
Dan Astor
Dan Astor is Director of Offensive Security, Research & Innovation at Security Risk Advisors, where he leads and oversees SRA’s penetration testing, application security, red team, and offensive security research practices.
Dan is responsible for the technical direction and execution of these services, including the development and maintenance of SRA’s testing methodologies, standards, tooling, quality practices, and operator tradecraft. He works closely with SRA’s technical teams to continually evolve how engagements are delivered as technologies, attacker techniques, regulatory requirements, and client environments change.
His work includes leading and supporting complex adversary simulation and threat-led penetration testing programs, including engagements aligned with TIBER-EU and DORA Threat-Led Penetration Testing (TLPT) requirements. He also helps guide the development of offensive security capabilities for highly regulated organizations and critical industries.
As part of SRA’s Research & Innovation efforts, Dan researches emerging offensive security techniques and technologies and helps translate that research into new tooling, methodologies, and client services. His current areas of focus include the application of artificial intelligence and agentic systems to penetration testing, application security, reconnaissance, security research, and the automation and augmentation of offensive security workflows.
Dan contributes to vulnerability research and coordinated disclosure, including SRA’s CVE Numbering Authority activities, and develops and contributes to open-source security tooling. He also regularly publishes technical blog post and presents at industry conferences.
Dan has worked with Fortune 1000 organizations across financial services, healthcare, pharmaceutical, technology, telecommunications, media and entertainment, manufacturing, utilities, and other critical industries. He holds the Offensive Security Certified Professional (OSCP), Certified Red Team Operator (CRTO), and CREST Practitioner Security Analyst (CPSA) certifications.




