Hi, I'm Calvin Hendriks.

A
Self-driven, quick starter, passionate penetration tester and security consultant with a curious mind who enjoys solving complex and challenging real-world problems.

About

I am a Cyber Security Consultant and Penetration Tester from the Netherlands. As the manager of the Tech team at Cyber4Z, I make sure my team members have assignments, write quotations for our services and help clients solve security issues. Always strive to bring 100% to the work I do. I have experience in pentesting in multiple industries, including automotive, healthcare and the public sector. I am passionate about helping customers find the right service to solve their security querstions.

  • Languages: Python, Java, JavaScript, C, C++, HTML/CSS, Bash
  • Databases: MySQL, PostgreSQL, MongoDB, MSSQL
  • Tools & Technologies: Git, Docker, JIRA, Kali Linux

Experience

Manager Technical Consulting Team
  • Leading a team of four pentesters and security consultants; responsible for capacity planning, work allocation and service quality.
  • Coaching colleagues in their technical and professional growth, encouraging ownership and independent decision-making.
  • Improved the pentest process by analyzing the full workflow end-to-end and aligning sales, planning, pentesters and backoffice.
  • Combines management with hands-on technical work so decisions on planning, quality and development stay grounded in daily practice.
November 2023 - Current | Eindhoven, Netherlands
Senior Pentester & Project Lead
  • Concurrently coordinating multiple pentests, overseeing scope, progress, quality and alignment with clients and team.
  • Actively contributing technically to one of the assessments, enabling timely adjustments for risks and dependencies.
  • Translating technical findings into business impact, clear priorities and actionable remediation advice.
  • Providing technical guidance to pentesters on technical choices, quality questions and their further professional development.
January 2026 - Current | Eindhoven, Netherlands
Security Engineer (via Securance Cyber4Z)
  • Supported dev teams in applying Toyota's internal security controls, working closely with infrastructure, cloud and SecOps teams.
  • Performed architecture reviews and security assessments, and guided threat-modelling sessions.
  • Organized penetration tests, including scope and requirements formulation.
  • Triaged high and critical vulnerabilities flagged by Checkmarx that blocked CI/CD pipelines, including technical impact analysis, exception review and escalation.
  • Tools: Checkmarx, Confluence, Jira
March 2024 - December 2025 | Brussels, Belgium (Hybrid)
Penetration Tester
  • Performed black- and grey-box penetration tests on web applications and Active Directory environments for clients in healthcare, government, transport, education and critical infrastructure.
  • Delivered reports with an accessible management summary, in-depth technical findings, reproducible steps and practical advice.
July 2023 - March 2024 | Eindhoven, Netherlands
Security Consultant
  • Raised security awareness among clients through social-engineering campaigns, including phishing, vishing and mystery-guest visits.
  • Performed vulnerability scans, including analysis, prioritization and reporting of findings and remediations.
  • Developed new services, including a GoPhish server for phishing simulations.
  • Supported penetration tests, wrote reports and presented findings to clients.
August 2022 - June 2023 | Eindhoven, NL (Hybrid)
Security Consultant
  • Security Engineer @ Nationale Nederlanden: secured CI/CD pipelines in GitLab and developed Splunk use cases and correlation rules for threat detection.
  • Inventoried IT infrastructure and SLAs as the basis for a disaster-recovery plan, including risk acceptance documentation for the financial application landscape.
  • Cyber Risk Advisor @ Nationale Nederlanden: analyzed SaaS supplier audit reports (ISO 27001, SOC 2), tracked identified risks, and coordinated the rollout of MFA across all active SaaS platforms.
  • Cloud Security Engineer @ Capgemini (intern): contributed to a new cloud security service from product design to market launch, implemented DDoS protection and a WAF on Azure and AWS, and hardened cloud resources with AWS Security Hub based on CIS benchmarks.
  • Tools: GitLab, Splunk, Jira, Azure DevOps, Java, Azure, AWS Security Hub
October 2020 - July 2022 | Utrecht, NL (Hybrid)

Certificates

OSCP

OffSec Certified Professional — 2024

eJPT

eLearnSecurity Junior Penetration Tester — 2022

PSM I

Professional Scrum Master I — 2021

Skills

Languages and Databases

Python
HTML5
CSS3
MySQL
PostgreSQL
Shell Scripting

Libraries

NumPy
Pandas
OpenCV
scikit-learn
matplotlib

Frameworks

Django
Flask
Bootstrap
Keras
TensorFlow
PyTorch

Other

Git
AWS
Heroku

Education

Master Cybersecurity

Enschede, NL

University: University of Twente
Grade: 7.7/10.0

    Relevant Courseworks:

    • Cryptography
    • Software Security
    • Cyber Risk Management

Bachelor Business & IT

Enschede, NL

University: University of Twente
Grade: 7.2/10.0

    Relevant Courseworks:

    • Software System (programming)
    • Business Intelligence
    • Finance for Engineers
    • IT Project Management

Contact