadership naturel, de professionnalisme et de compétence technique. Sa capacité à résoudre des problèmes, au-delà même de son rôle, est vraiment impressionnante. À plusieurs reprises, lorsqu'une tâche ou une échéance semblait insurmontable, il a fourni des conseils clairs et concrets qui ont rendu le problème trivial.

Gavin McIntosh
Software Engineer, Webflow · reported to Jacob at Humera
Ingénieur logiciel, Webflow · a relevé de Jacob chez Humera

I've worked closely with Jacob at Humera and he's been great to have on the team. He keeps things moving and handles both the technical and operational sides without overcomplicating things. He's reliable, communicates clearly, and does a solid job.

J'ai travaillé de près avec Jacob chez Humera et c'est un atout formidable pour l'équipe. Il fait avancer les choses et gère aussi bien le côté technique qu'opérationnel sans rien compliquer. Il est fiable, communique clairement et fait un excellent travail.

Matthew Ransley
Security Software Engineer · Humera
Ingénieur logiciel sécurité · Humera

Jacob is an excellent project manager. From contract software work to affordable hosting solutions, Jacob does it all. He's an excellent communicator, and extremely ambitious in the most realistic way possible. He knows how to get things done and problem solve. I don't think you could ask for a better team player.

Jacob est un excellent chef de projet. Du développement logiciel sous contrat aux solutions d'hébergement abordables, Jacob fait tout. C'est un excellent communicateur, ambitieux de la manière la plus réaliste qui soit. Il sait faire avancer les choses et résoudre les problèmes. On ne pourrait pas rêver d'un meilleur coéquipier.

Julian Seitz
Software Developer · reported to Jacob
Développeur logiciel · a relevé de Jacob

I worked under Jacob at Parrot Pentest on various projects, mainly Parrot-CTFs. He works well under pressure, with a team, and solo. I've been able to rely on him for various coding problems. He is very helpful and a great asset to any team.

J'ai travaillé sous la direction de Jacob chez Parrot Pentest sur plusieurs projets, principalement Parrot-CTFs. Il travaille bien sous pression, en équipe comme en solo. J'ai pu compter sur lui pour divers problèmes de code. Il est très serviable et un véritable atout pour toute équipe.

Kevin Qualls
Cybersecurity Student · Parrot CTFs
Étudiant en cybersécurité · Parrot CTFs
Credentials Certifications

The paperwork that backs it up.

Les certifications qui le prouvent.

🔒
eCPPT
INE / eLearnSecurity
🔒
eWPT
INE / eLearnSecurity
🔒
eJPT
INE / eLearnSecurity
🛡
SSCP
(ISC)²
🛡
CompTIA PenTest+
CompTIA
🛡
CompTIA CySA+
CompTIA
🛡
CompTIA Security+
CompTIA
🛡
CompTIA Network+
CompTIA
💻
CompTIA A+
CompTIA
💻
ITIL 4 Foundation
PeopleCert / Axelos
Azure Fundamentals
Microsoft (AZ-900)
🌍
DELF B1 French
Ministère de l'Éducation nationale
🎓
B.S. Cybersecurity & Information Assurance
Western Governors University · Graduate
🏆
WGU Excellence Award
Information Systems Security, March 2026
FAQ FAQ

Questions people ask before reaching out.

Questions fréquentes avant de me contacter.

What do you actually do?

Que faites-vous concrètement ?

Cybersecurity consulting for startups and SMBs: SOC 2 and ISO 27001 readiness, penetration testing, and fractional CISO / vCISO engagements. You work directly with me, not a junior analyst.

Conseil en cybersécurité pour startups et PME : préparation SOC 2 et ISO 27001, tests d'intrusion et mandats de RSSI à temps partagé. Vous travaillez directement avec moi, pas avec un analyste junior.

Where are you based, and do you work remotely?

Où êtes-vous basé et travaillez-vous à distance ?

I'm based in Canada and work remote-first with startups across Toronto, Windsor, Ottawa, Waterloo, Vancouver, Calgary, and Montreal, and with teams anywhere. On-site time is available when it genuinely helps.

Je suis basé au Canada et travaille en priorité à distance avec des startups à Toronto, Windsor, Ottawa, Waterloo, Vancouver, Calgary et Montréal, et avec des équipes partout. Des rencontres sur place sont possibles au besoin.

How much does an engagement cost?

Combien coûte un mandat ?

It depends on scope. Projects like SOC 2 readiness or a pentest are fixed-scope; fractional CISO work is a monthly retainer. Tell me what's driving the timeline and I'll give you a straight quote, no drawn-out sales process.

Ça dépend de la portée. Les projets comme la préparation SOC 2 ou un test d'intrusion sont à portée fixe ; le RSSI à temps partagé est un forfait mensuel. Dites-moi ce qui motive l'échéance et je vous donnerai un prix clair.

Can you help on a tight deadline, a stalled deal or upcoming audit?

Pouvez-vous aider dans un délai serré ?

Yes, a stalled enterprise deal, a customer security questionnaire, or an upcoming audit is the most common reason people reach out. Get in touch and I'll tell you honestly what's achievable in your window.

Oui, un contrat bloqué, un questionnaire de sécurité client ou un audit à venir sont les raisons les plus fréquentes. Contactez-moi et je vous dirai honnêtement ce qui est réalisable dans votre délai.

How do we get started?

Comment commencer ?

Book a call or send a short note about your company through the Work With Me page. I respond to every message personally.

Réservez un appel ou envoyez un mot sur votre entreprise via la page Travailler avec moi. Je réponds personnellement à chaque message.

Get in touch Me contacter

Building something that
needs to be secure?

Vous construisez quelque chose
qui doit être sécurisé?

I work with founders, security teams, and early-stage companies on product, security, and operations. If you're building something that matters, let's talk.

Je travaille avec des fondateurs, des équipes de sécurité et des startups sur le produit, la sécurité et les opérations. Si vous construisez quelque chose d'important, parlons-en.

Current Availability

Disponibilité actuelle

Security Consulting Conseil en sécurité Open
Product Leadership Leadership produit Open
Advisory / Fractional Conseil / Fractionnel Open
Full-time Roles Postes à temps plein Selective

Based in Canada. Working globally.
Bilingual: English (native) · French (intermediate, B1).

Basé au Canada. Travail à l'international.
Bilingue: anglais (natif) · français (intermédiaire, B1).