Handbook

Biographical data sheets

Updated 14 July 2026People✎ Suggest a change
On this page

Overview

This page includes biographical data sheets for key personnel in Volkis.

The Industry Presentations page showing presentations from our team is a companion to this page.

Matthew Strahan - Managing Director

18 years of dedicated, cyber security experience in designing security strategies, security architecture, implementing cyber security frameworks and standards, developing policy, procedure, standards, and processes, technology selection and implementation, incident response, and penetration testing. Carries industry qualifications including GAICD, CISSP, CISM, CISA, CGEIT, and OSCP, holds a Bachelor of Computer Science and Masters of Business Administration.

13 years of team leadership and management experience as the leader of operations and principal consultant, including leading internal IT, including support, IT transformations and an ISO27001 implementation. Led the implementation of internal systems and process improvement.

Currently serves as Managing Director of Volkis.

Available on the following social media sites:

Employment history

CompanyRoleFromTo
VolkisManaging Director2019Present
Content SecuritySenior Security Strategist20192019
Content SecurityOperations Manager20172019
Content SecurityPrincipal Consultant20122017
Securus GlobalSecurity Consultant20072011

Education

InstitutionDegreeObtained
Macquarie UniversityMBA2021
University of NSWBSc (Computer Science)2007

Certifications

  • Graduate of AICD Company Directors Course (GAICD)
  • Certified Information Security Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Certified in Governance of Enterprise IT (CGEIT)
  • Certified Ethical Hacker (CEH)
  • Certified Information Systems Security Professional (CISSP)
  • Offensive Security Certified Professional (OSCP)

Key skills

  • Experienced in business and technical security.
  • Penetration testing, including internal, external, wireless, web app, desktop app.
  • Business security, including security architecture, governance, management, policy, procedure, and framework.
  • Credit card security, including PCI DSS.
  • General IT, including transformation, governance, programming, software engineering.
  • Presented at industry bodies such as CPA Forum, Power Housing Risk and CFO meetings, LGASA.

Alexei Doudkine - Offensive Director

Penetration tester, hacker and security consultant with a decade of experience in building security systems and providing bespoke security consultancy with empathy. Worked to build and lead multiple teams and service offerings including penetration testing, security consulting, IR and security training.

Built the "Hands-on Hacking" security education course, teaching members of the NSW Police and Department of Justice around hacking techniques.

Takes great pride in helping students and newcomers to the industry get into the cyber security field through workshops, online content and CV reviews. E.g. UTS CSEC workshop

Created hacking tools for security professionals including RidRelay.

Outside of infosec, loves taking Volk the siberian husky 🐺 for walks, modding cars 🚗, rock climbing 🧗‍♂️, movies 🎥, and games 🎮.

Available on the following social media sites:

Employment history

CompanyRoleFromTo
VolkisOffensive Director2019Present
Content SecurityPrincipal Consultant20172019
Content SecuritySecurity Consultant20132017
Pacom SystemsSoftware Engineer20102013

Education

InstitutionDegreeObtained
University of NSWBSc (Computer Science)2010

Certification

  • Offensive Security Certified Professional (OSCP)
  • Offensive Security Experienced Penetration Tester (OSEP)
  • CREST Registered Tester (CRT)
  • GIAC Certified Forensic Examiner (GCFE)
  • Certified Information Systems Security Professional (CISSP) (lapsed)
  • Payment Card Industry - Qualified Security Assessor (PCI-QSA) (lapsed)

Key skills

  • Red team, Penetration testing, including internal, external, wireless, web app, mobile app
  • Social engineering and physical security, including manipulating security badges and access control systems
  • Presenting, including creating full security education courses
  • Infrastructure development and systems administration
  • Security design and architecture
  • Business security, including payment card industry, risk assessments

Joshua Rynan - Senior Security Consultant

A over decade of IT security experience, half of which being dedicated to penetration testing.

Expertise in setting up and running enterprise vulnerability management programs.

Experience running an associate penetration tester program, upskilling new pentesters from various degrees of industry experience.

Spends too much time thinking about how to write better reports.

Available on the following social media site:

Employment history

CompanyRoleFromTo
VolkisSenior Security Consultant2021Present
CyberCXPenetration Tester20192021
Content SecurityPenetration Tester20162019
IBMVulnerability Scan Analyst20112015

Education

InstitutionDegreeObtained
Federation UniversityBITC (Professional Practice)2010

Certifications

  • Altered Security Certified Red Team Master (CRTM)
  • Zero-Point Security Certified Red Team Leader (CRTL)
  • Zero-Point Security Certified Red Team Operator (CRTO)
  • Offensive Security Certified Professional (OSCP)
  • Spectre Ops Adversary Tactics: Red Team Operations (AT:RTO)

Key skills

  • Penetration testing, including internal, external, wireless, web app and social engineering.
  • Making memes in MS Paint.

David Chadwick - Senior Security Consultant

Over fifteen years of IT security experience, of which six was dedicated to penetration testing.

Expertise in setting up and running enterprise vulnerability management programs, team leadership, process engineering and documentation.

Available on the following social media site:

Employment history

CompanyRoleFromTo
VolkisSenior Security Consultant2021Present
CyberCXSenior Security Consultant - Team Lead20202021
Sense of SecuritySenior Security Consultant20202020
Content SecuritySenior Security Consultant20192020
Content SecuritySecurity Consultant20152019
IBMVulnerability Scan Analyst20122015
IBMIntel and Remote Access Security Team Leader20102012
IBMRemote Access Security Dispatcher20092010
IBMRemote Access Security Administrator20082009
IBMSecurity Operations Administrator20072008
IBMCustomer Service Consultant20062007

Education

InstitutionDegreeObtained
Federation UniversityBITC (Professional Practice)2008

Certifications

  • Offensive Security Certified Professional (OSCP)

Key skills

  • Penetration testing, including internal, external, wireless, web app and social engineering.
  • Experienced in business and technical security

Andy Wallis - Senior Security Consultant

Over twenty years of IT experience (that makes me feel old), with the last seven years as a professional penetration tester.

Working as a system administrator for many years along side developers has given me a unique perspective and empathy for the challenges faced when securing both networks and applications.

Available on the following social media site:

Employment history

CompanyRoleFromTo
VolkisSenior Security Consultant2022Present
TesserentSenior Security Consultant20202022
NCCSenior Security Consultant20202020
Content SecurityOffensive Consultant20192020
Alcorn GroupSecurity Consultant20172019
Content SecuritySecurity Consultant20152017
EYSenior Security Consultant20152015
ThalesSenior System Administrator20142014
OlamSenior Network Administrator20132013
CaterpillarNetwork Administrator20112013
ZBI QuanIT Infrastructure Specialist20102011
CaterpillarNetwork Administrator20082010
SuncorpSystem Security Access Administrator20072008
Odyssey GamingSystem Administrator / Software Engineer20022007
Bounty LimitedSoftware Engineer/Onsite Support20012002

Education

InstitutionQualificationObtained
Tafe NSWDp. PC and Network Support2001

Certifications

  • Offensive Security Wireless Professional (OSWP)
  • eLearnSecurity Certified Professional Penetration Tester (eCPPT)

Key skills

  • Penetration testing, including internal, external, wireless, web and mobile application.

Nathan Jarvie - Senior Security Consultant

I have over ten years of IT experience working as, and leading a team of, systems and network administrators for an MSP. This allowed me to work with a variety of technologies and people and across many industries. I am experienced with Mac, Windows and Linux systems and environments.

I moved into a career in penetration testing in 2021, and seem to be determined to get every certification that is available.

I moonlight as a Latin American and Ballroom dancing instructor during the week. I also have achieved my Black Belt in Taekwondo.

Available on the following social media sites:

Employment history

CompanyRoleFromTo
VolkisSenior Security Consultant2026Present
VolkisSecurity Consultant20222026
VolkisAssociate Security Consultant20212022
Mac AidTechnical Manager20202021
Mac AidSenior Systems and Network Engineer20122021

Education

InstitutionQualificationObtained
RMITDp. Information Technology2012

Certifications

  • Certified Red Team Leader (CRTL/CRTO2)
  • Altered Security Certified Red Team Master (CRTM)
  • HTB Certified Bug Bounty Hunter (CBBH)
  • Altered Security Certified Azure Red Team Professional (CARTP)
  • Altered Security Certified Red Team Expert (CRTE)
  • Zero-Point Security Certified Red Team Operator (CRTO)
  • eLearnSecurity Web Penetration Tester (eWPT)
  • Offensive Security Certified Professional (OSCP)
  • TCM Security Practical Network Penetration Tester (PNPT)

Key skills

  • Penetration testing, including internal, external, wireless, and web applications
  • Email phishing engagements

Alissa Borg - Associate Security Consultant

Alissa has a solid foundation in IT and a growing specialisation in cybersecurity. With a year of hands-on experience in the industry, she brings a unique blend of technical insight and problem-solving skills, backed by a background in software development and networking.

Her journey into cybersecurity was shaped by a passion for building secure systems and understanding the intricacies of digital infrastructure. Alissa has worked across various environments, contributing to vulnerability assessments, security audits, and helping teams implement best practices for secure software development.

Available on the following social media sites:

Employment history

CompanyRoleFromTo
VolkisAssociate Security Consultant2025Present
Gold Coast City CouncilCyber Trainee20252025
Cyber Audit TeamCyber Security Analyst20242025

Education

InstitutionQualificationObtained
Griffith UniversityBIT (Information Technology)2025

Certifications

  • PNPT (Practical Network Penetration Tester)
  • ISC2 Certified in Cyber Security

Key skills

  • Penetration testing, including internal, external, wireless, and web applications
  • Blue Teaming

Vini Marino - Security Consultant

Vini has 15+ years working in IT and security, starting out as a sysadmin and network admin before making the jump into offensive security. He has been breaking into things professionally (and often with permission) for over a decade now!

He enjoys building tools for self use in automations or releasing them as open-source software. Vini loves open-source and decentralisation.

Outside of work, he spends an unreasonable amount of time with blockchains, smart contracts, yelling at local LLM models, doing calisthenics and riding his motorbike.

Vini's best way to describe himself is probably in his own words:

"I like security, crypto, handstands and beers (not in order). Totally not a hacker."

Available on the following social media sites:

Employment history

CompanyRoleFromTo
VolkisSecurity Consultant2026Present
TesserentPrincipal Security Consultant20212024
Pure.SecuritySenior Security Consultant20202021
Content SecuritySenior Security Consultant20152020
WEST 1Network Administrator20132015

Education

InstitutionQualificationObtained
FIAPNetwork Administration and Security2009

Certifications

  • Offensive Security Certified Professional (OSCP)

Key skills

  • Penetration testing, including internal, external, infrastructure, wireless, and IoT
  • Web application and API security assessments
  • Mobile application security (iOS and Android)
  • Cloud, DevSecOps and assumed-breach assessments
  • Blockchain security and smart contract auditing (wasm)
  • AI and LLM security
  • Red teaming and social engineering
  • Tool & exploit development
  • Automation++