Joey Victorino

The record behind the signature.

Before security, I studied medicine: a B.S. in Biology and Pre-Medicine at the University of Texas-Pan American, and roughly three years of clinical work in ICU, CCU, and emergency care at Doctors Hospital at Renaissance. Triage taught me to separate urgency from evidence and to explain consequences to people under pressure. I was studying toward medicine, not practicing as a physician.

At NCC Group I performed digital forensics, incident response, security testing, and acquisition-related technical examination. At IBM X-Force IRIS I led high-severity investigations as a Principal Consultant. I responded to enterprise compromise with Microsoft DART, then served as Senior Consultant for Cloud Security at CrowdStrike. Today I build and secure private and sovereign AI infrastructure as VP of Infrastructure & Security at Qompute AI.

The method has not changed between disciplines: stabilize, preserve evidence, test hypotheses, identify the irreversible decisions, and put the findings in writing. I lead every matter from brief to conclusion.

Service record

Microsoft DARTIncident responder — enterprise compromise response
CrowdStrikeSenior Consultant — cloud security
IBM X-Force IRISPrincipal Consultant — high-severity investigations
NCC GroupSecurity Consultant — security testing and acquisition-related technical examination
Qompute AIVP, Infrastructure & Security — private and sovereign AI (current)

Credentials

CISSP and ten GIAC certifications, with GIAC Advisory Board recognition. M.S. in Cybersecurity and Information Assurance; B.S. in Biology and Pre-Medicine.

Full certification record
CISSPCertified Information Systems Security Professional
GSECGIAC Security Essentials
GCIHGIAC Certified Incident Handler
GCIAGIAC Certified Intrusion Analyst
GREMGIAC Reverse Engineering Malware
GCFAGIAC Certified Forensic Analyst
GNFAGIAC Network Forensic Analyst
GCFEGIAC Certified Forensic Examiner
GASFGIAC Advanced Smartphone Forensics
GCDAGIAC Certified Detection Analyst
GCWNGIAC Certified Windows Security Administrator
BoardGIAC Advisory Board recognition

Earlier certification history: AWS Certified Cloud Practitioner; Cisco CCNA Routing & Switching; Cisco CCNA Security; CompTIA A+, Linux+ (Powered by LPI), Project+, Security+, and Systems Support Specialist. Some earlier vendor credentials are no longer active; issue and expiration dates are available during qualified diligence. Badge history also records IBM Mentor, IBM Recognized Speaker/Presenter, IBM Recognized Teacher/Educator, and X-Force IR Security Incident First Responder recognition.

Independence

I am not paid to recommend hardware, close deals, or defend prior work. When independence can’t be preserved, I decline.

Material conflicts — including my role at Qompute AI — are disclosed in writing before I accept an engagement.

Operating model

Personally ledAccountable from first brief to final conclusion. Authority, evidence standard, scope, and deliverable are agreed before work begins.
CollaborativeThe people who know the system contribute context, test hypotheses, and see how the evidence changes the working view.
Honest about capacityA matter that needs continuous coverage, a larger team, or a regulated capability outside my scope gets that said out loud — with approved support structured, or the work declined.
Conflicts before scopeAny potential benefit from a recommendation is disclosed in writing before scope is set.

On the record

“…got the client on track and on the road to recovery in very short order.”

From a public LinkedIn recommendation of my incident-response work. Names and organizations are omitted here.

Beyond the work

Old computers and digital preservation, high-fidelity audio, automotive and aviation engineering, tennis, and American government, campaigns, and public policy. I split time between Las Vegas and Washington, D.C., and I enjoy meeting people well outside the security circle — not every useful conversation begins as an engagement.