About Skills Experience Education Contact Projects
CYBERSECURITY PROFESSIONAL

Hi, I'm Josh Laur

Risk Analyst at Canada Life and Cyber Security Advanced Diploma student at Fanshawe College. CEH certified and active in CTF competitions. I bridge offensive security research with enterprise risk, vulnerability remediation, and technology risk assessments.

🚀 View My Work
NmapBurp SuiteWiresharkMetasploitGhidrax64dbgHashcatNessusHydraSQLmapAircrack-ngShodanProxmoxOPNsenseDockerPrometheusPython
01 Who I Am

Attacker mindset,
analyst discipline.

Offensive security is what I'm most passionate about.

I'm a Risk Analyst at Canada Life and a Cyber Security Advanced Diploma (Co-op) student at Fanshawe College, expecting to graduate in December 2027 with a 3.5 GPA. My work covers vulnerability remediation and issue management from a GRC perspective across infrastructure and applications, PAM controls, and technology risk assessments - mapping findings to business risk. Outside of work and school, offensive security is what I'm most passionate about. I spend my time building isolated research labs, earning certifications, and competing in CTFs. All of that combined is how I genuinely understand how attackers think and operate. Fluent in English and French.

02 What I Know

Technical Expertise

Domain knowledge across the offensive and defensive security spectrum.

Penetration testing and red-team research in isolated lab environments.

  • CEH certified (v13, March 2026). Trained and tested across 20 domains: scanning, exploitation, malware, social engineering, cryptography, cloud. Same tools attackers use, applied to securing real environments.
  • CPTS (Hack The Box Certified Penetration Testing Specialist) - approximately 50% complete
  • HTB Certified CTF Player - Polar Bear Championship (February 2026)
  • 1st place at The Great Canadian CTF 2026 with team SWOCTS
  • Built PhantomStack, an authorized C2 research lab running only between isolated VMs on a segmented network, with encrypted Tor/mTLS transport and a control dashboard
  • Penetration testing covering reconnaissance, exploitation, privilege escalation, and post-exploitation
  • Studied how red team infrastructure is designed: how traffic routes through VPNs to redirectors, into a DMZ, to the operations server and back
  • Focused on encrypted channels, network segmentation, session management, and building secure systems from the ground up
  • Conducted independent reverse engineering research on commercial software, including binary disassembly with Ghidra, live debugging with x64dbg, and protocol analysis through network traffic captures
  • Vulnerability assessment and security auditing
  • OSINT and reconnaissance methodology: Google dorking, Whois, DNS enumeration, Shodan
  • Sniffing and MITM techniques: ARP poisoning, packet capture analysis
  • IDS and firewall evasion techniques
  • Session hijacking and countermeasures
  • Malware analysis fundamentals: trojans, fileless malware, behavioral analysis
  • Steganography
  • Hands-on labs on Hack The Box and TryHackMe, working through real exploitation scenarios

Enterprise risk management, incident response, and security operations.

  • Risk Analyst at Canada Life: vulnerability remediation and issue management from a GRC perspective across infrastructure and applications, PAM controls, and technology risk assessments mapped to business risk
  • Security management and security fundamentals
  • Security operations and monitoring principles
  • NIST Cybersecurity Framework, OWASP Top 10, MITRE ATT&CK
  • Built and ran phishing simulations using GoPhish to study social engineering tactics and user behavior
  • Sophos endpoint security, ticketing systems, and client support from my MSP co-op at Attache Group
  • Ethics and criminology coursework providing legal and regulatory context for security work

Building security tools and platforms from the ground up.

  • Built CoreID from scratch: WebAuthn/FIDO2, MFA, CSRF protection, session hardening. Learned web security by building real auth, not reading about it.
  • Isolated IDS logging forwarded to a separate network segment for defense-in-depth
  • Developed PortPhantom with a friend, a Python network scanner with automated NVD CVE lookup
  • Cryptography fundamentals: symmetric and asymmetric encryption, hashing algorithms, PKI, certificate management, and key exchange protocols
  • Scripting for security automation using Python, Bash, and PowerShell

Network architecture, virtualization, and systems administration.

  • Designed and run my own VLAN-segmented home lab on Proxmox with OPNsense firewall
  • DMZ and redirector architecture for network isolation
  • Docker containers, Nginx reverse proxies, Caddy, MariaDB, Redis
  • Monitoring stack: Prometheus, Grafana, Loki, Promtail. Built to give stakeholders clear visibility into real risk through dashboards they can actually read.
  • VPN configuration and management: OpenVPN, WireGuard, site-to-site and remote access setups
  • Network fundamentals: TCP/IP, DNS, DHCP, routing and switching, OSPF, VLANs, ACLs
  • Wireless and mobile security
  • Perimeter defence and secure network architecture
  • Windows and Linux server administration, Active Directory, Group Policy
  • Data centre infrastructure and database management
  • Hands-on firewall, routing, and AD management from my co-op at Attache Group

Languages, frameworks, and security tooling across the stack.

  • Languages: Python, C, Bash, PowerShell, PHP, JavaScript/Svelte, SQL, HTML/CSS
  • RE tools: Ghidra, x64dbg, Fiddler
  • Pentesting: Burp Suite, Nmap, Nessus, Wireshark, Metasploit, Hydra, Nikto, SQLmap
  • Recon and OSINT: Shodan, theHarvester, Recon-ng, Gobuster, ffuf, Hping3
  • Password cracking: Hashcat, John the Ripper
  • Wireless: Aircrack-ng
  • Network: Netcat, tcpdump, OpenSSL, Responder, enum4linux
  • Social engineering: GoPhish, SET (Social Engineering Toolkit)
  • Infrastructure: Docker, Proxmox, OPNsense, Nginx, Caddy, Prometheus, Grafana
  • Other: Git, Scapy, SIEM, Active Directory
03 Background

Experience

Risk Analyst

📅 May 2026 - Present 📍 Canada Life, London, ON
  • Vulnerability remediation and issue management from a GRC perspective across infrastructure and applications.
  • PAM controls and technology risk assessments, mapping findings to business risk.
  • Bridging the gap between technical security knowledge and organizational risk management in a corporate environment.

IT / Cyber Technician

📅 January 2026 - April 2026 📍 Attache Group Inc., London, ON
  • First co-op work term at a managed service provider, supporting multiple business clients with varying security requirements.
  • Level 1 IT and cybersecurity support: endpoint protection, firewall configuration, Active Directory management, and client-facing troubleshooting.
  • Worked with enterprise tools including Sophos endpoint security, ticketing systems, and remote management platforms in a hybrid environment.
04 Credentials

Education & Certifications

🎓

Cyber Security Advanced Diploma (Co-op)

Expected Graduation: December 2027 - GPA 3.5
Fanshawe College, London ON
🔒

Certified Ethical Hacker (CEH v13)

Obtained: March 2026
EC-Council
🎯

CPTS - In Progress (~50%)

Hack The Box Certified Penetration Testing Specialist
Currently working through the certification path
🏆

HTB Certified CTF Player - Polar Bear Championship

February 2026
Hack The Box
🎓

Ontario Secondary School Diploma

French Immersion
Strathroy District Collegiate Institute
Competition Wins

Awards

🏆

The Great Canadian CTF 2026: 1st Place

National Bracket Tournament
Hack The Box x Canadian Cybersecurity Network, Team SWOCTS
05 Get In Touch

Let's Connect

Open to discussing cybersecurity opportunities, collaborations, and innovative security solutions.