Who I Am

I’m Jean Romero (aka Heretek), an OSCP+ certified Cyber Field Engineer at Pentera. In August 2026 I made the jump from the SOC to offensive security, and I still break boxes every hour I’m not at work. This blog is where I document what I learn: the boxes I root, the techniques I pick up, the mistakes I make, and the methodology that got me through OSCP+.

The Path

SOC Analyst → Offensive Security. That was the mission, and as of August 2026 it’s complete: I joined Pentera as a Cyber Field Engineer, running real attack techniques in real environments through automated security validation. The full story is in the Journey section. Next mission: keep leveling up. No shortcuts, no excuses.

Certifications

CertStatus
CompTIA Security+✅
CEH✅
eLearnSecurity eJPT✅
eLearnSecurity eCPPT✅ (March 2026)
OffSec OSCP+✅ June 2026

What I Do

  • Day job: Cyber Field Engineer at Pentera, helping security teams validate their defenses with real attack techniques.
  • Breaking things: Active Directory attacks, Windows & Linux privesc, web apps. 49+ boxes rooted on HackTheBox and Proving Grounds.
  • Tools I live in: Nmap, BloodHound, Impacket, CrackMapExec, Burp Suite, custom scripts
  • Code: Python, Bash, PowerShell
  • Future: OT / ICS / Autonomous Systems security

Languages

English | Português | Español | Learning French & German

Contact

As of August 2026 I’m a Cyber Field Engineer at Pentera, so I’m off the job market for now. Everything on this blog is my own personal work and opinion, not my employer’s.

Want to talk offensive security, collaborate on tools, or swap war stories? Reach out.