About
David Ancheta-Nunez
Offensive Security Engineer | OSWE, OSWA, OSCP, GWAPT, GPEN
Interdepartmental liaison and advocate for Software Engineering & Offensive Security Teams. Elevating cybersecurity standards, one code line at a time. At the forefront of secure development, my cutting-edge penetration testing and training services are not just about protecting applications; they're about shaping the future of digital resilience.
Key Accomplishments:
- Mentored and cross-trained blue teamers for regular cadence purple team activities
- Crafted and ran developer organization wide tournament on secure development and the OWASP Top 10
- Presented at Q2's Security Champion Program

Career
Professional Experience
Over 12 years of experience in software development and security.
RoseCross LLC
Founder & Offensive Security Engineer
Fortifying Futures: Mastering Security in Development, Testing, and Beyond. Providing enterprise-grade penetration testing and security consulting services.
- •Full-stack security assessments across AI, Web, Mobile, Network, and Cloud
- •Secure development consulting and training
- •Threat modeling and security architecture reviews
Q2
Offensive Security Engineer
Leading offensive security initiatives for Q2's online banking platform serving 450+ financial institutions.
- •White Box Testing of Internal APIs and Web Applications
- •Active engagement with Development Teams through Threat Modeling of new products and features
- •Spearheaded PoC criteria and selection efforts leading to successful rollout of Secure Development Training Platform
- •Networking & gathering of industry security professionals for Q2's Security Champion's Program
- •Handles triaging, validation, and response of 3rd Party Pentest results for Online Banking Suite
- •Participates in secure code reviews of FI developed extensions via Q2's Innovation Studio Program
Q2
DevSecOps Engineer
Designed and implemented security automation tools and integrated security into the SDLC.
- •Built out a process resulting in the reduction of critical container vulnerabilities 30% over 2 sprints
- •Design and implement Security Automation tools for testing, monitoring, and reporting
- •Trains engineers on the OWASP Top 10 and secure coding principles
- •Ensures the integrity of Q2 software by training, implementing, and monitoring practices on Q2's SSDLC Policy
San Joaquin County Office of Education (CodeStack)
Web Architect
Led development and architecture for California Department of Education projects.
- •Spearheaded re-write of SEIS 2.0 Project
- •Experience configuring and deploying code using Azure DevOps CI/CD Pipelines
- •Full-stack development utilizing T-SQL, JavaScript (AngularJS and Angular), TypeScript, and C#
- •Performed code reviews to assure software stability, cleanliness, and performance
San Joaquin County Office of Education (CodeStack)
Web Developer
Development and maintenance of Special Education Information System (SEIS.org).
- •Responsible for the Development and Maintenance of Special Education Information System
- •ASP.NET WebForms/MVC/Web API Programming in C#
- •Client-Side Programming (JavaScript/jQuery/AngularJS)
- •SQL Server 2014 Programming
Credentials
Industry Certifications
20+ certifications in offensive security, secure development, and cloud platforms.
Offensive Security Web Expert (OSWE)
Offensive Security
Offensive Security Web Assessor (OSWA)
Offensive Security
Offensive Security Certified Professional (OSCP)
Offensive Security
Offensive Security Wireless Professional (OSWP)
Offensive Security
GIAC Web Application Penetration Tester (GWAPT)
GIAC
GIAC Penetration Tester (GPEN)
GIAC
GIAC Incident Handler (GCIH)
GIAC
GIAC Certified Web Application Defender (GWEB)
GIAC
GIAC Mobile Device Security Analyst (GMOB)
GIAC
GIAC Security Essentials (GSEC)
GIAC
GIAC Cloud Penetration Tester (GCPN)
GIAC
GIAC Cloud Security Automation (GCSA)
GIAC
GIAC Python Coder (GPYC)
GIAC
Certified AI Security Professional (CAISP)
Practical DevSecOps
AI Red Teaming Certified Professional (AIRTP+)
Learn Prompting
AWS Certified AI Practitioner
Amazon Web Services
Practical Web Pentest Associate (PWPA)
TCM Security
Practical Junior Penetration Tester (PJPT)
TCM Security
Practical Mobile Pentest Associate (PMPA)
TCM Security
Certified API Security Analyst (CASA)
APIsec University
Certified DevSecOps Professional (CDP)
Practical DevSecOps
Microsoft Certified: Azure Fundamentals
Microsoft
Education
Academic Background
ITT Technical Institute - Clovis, CA
Associate of Science Degree - Software Development Technology
Graduated with Highest Honors: June 2011
Reach Out
Contact Information
Phone
707-918-4168Website
rosecross.sh