Hello, I'm

David Touma

Passionate about hardening systems, identifying weaknesses, and helping organizations strengthen their security posture through practical contributions and continuous learning.

About Me

Get to know more about my journey

I'm a Cybersecurity student at Fanshawe College with a strong passion for Windows security research and penetration testing. Currently seeking a Winter 2026 co-op opportunity where I can apply my skills to help identify and mitigate security vulnerabilities.

With hands-on experience in Active Directory exploitation, scripting in Python, coding in Java, and Bug Bounty Hunting, I'm dedicated to understanding both offensive and defensive security techniques. I actively practice on VulnLabs machines and maintain a home Active Directory environment for testing attack and mitigation strategies.

Beyond cybersecurity, I founded BrightBiz Solutions, a web services business where I develop, deploy, and maintain business services like Websites, CRM, and Databases. I'm also a tutor, helping students master different programming languages like Python and Java.

Education: Fanshawe College - Cybersecurity | Current GPA: 3.53
Certifications: Practical Junior Penetration Tester (PJPT) - TCM Security, 2025
Goals:
  • HTB Certified Penetration Testing Specialist (CPTS) by early 2026
  • OffSec Certified Professional (OSCP) by 2027

Skills & Expertise

A look at what I can do

Penetration Testing

I use tools like Nmap for network recon, Burp Suite for web app testing, and Metasploit for exploitation. I have a strong focus on Active Directory attacks.

Programming

I write scripts in Python and build applications in Java to automate tasks and create security tools, always with a focus on writing secure, clean code.

Security Research

I enjoy digging into systems to find vulnerabilities. I'm skilled at developing Proof-of-Concept (PoC) exploits and writing clear, professional reports on my findings.

Web Security

I have hands-on experience finding and fixing common vulnerabilities, like those in the OWASP Top 10. I also securely deploy and manage web servers like Nginx.

System Security

My main passion is Windows and Active Directory security. I build and audit AD environments to find and exploit common misconfigurations and weaknesses.

Tools & Infrastructure

I build and maintain my own virtual labs with VMWare. I use Git for all my projects and am comfortable working with MySQL databases and core networking.

Projects & Experience

Recent work and personal development

Home AD Lab

Penetration Testing

Built and maintain a virtual Active Directory environment for testing various attack vectors and mitigation strategies, gaining hands-on experience with AD security.

  • VMWare-based virtual environment
  • Testing attack techniques (Kerberoasting, Pass-the-Hash, etc.)
  • Implementing and validating security controls like LAPS

BrightBiz Solutions

Web Development

Founded and operate a web services agency, developing secure, business-focused web services and managing deployment, maintenance, and client relations.

  • Engineered secure web applications with attention to input validation, encryption, and access control
  • Integrated continuous security checks and vulnerability mitigation into the development process
  • Hardened web servers and implemented monitoring to ensure application integrity

VulnLabs

Penetration Testing

Ongoing offensive security training through VulnLabs CTF environments, emphasizing practical exploitation, AD attacks, and lateral movement within simulated corporate networks.

  • Conducted reconnaissance, vulnerability exploitation, and privilege escalation
  • Simulated internal network compromises and domain privilege abuse
  • Documented attack paths and remediation strategies for lab reporting

Notebooks & Writeups

Documentation of my learning journey and research

I maintain detailed documentation of my penetration testing exercises, CTF writeups, and security research findings. These notebooks serve as both a learning resource and a portfolio of my practical skills.

View All Notebooks & Writeups

Includes CTF writeups, vulnerability research, and technical documentation

Get In Touch

Let's connect and discuss opportunities

I'm always open to discussing new opportunities or connecting with other security professionals.