Phil Condon

Security Consultant

Phil Condon

Phil joined Sentrium in 2022, having previously worked in DevOps at a fast-paced MedTech startup before serving as their Information Security Officer. He has experience across DevOps and Governance, Risk, and Compliance (GRC), including deploying and automating cloud environments for TeleHealth platforms, working with FHIR and HL7 standards.

Since joining Sentrium, Phil has completed hundreds of penetration tests across healthcare, telecoms, and financial/fintech sectors. Phil focuses on web applications and API security, leveraging his cloud security knowledge to uncover vulnerabilities that often go unnoticed. Phil is motivated by curiosity and the challenge of making systems more secure.

Connect with Phil

Areas of expertise

  • Web application penetration testing
  • API security testing
  • Cloud security
  • Governance, Risk & Compliance (GRC)
  • Red teaming and adversary simulation

Writing focus

Phil writes about emerging trends in application and cloud security, exploring novel techniques that exploit vulnerabilities in unusual ways and helping teams stay ahead of evolving threats.

Phil's work

  1. RoguePlanet: Microsoft Defender Privilege Escalation Zero-Day Vulnerability
  2. CPanel WHM Authentication Bypass Vulnerability (CVE-2026-41940)
  3. OAuth security, vulnerabilities and best practices

    February 24, 2026

    OAuth security guide: Flows, vulnerabilities and best practices

    Read more arrow_right_alt

  4. SPF, DKIM, DMARC and BIMI for Email Security

    October 24, 2022

    SPF, DKIM, DMARC and BIMI for Email Security

    Read more arrow_right_alt

  5. Terraform security best practices

    July 19, 2022

    Terraform security best practices (2022)

    Read more arrow_right_alt