Cybersecurity • Technical Project Management • IT Operations

I lead technical work where security, delivery, and operations meet.

I’m Mike Shelton, Head of Pentesting at Red Sentry. My background spans offensive security leadership, technical project management, cybersecurity consulting, and IT operations.

01Offensive Security Leadership
02Technical Project Management
03Cybersecurity Delivery
04IT Operations

Technical depth, delivery discipline, and practical leadership.

I lead the pentesting practice at Red Sentry, where my work spans technical leadership, project management, security delivery, team development, QA, resource planning, scoping, and client escalations.

My career has moved through IT support, systems administration, IT management, cybersecurity operations, security consulting, technical project management, and offensive security leadership. The common thread has been solving operational problems in technical environments.

I’m strongest when the work is complicated, ownership is unclear, and technical teams need a practical path from requirements to execution.

Offensive Security Leadership

Pentest practice leadership, methodology, QA, technical escalation, capability development, staffing, and delivery standards.

Technical Project Management

Complex project delivery, scoping support, SOW alignment, scheduling, stakeholder communication, risk management, and closeout.

Cybersecurity Delivery

Security consulting operations across pentesting, reporting, remediation validation, client readouts, and delivery process improvement.

IT Operations

Infrastructure, systems administration, security controls, vulnerability management, migrations, support, and IT leadership.

March 2025 – PresentRed Sentry

Head of Pentesting

Lead the penetration testing practice across delivery quality, methodology, QA, technical standards, team development, scoping support, resource planning, and client escalations.

  • Oversee day-to-day delivery across PMs, lead testers, pentesters, and contractors, including scheduling, capacity, project risk, and delivery readiness.
  • Support engagements from scoping and planning through testing, reporting, remediation validation, and closeout.
  • Partner with Sales, Product, and Operations to improve scoping, delivery tooling, workflows, and repeatable engagement processes.
  • Serve as an escalation point for complex findings, scope ambiguity, access issues, client concerns, and non-standard assessment requests.
  • Define and maintain testing methodologies, reporting standards, QA expectations, and rules of engagement across offensive security services.
  • Develop tester capability through skills assessment, training, mentoring, CTFs, and targeted learning plans.
July 2024 – October 2024Trail of Bits

Project Manager II

Managed cybersecurity consulting delivery across client communication, technical teams, timelines, reporting, and engagement closeout.

  • Managed end-to-end delivery of penetration testing and vulnerability assessment engagements against client requirements, SOWs, timelines, and deliverables.
  • Served as the primary client point of contact for project status, technical findings, recommendations, and next steps.
  • Coordinated security consultants and cross-functional stakeholders to keep engagements moving.
  • Supported technical and executive reporting, translating complex findings into clear, actionable information.
  • Improved project workflows and delivery processes to increase consistency and reduce friction.
February 2022 – May 2024Include Security LLC

Technical Project Manager

Led delivery of cybersecurity consulting engagements and coordinated distributed technical teams across the full client lifecycle.

  • Managed end-to-end delivery of penetration testing and security assessment engagements from kickoff through reporting and closeout.
  • Led kickoff meetings, status updates, readouts, and technical discussions as the primary client contact.
  • Coordinated distributed security consultants across multiple time zones, managing schedules, dependencies, blockers, and timelines.
  • Translated client requirements into clear project plans, priorities, and deliverables.
  • Supported report delivery and client readouts, connecting technical findings to practical remediation guidance.
  • Improved delivery workflows and processes to reduce friction and improve consistency.
March 2020 – February 2022Legence Bank

Cybersecurity Administrator

Managed security operations and controls across enterprise infrastructure in a banking environment.

  • Managed and secured enterprise IT infrastructure across endpoints, servers, networking, and security systems.
  • Led vulnerability management, security monitoring, patching, and remediation efforts.
  • Administered and improved controls including firewalls, endpoint protection, and access controls.
  • Developed and maintained IT security policies and procedures.
  • Delivered security awareness training and partnered with business stakeholders on security initiatives.
August 2018 – March 2020Rides Mass Transit District

Information Technology Manager

Led IT operations, infrastructure, security, projects, and staff in a public-sector environment.

  • Managed day-to-day IT operations across infrastructure, systems, networking, security, and end-user technology.
  • Led IT projects including MFA deployment, server migrations, system upgrades, and infrastructure improvements.
  • Supervised IT staff, assigned priorities, and supported operational coverage and development.
  • Managed monitoring, patching, backups, access controls, and security reviews.
  • Evaluated technology needs, vendors, and upgrade options against cost, reliability, security, and business requirements.

Earlier experience

Information Technology ManagerWalker’s Bluff Casino Resort
November 2017 – August 2018
System AdministratorLegence Bank
August 2014 – November 2017
Information Technology Support TechnicianSoutheastern Illinois College
December 2013 – August 2014
IT SupportFerrell Hospital
August 2013 – December 2013
AuditorMediacom Communications
June 2011 – February 2013
Cannon Crew Member, 13BU.S. Army Reserve
May 1997 – April 2004

Examples of the kind of problems I work on.

These examples are anonymized and focused on the operating problems, decisions, and outcomes rather than client-specific details.

Case study

Pentest Delivery Operating Model

Challenge
Engagement ownership, readiness, scheduling, and delivery expectations were inconsistent across Sales, PM, and testing.

Work
Defined clearer handoffs, delivery stages, access-readiness expectations, scheduling controls, QA ownership, and remediation workflows.

Impact
Created a more repeatable delivery model with clearer accountability and fewer mid-engagement surprises.

Case study

Capacity & Staffing

Challenge
Project count alone did not reflect actual tester workload, QA rotations, skill requirements, or contractor dependency.

Work
Built practical capacity planning around tester capability, QA rotations, project weight, contractor usage, and delivery windows.

Impact
Improved staffing visibility and made it easier to identify when internal capacity was exhausted before delivery quality suffered.

Case study

QA & Team Development

Challenge
Reporting consistency and technical capability varied across testers and assessment types.

Work
Strengthened QA expectations, severity consistency, technical review, skills tracking, mentorship, and training tied to real delivery needs.

Impact
Created clearer quality expectations while using recurring delivery issues to drive targeted team development.

Case study

Scoping & Delivery Alignment

Challenge
Technical scope, effort, staffing, and client timelines were not always aligned before delivery commitments were made.

Work
Connected scoping inputs to effort models, delivery assumptions, resource feasibility, and clearer SOW expectations.

Impact
Improved the handoff between Sales, scoping, PM, and testing while reducing avoidable scope and scheduling friction.

Built from operations up.

Before moving fully into cybersecurity consulting, I spent years in infrastructure, systems administration, IT management, banking technology, healthcare IT, and public-sector environments.

EducationA.S. Information Technology SecuritySoutheastern Illinois College
EducationA.S. Information TechnologySoutheastern Illinois College
MilitaryU.S. Army ReserveCannon Crew Member, 13B • 1997–2004
ProfessionalInfraGardMember

Technical credibility with delivery and operational leadership.

My background fits roles where technical security, project delivery, and operational leadership overlap. I’m especially interested in offensive security leadership, technical project management, cybersecurity delivery, security consulting operations, and IT leadership.

Contact

Want to talk about a role, project, or security delivery challenge?