Offensive + Cloud Security

Brian Montiel

building Cloud Security _

Security analyst, hacker, and builder focused on FedRAMP, cloud security, and building tools that make compliance work less painful.

11Projects
5Certifications
7HTB Write-ups
Brian Montiel

01 / workspace

Projects

POA&M Automation Tool

Turns Nessus, Tenable, Qualys, and Wiz exports into FedRAMP-compliant POA&Ms. NIST 800-53 mapping, dedup, and live VDR reports with CISA KEV + EPSS lookups.

SecurityGRCAutomation
View repo →

CloudGRC

Multi-cloud evidence collector for AWS, Azure, and GCP. Covers 180+ resource types and 230+ automated checks mapped to NIST 800-53, packaged into audit-ready bundles.

CloudGRCSecurity
View repo →

CMMC Toolkit

Terminal CLI for CMMC 2.0 readiness. Gap assessment with SPRS scoring, SSP builder with multi-format export, and a searchable library of all 110 practices.

GRCSecurity
View repo →

OCR Screenshot Renamer

Renames screenshots from visible text and image content, turning generic names into readable files like aws-vpc-route-tables.png.

SecurityAutomation
View repo →

02 / stack

Skills & Tooling

$ cloud & infra

AWSAzureGCP DockerLinux

$ offensive security

Penetration TestingRed Teaming C2 / CRTOHTB / CTFOSINT

$ grc & compliance

FedRAMPNIST 800-53 CMMC 2.0POA&MSPRS

$ languages & tooling

PythonRustTypeScript BashSolana / Anchor

03 / writeups

Labs

04 / credentials

Badges & Certifications

CRTO Badge

CRTO

PNPT Badge

PNPT

School of Solana Badge

School of Solana S8

eJPT Badge

eJPT

CySA+ Badge

CySA+

05 / connect

Contact