Summary
Justin Larson is a Senior Application Security Consultant with 11+ years securing software across the SDLC, currently helping clients at Redpoint Security build developer-first security programs. He blends hands-on offensive work—secure code reviews, penetration testing, and threat modeling—with engineering skills to automate continuous security validation and integrate tooling into CI/CD pipelines. Justin specializes in finding vulnerabilities in modern web apps (he’s always on the hunt for the next IDOR) and has hands-on experience building intentionally vulnerable apps for CTFs to teach secure development. His background includes roles from system administration to lead security engineer, giving him practical insight into operational controls, monitoring, and host hardening. Based in Salt Lake City, he’s known for making security approachable to developers by pairing offensive expertise with a builder’s mindset to scale remediation and training.
11 years of coding experience
9 years of employment as a software developer
The University of Utah