Dmitrii “Zamrax” Strizhkov

Head of Offensive Security. Penetration tester. AI red teamer.

Canada-based ethical hacker focused on practical offensive security, AI security assessment, and helping teams understand their real attack surface.

latest transmissionpublished

AI red teaming · field note

OffSec's New OSAI+

My experience taking OffSec's OSAI+ course and exam.

open field note
Continue to experience

Experience in the field

Canada-based penetration tester and ethical hacker focused on helping organizations understand their vulnerabilities, strengthening offensive security practice, and mentoring people entering the field.

Parabellyx Cybersecurity

3 progressive roles

  1. Head of Offensive Security

    February 2026Present

    Scaled the offensive team, implementing a Shadow-to-Lead mentorship program that cut junior onboarding-to-billable time by 40%

    Additional evidence
    • Engineered a custom LLM-based agent for automated report generation, reducing administrative overhead by 20%
    • Architected and deployed an MCP server and gateway, automating 40% of internal engagement execution
    • Institutionalized peer-review process, reducing client clarification requests by 15%
  2. Penetration Testing Practice Lead

    April 2024February 2026

    Led strategic planning and execution of the penetration testing practice, aligning security initiatives with business objectives

    Additional evidence
    • Conducted 50+ web application, 20+ network infrastructure, and wireless penetration tests independently
    • Led adoption of the updated OWASP ASVS 5.0 framework for enhanced application security verification
    • Reported directly to and assisted the CTO in shaping security strategy
  3. Penetration Tester

    February 2022April 2024

    Conducted testing on 200+ web applications, 40+ network infrastructures, and wireless networks

    Additional evidence
    • Developed custom Python tooling, reducing testing time by 20% and report writing by 60%
    • Produced comprehensive reports for technical and executive audiences with tailored remediation strategies
    • Achieved average 60% improvement in client security maturity through personalized recommendations

Digital Defence

consulting role

  1. Information Security Consultant

    May 2021February 2022

    Conducted internal and external penetration tests on networks, operating systems, and databases as part of a 4-member team

    Additional evidence
    • Utilized NMAP and Nessus for network mapping, resulting in 20% improvement in network hardening
    • Authored comprehensive penetration testing reports with vulnerability analysis and remediation strategies
    • Assisted in incident response activities including forensic investigations and risk mitigation

University of Toronto

Honours BSc, Specialist in Information Security, Major in Statistics

September 2017 — June 2021

Capabilities with evidence

The tool list matters less than where it has been applied. These are the disciplines that organize the work, with credentials and supporting tooling available for verification.

Application & AI security

Security assessment across modern web, mobile, API, and AI-enabled systems.

  • Web application penetration testing
  • AI security assessment
  • Mobile penetration testing
Supporting tools and platforms
  • Burp Suite
  • Postman
  • SQLMap

Adversary simulation

Internal and external testing that follows realistic attacker paths through infrastructure and identity.

  • Internal penetration testing
  • External perimeter testing
  • Active Directory, OSINT, wireless, and firewall assessment
Supporting tools and platforms
  • Nmap
  • Nessus
  • Impacket
  • Metasploit
  • BloodHound
  • Wireshark
  • Covenant

Security engineering

Custom tooling and automation that make testing, evidence collection, and reporting more reliable.

  • Python, Go, Rust, and Bash automation
  • Windows and Linux operations
  • AWS, GCP, and Azure environments
Supporting tools and platforms
  • Java
  • C
  • Assembly

Field notes

Practical observations from offensive security, AI red teaming, and the systems built around the work.

Browse the archive →