PERSONNEL SECURITY DOSSIER

FILE NO. AL-2026-0806

PREPARED BY: THE SUBJECT

Alexey Laktionov — Staff Security Engineer

Subject
LAKTIONOV, ALEXEY
Occupation
Staff Security Engineer — Bloomberg, Product Security
Specialty
product security · AI/LLM security · offensive mindset
Station
Princeton, NJ (hover to declassify)
Handling
Status
ACTIVE — current posting since Oct 2020
In field
security ops since 2015 · building for the web since 2009
Channels
email · linkedin · x · resume.pdf
Alexey Laktionov — headshot
FIG. A — SUBJECT

Section I — Summary of Subject

Staff Security Engineer on Bloomberg’s Product Security team. Subject assesses new applications and features pre-release, with an offensive mindset: threat modeling, architecture and design reviews, source code review, and targeted testing. Works closely with engineers to translate findings into clear risk decisions and practical remediation.

Also focuses on GenAI/LLM application security — agentic workflows, tool use, RAG — and improving guardrails. Before Bloomberg, subject spent 10+ years in security consulting delivering penetration tests and security assessments for large enterprises.

Section II — Operational History

Bloomberg — Staff Security Engineer

Oct 2020 – present

  • Test AI/LLM applications — agentic, tools, RAG — and help improve guardrails
  • Blackbox & whitebox pentesting of new applications and features, pre-release
  • Security architecture & design reviews of applications and their full stacks
  • Source code reviews; triage/validation of SAST/DAST and bug bounty findings
  • Risk assessment & remediation guidance for developers and technical leadership

Optiv — Senior Security Consultant, Attack & Penetration

Dec 2018 – Oct 2020

  • Perimeter & internal pentests, PCI & segmentation testing — Fortune 100 clients
  • Targeted ERP/mainframe assessments; attack surface management
  • Web app, manual API, product (ATMs, kiosks), wireless, and phishing assessments

Protiviti — Senior Red Team Penetration Tester

Oct 2017 – Dec 2018

  • Red team ops, PCI/external/internal pentests, web app testing, phishing
  • Built the practice’s reporting-automation system (findings DB, templating)

Grant Thornton — Senior Penetration Tester

Jun 2015 – Oct 2017

  • External/internal pentests, red teaming, and IT audits for financial clients
  • Built and ran GT’s Cyber Lab in Azure — C2, phishing, hash cracking, scanning

2009 – 2015 · prior activity: web developer and e-commerce co-founder (Magento, Joomla, WordPress) — the web roots behind the appsec focus.

Section III — Credentials & Qualifications

Section IV — Known Capabilities

web-apps
blackbox & whitebox assessments, static & dynamic testing
ai-llm
agentic workflows, tool use, RAG, guardrails, prompt-injection testing
code-review
Python, JavaScript, C++
network
internal & external pentests, evasive & non-evasive
api
REST, GraphQL
red-team
recon, compromise, foothold, privesc, objective
product
ATMs, kiosks, embedded & device systems
social-eng
phishing, vishing, payload execution, MFA bypass
mobile-wifi
mobile app assessments; WPA/802.1x, rogue AP hunting
pci
segmentation testing, CDE & cardholder-data access paths
misc
the best findings never make the report

Section V — Commendations

  • GIAC Advisory Board member
  • 1st place (of 8) — SANS SEC660/GXPN CTF challenge
  • 6th place (of 25) — SANS NetWars 2017 (SANSFIRE, Washington DC)

Section VI — Education

  • Temple University — BBA, Management Information Systems, summa cum laude (2016)
  • Kuban State University of Technology — BSc Computer Science · BSc Economics (2006)

Section VII — Exhibits

Exhibit A
alexey@laktionov.com — primary contact channel
Exhibit B
full record (PDF) — phone upon request
Exhibit C
linkedin.com/in/alaktionov

END OF FILE · PAGE 1 OF 1 · © 2026 Alexey Laktionov

This file is static paper: no JavaScript, no cookies, no trackers.