AVAILABLE FOR SECURITY ROLES

Andrew Ingram

Cybersecurity Specialist

5+ years defending financial-sector networks — incident response, penetration testing, and security operations for community and regional banks. I build offensive-security tooling to understand how attackers work, then use that to harden the systems I protect.

5+
Years in security
1460+
Immersive Labs completed
Top 1%
TryHackMe global rank
16+
Public security tools
01.

About

I'm a cybersecurity specialist based in Cincinnati, Ohio, currently protecting systems and networks in the banking sector. My day-to-day spans incident response, risk assessment, vulnerability management, and security awareness — but my background runs deeper than any single role.

At EAGLE.bank I served as assistant to the CISO, running security audits, penetration tests, and vendor assessments; monitoring events through IDS/SIEM tooling; managing incident response and fraud investigations; and reporting the bank's security posture directly to the board of directors.

Outside of work I build — a lot. From ESP32 firmware and RF testing toolkits to a post-quantum encrypted messenger and a unified OSINT platform, I use hands-on projects to stay sharp on both the offensive and defensive sides of the field. I've been running my own IT and security consultancy, Ingram Technologies, since 2016.

$ userAndrew Ingram
$ roleCybersecurity Specialist
$ locationCincinnati, Ohio
$ sectorFinancial / Banking
$ focusIR · Pentest · DFIR · OSINT
$ statusopen to opportunities
02.

Experience

IT Administrator · LCNB National Bank
Apr 2024 — Present
Lebanon, OH
  • Collaborate with the Risk department on secure system configurations and hardening standards
  • Troubleshoot hardware, software, and network issues across the organization
  • Support the delivery of company-wide cybersecurity awareness training
IT Administrator & Information Security Specialist · EAGLE.bank
Sep 2020 — Apr 2024
Cincinnati, OH
  • Developed and implemented organizational security measures as assistant to the CISO
  • Conducted security audits, penetration tests, and third-party vendor risk assessments
  • Monitored security events using IDS and SIEM tooling; managed incident response and fraud investigations
  • Authored monthly cybersecurity reports presented to the board of directors
  • Served as the organization's FS-ISAC member for threat-intelligence sharing
Owner & Operator · Ingram Technologies
Sep 2016 — Present
Ohio
  • Provide IT support, networking, and cybersecurity consulting to small-business clients
  • Deliver security assessments, hardening, and remediation guidance on an engagement basis
03.

Featured Projects

SubGHzuki

C++

Wireless-security testing firmware for the LilyGO T-Embed CC1101 (ESP32-S3). A full multi-radio toolkit — Sub-GHz spectrum analysis and OOK capture/replay, WiFi recon, BLE HID with a DuckyScript engine, RFID/NFC cloning, NRF24, and IR — all driven from a password-protected WebSocket console.

ESP32-S3CC1101RFArduino

HexBox

Python

A Raspberry Pi red-team platform that unifies seven Hak5 devices, a Flipper Zero, and ESP32 hardware under one authenticated dashboard. Aggregates loot, auto-parses NTLM hashes and AD data, supports encrypted DNS/HTTPS exfil, and integrates the Sliver C2 framework.

FlaskHak5C2Red Team

Lattix

JavaScript

A post-quantum secure messenger and file-sharing app with a zero-knowledge relay — the server can't read or forge messages. Built on NIST primitives: ML-KEM-768, ML-DSA-65, AES-256-GCM, and HKDF, with E2E group chats, disappearing messages, and fingerprint verification.

Post-QuantumFastAPIE2EECrypto

OSINT Master Tool

Python

A unified intelligence-gathering suite with a professional web GUI wrapping 15+ OSINT tools (Sherlock, Blackbird, SpiderFoot, theHarvester) plus built-in geolocation, WHOIS/DNS, and hash utilities. Security-first: AES-256 key storage, CSRF protection, input validation, and path-traversal defense.

FlaskOSINTSSERecon

ESP32-Net

C++

A distributed defensive wireless-recon toolkit: a coordinator dashboard plus three headless ESP32-S3 nodes doing WiFi surveying with GPS, passive 802.11 monitoring with intrusion detection, and BLE/GATT enumeration. Passive-only by design — live capture, watchlist alerting, and CSV export.

PlatformIOIDS802.11BLE

RedTeam Recon Dashboard

JavaScript

A Chrome (Manifest V3) extension that aggregates passive recon for the active tab into one popup: WHOIS/RDAP registration, DNS records, technology fingerprinting, and open ports via Shodan's InternetDB. Streams results progressively using only free, keyless HTTPS services — zero config.

Chrome MV3ReconShodan
04.

Technical Skills

Defense & Ops

MDR / EDRIDS / IPSSIEM Incident ResponseDFIRHoneypots OS HardeningActive Directory

Offense & Assessment

Penetration TestingVuln Scanning (Nessus) Risk AssessmentSecurity Audits OSINT / CTIRed Team Tooling

Engineering

PythonBashC++ / Arduino JavaScriptFlask / FastAPIESP32 / PlatformIO

Governance

Vendor RiskBusiness Continuity Board ReportingSecurity Awareness Fraud InvestigationFS-ISAC
05.

Credentials & Training

1460+
Immersive Labs completed
Top 1%
TryHackMe ranking
5+ yrs
Financial-sector security

Education

Bank Technology Security School
University of Wisconsin · 2022
A.A.S. Cybersecurity & Information Assurance
Ivy Tech · 2016 – 2018
Technical Certificate, Software Development
Ivy Tech · 2018

Certifications & Training

CISA — Cyber Risk Management
Cybersecurity & Infrastructure Security Agency
CISA — Cyber Intelligence
Cybersecurity & Infrastructure Security Agency
CISA — Cybersecurity for Managers
Cybersecurity & Infrastructure Security Agency
06.

Contact

Let's talk security.

Open to cybersecurity roles and consulting engagements. Whether you're hiring, need an assessment, or want to talk shop about RF hacking and post-quantum crypto — reach out.