Senior Distinguished Security Engineer, Offensive Security at Walmart
New York, New York, United States
Join Prog.AI to see contacts
Join Prog.AI to see contacts
Summary
🤩
Rockstar
🎓
Top School
Alex Flores is a Senior Distinguished Security Engineer specializing in offensive security with 12 years of hands-on experience building adversary emulation programs and custom offensive tooling at scale for Walmart. He leads objective-based red team engagements, introduces new TTPs into playbooks, and architects OPSEC-conscious attack infrastructure and automation to improve enterprise testing fidelity. A prolific back-end contributor to notable open-source C2 and emulation projects like BishopFox/sliver and Merlin, he focuses on expanding core functionality and robust agent/CLI behavior. His background spans IoT, VR, secure API design, and platform engineering, giving him a rare blend of low-level systems, cloud-native practices, and pragmatic security trade-offs. Comfortable mentoring operators through to senior roles, he pairs disciplined engineering (and a fondness for “temporary hacks” that become permanent) with operational rigor to harden large-scale environments.
13 years of coding experience
15 years of employment as a software developer
High School Diploma, High School Diploma at Redlands East Valley High School
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
Role in this project:
Back-end Developer
Contributions:12 commits, 4 PRs, 6 comments in 1 month
Contributions summary:Alex primarily focused on implementing and extending the functionality of the Merlin C2 framework's agent and command-line interface. Their work involved adding new commands like `ls`, `cd`, and `pwd` to the agent, along with the corresponding client-side implementations. The user also refactored the codebase by renaming message types and improving the handling of arguments with spaces in the file paths. Furthermore, the user made adjustments to build configurations to allow setting callback URLs at runtime.
Contributions:2 reviews, 6 commits, 7 PRs in 3 days
Contributions summary:Alex contributed significantly to the `sliver` framework, primarily focused on adding and modifying core back-end functionality. Their contributions included implementing a file move command (`mv`), adding generated protobuf files, and adding the ability to view the current impersonated token via `whoami`. These changes involved modifications across multiple components of the framework, including client commands, server RPC, implant handlers, and protobuf definitions, indicating a focus on expanding the framework's capabilities and functionality.
emulationsecurity-toolsimplantgolangdns-server
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.