Offensive Security Leadership
Pentest practice leadership, methodology, QA, technical escalation, capability development, staffing, and delivery standards.
I’m Mike Shelton, Head of Pentesting at Red Sentry. My background spans offensive security leadership, technical project management, cybersecurity consulting, and IT operations.
I lead the pentesting practice at Red Sentry, where my work spans technical leadership, project management, security delivery, team development, QA, resource planning, scoping, and client escalations.
My career has moved through IT support, systems administration, IT management, cybersecurity operations, security consulting, technical project management, and offensive security leadership. The common thread has been solving operational problems in technical environments.
I’m strongest when the work is complicated, ownership is unclear, and technical teams need a practical path from requirements to execution.
Pentest practice leadership, methodology, QA, technical escalation, capability development, staffing, and delivery standards.
Complex project delivery, scoping support, SOW alignment, scheduling, stakeholder communication, risk management, and closeout.
Security consulting operations across pentesting, reporting, remediation validation, client readouts, and delivery process improvement.
Infrastructure, systems administration, security controls, vulnerability management, migrations, support, and IT leadership.
Lead the penetration testing practice across delivery quality, methodology, QA, technical standards, team development, scoping support, resource planning, and client escalations.
Managed cybersecurity consulting delivery across client communication, technical teams, timelines, reporting, and engagement closeout.
Led delivery of cybersecurity consulting engagements and coordinated distributed technical teams across the full client lifecycle.
Managed security operations and controls across enterprise infrastructure in a banking environment.
Led IT operations, infrastructure, security, projects, and staff in a public-sector environment.
These examples are anonymized and focused on the operating problems, decisions, and outcomes rather than client-specific details.
Challenge
Engagement ownership, readiness, scheduling, and delivery expectations were inconsistent across Sales, PM, and testing.
Work
Defined clearer handoffs, delivery stages, access-readiness expectations, scheduling controls, QA ownership, and remediation workflows.
Impact
Created a more repeatable delivery model with clearer accountability and fewer mid-engagement surprises.
Challenge
Project count alone did not reflect actual tester workload, QA rotations, skill requirements, or contractor dependency.
Work
Built practical capacity planning around tester capability, QA rotations, project weight, contractor usage, and delivery windows.
Impact
Improved staffing visibility and made it easier to identify when internal capacity was exhausted before delivery quality suffered.
Challenge
Reporting consistency and technical capability varied across testers and assessment types.
Work
Strengthened QA expectations, severity consistency, technical review, skills tracking, mentorship, and training tied to real delivery needs.
Impact
Created clearer quality expectations while using recurring delivery issues to drive targeted team development.
Challenge
Technical scope, effort, staffing, and client timelines were not always aligned before delivery commitments were made.
Work
Connected scoping inputs to effort models, delivery assumptions, resource feasibility, and clearer SOW expectations.
Impact
Improved the handoff between Sales, scoping, PM, and testing while reducing avoidable scope and scheduling friction.
Before moving fully into cybersecurity consulting, I spent years in infrastructure, systems administration, IT management, banking technology, healthcare IT, and public-sector environments.
My background fits roles where technical security, project delivery, and operational leadership overlap. I’m especially interested in offensive security leadership, technical project management, cybersecurity delivery, security consulting operations, and IT leadership.