[ scroll down ]
// root@sumlac:~#
sumlac — bash — 80x24
Welcome to sumlac.com // Type help for available commands.
 
visitor@sumlac:~$ 
// ./games --interactive
Prompt Injection Challenge
Level 1 / 5
AI or Human?
Score: 0 10s
Read the text. Decide if it was written by an AI or a human.

You have 10 seconds per round. How good is your detector?
 
// cat career.log
[2025-01 — PRESENT]
SVP Portfolio Cybersecurity
Silver Lake
Lead portfolio-level cybersecurity strategy across diverse investments. Partner with portfolio companies to implement robust security measures and compliance programs. Drive strategic risk management and value creation.
[2019-05 — 2023-04]
CISO / Chief Trust Officer
WeWork
Spearheaded global security and compliance strategies for the public offering. Led zero-trust architecture implementation and digital transformation. Reduced threat detection/response times by 50%. SOC 2, ISO27001, PCI, SOX compliance.
[2018-04 — 2019-05]
Chief Security Officer
OneLogin
Redefined security strategy post-breach with "Security First" initiative. Integrated Shift Left Security into SDLC. Led compliance for GDPR, CCPA, SOC 2, PCI, and FedRAMP.
[2016-10 — 2018-04]
VP Security Research
HackerOne
Directed advanced security research. Executed 200+ penetration tests, uncovering 500+ high-severity vulnerabilities. Developed "Cyberwar" course at UC Berkeley. Drove 200% revenue increase.
[2015-03 — 2016-10]
Chief Security Officer / CIO
Zenefits
Built global security and IT functions during hypergrowth. Reduced IT costs by 33%, achieved SOC 2 compliance. Established Red Team operations, CSIRT/CERT, and secure SDLC.
[2014-03 — 2015-03]
Director of Security
Salesforce
Led enterprise security and M&A due diligence for $1B+ acquisitions. Reduced MTTD by 60% and MTTR by 50% with advanced threat detection. SOX, SOC 2, ISO 27001 certified.
[2012-05 — 2014-03]
Head of IT Security
LinkedIn
Oversaw internal security operations for 200M+ members. Established incident response team, significantly reducing detection and response times. Enhanced global infrastructure resilience.
[2005-01 — 2012-04]
Lead Security Engineer
Salesforce
Pioneered DevOps practices, architected secure scalable infrastructures. Championed Salesforce's inaugural DevOps environment, driving efficiency and technical excellence.
// cat skills.dat
Offensive Security
Penetration Testing
Red Teaming
Threat Modeling
Vulnerability Research
Exploit Development
Reverse Engineering
Bug Bounty
Social Engineering
GRC & Compliance
SOC 2
ISO 27001
PCI DSS
SOX
GDPR / CCPA
FedRAMP
NIST CSF
Risk Management
Security Engineering
Zero Trust Architecture
SIEM / SOAR
IAM / SSO
Cloud Security (AWS/GCP)
Container Security
DevSecOps
Incident Response
Secure SDLC
Leadership
CISO Strategy
Board Reporting
M&A Due Diligence
Team Building
Security Culture
Vendor Risk Mgmt
Security Transformation
IPO Readiness
// ls -la ~/arsenal/
// AI Lab & Workflow
$ neofetch --cluster
hardware4x Mac Studio (M2 Ultra) — clustered via exo
memory2TB unified RAM across cluster
local modelKimi K2.5 (full weights) — ~23 tok/s
use caseLarge local asks, air-gapped reasoning, long-context analysis

local codingSmaller models for fast iteration and offline dev

$ cat pipeline.conf
strategyOpenAI + Anthropic (cloud) — decisions & PRD generation
routingPRDs auto-populate Kanban board as task specs
executionBoard state changes trigger Claude Code / Codex / Custom Bots
workflowMove card → agent picks up task → PR lands → review
// AI Security & Red Teaming
promptfoo
LLM vulnerability scanner with red-teaming and CI/CD integration
TypeScriptLLM Security
garak
NVIDIA's LLM vuln scanner testing 100+ attack vectors
PythonLLM Security
PyRIT
Microsoft's automation framework for AI red team campaigns
PythonAI Red Team
NeMo Guardrails
Programmable guardrails toolkit for LLM-based systems
PythonGuardrails
presidio
PII detection and anonymization for text and images via NLP
PythonData Privacy
deepteam
LLM red teaming framework with 40+ vulnerability types
PythonAI Red Team
// Bug Bounty & Offensive Security
nuclei
YAML-templated vulnerability scanner for web, DNS, and cloud
GoScanning
subfinder
Fast passive subdomain enumeration using 50+ sources
GoRecon
httpx
Multi-purpose HTTP toolkit for probing live hosts at scale
GoRecon
katana
Next-gen web crawler with JS rendering and scope control
GoRecon
ffuf
Fast web fuzzer for directories, vhosts, and parameters
GoFuzzing
feroxbuster
Recursive async content discovery tool written in Rust
RustFuzzing
sqlmap
Automatic SQL injection detection and database exploitation
PythonWeb Exploit
dalfox
Parameter-aware XSS scanner with automatic POC generation
GoXSS
amass
In-depth attack surface mapping via DNS, scraping, and APIs
GoRecon
sliver
Cross-platform adversary emulation C2 framework with mTLS
GoRed Team
trufflehog
Find and verify leaked credentials across git, S3, and Slack
GoSecrets
gitleaks
SAST tool for detecting hardcoded secrets in git repos and CI
GoSecrets
trivy
All-in-one scanner for containers, IaC, SBOM, and secrets
GoContainer
prowler
AWS/Azure/GCP security posture and compliance auditing
PythonCloud
semgrep
Lightweight static analysis with community rulesets for 30+ languages
OCamlSAST
// cat contact.txt
email : justin [at] sumlac [dot] com
linkedin : linkedin.com/in/jcalmus