The founder

Senior security experience, on your side of the table.

OP4 is a one-person consultancy backed by a subcontractor network — led by a security leader who has run enterprise programs, offensive-security teams, and the automation behind them.

01Andrew Robb

Andrew Robb is the founder and CEO of OP4. Over 17+ years in information security he has led enterprise vulnerability management programs, run penetration-testing and threat-emulation teams, and advised organizations on security strategy, governance, risk, and compliance.

Today he leads enterprise vulnerability management at a Fortune 200 infrastructure-services company — a program spanning more than 90 operating companies and roughly 70,000 assets. He built the team from the ground up, set the standards the program runs on, and has taken security strategy to the board level. Earlier, at a global energy company, he transformed a ~100,000-asset vulnerability management program from reactive and spreadsheet-based into an integrated, metrics-driven function, overseeing the remediation of more than 15 million vulnerabilities. Before that he led penetration-testing and threat-emulation teams whose clients spanned financial services, healthcare, government, and energy, with earlier roles across defense, homeland security, and the intelligence community. Along the way he has sat on the practitioner side of SOC 2, PCI-DSS, HITRUST, and NIST CSF assessments — the same audits OP4 now prepares clients for.

He founded OP4 to bring that senior, practical perspective to the small and mid-sized organizations that need it most but can't justify a full-time security team.

Andrew Robb
Founder & CEO, OP4 LLC
Experience — 17+ years in information security
Based — Arlington, Virginia
Focus — vulnerability management, penetration testing, program leadership, GRC
LinkedIn
02What sets the work apart

More than advice — capability you can borrow.

01
A builder, not just an advisor

Most security consultants advise. Andrew also builds. He engineers production AI tooling for security operations — a custom Model Context Protocol (MCP) server exposing 60+ security-platform tools to AI assistants, a fleet of role-specialized AI agents, and scheduled pipelines that turn live security data into threat-intelligence briefings and audit-ready compliance evidence. It's a long-running pattern: as a penetration-testing team lead he wrote the practice's methodology, scoping questionnaires, and report templates — and personally authored roughly 110 of the team's 132 knowledge-base articles. The same capability is behind OP4's AI-implementation consulting: secure, practical AI adoption from someone who ships it — not just talks about it.

02
Both sides of the table

Offense and defense. Hands-on penetration testing and threat emulation, plus years maturing large defensive programs — so recommendations come from knowing how attacks actually land and what it takes to fix them at scale.

03
Fluent from the endpoint to the boardroom

Comfortable writing the PowerShell that patches 25,000 machines and presenting security strategy to a board of directors — and translating cleanly between the two.

03Range of work

Hands-on across the discipline.

The engagements below span nearly two decades — offense and defense, technical and advisory. Not every organization needs all of it, but it's the range behind every recommendation.

01
Offensive security & penetration testing

External and internal network, web-application, API, mobile, container, and wireless testing — plus physical-site, network-segmentation, and PCI-DSS validation. Full-chain work: reconnaissance, exploitation, privilege escalation, and lateral movement, run as adversary emulation rather than a scan-and-report.

02
Application security

Static and dynamic testing (SAST and DAST) across the software lifecycle, secure-SDLC and DevSecOps pipeline integration, and the secure-coding standards and baselines that keep the same findings from coming back.

03
Vulnerability management at scale

Enterprise programs across roughly 100,000 assets — millions of vulnerabilities remediated, near-total ownership assignment, automated metrics and live reporting, and a vulnerability disclosure program.

04
Governance, risk & compliance

Readiness and audit support for SOC 2, PCI-DSS, HITRUST, ISO 27001, and NIST CSF; security-policy and risk-management program development; questionnaire and RFP response; and interim ISSO duties.

05
Threat modeling & threat hunting

Design-time attack mapping to catch flaws before code ships, and leading a threat-hunt exercise whose high-impact findings went straight into the risk register for tracking and closure.

06
Security program leadership

Turning reactive, spreadsheet-bound programs into integrated, metrics-driven functions — roadmapping, building and hiring teams from the ground up, standing up working groups, and taking security strategy to the board.

04Track record

Two decades across offense, defense, and the enterprise.

Current
Enterprise Vulnerability Management — Sr. Manager
Fortune 200 infrastructure services

Leads enterprise vulnerability management across more than 90 operating companies and roughly 70,000 assets — built the team from the ground up, set the standards the program runs on, took security strategy to the board level, and engineered the AI-assisted operating model that lets a small team run at enterprise scale. Holds a seat on the Qualys Customer Advisory Board — the second consecutive program he has represented there.

2021–2024
Sr. Manager, Enterprise Vulnerability Management
Global energy company

Transformed a ~100,000-asset program within a Cyber Fusion Center from reactive and spreadsheet-based into an integrated, metrics-driven function — overseeing the remediation of more than 15 million vulnerabilities (8.5 million in 2024 alone), with 98.5% of vulnerabilities assigned an owner, 75% of monthly metrics collection automated, and external exposures remediated until the company’s BitSight and SecurityScorecard ratings reached "A." The program came through a NIST CSF assessment with zero gaps; he also contributed to three compliance audits, including a SOC 2 Type 1, and held customer advisory board seats with both Brinqa and Qualys.

2018–2021
Penetration Testing Team Lead
Commercial & public-sector clients

Built and led the US penetration-testing and threat-emulation practice for an IT-consulting firm — delivering roughly 30 engagements spanning external and internal network, web-application, API, mobile, container, wireless, physical-site, PCI-DSS, and network-segmentation testing for clients across financial services, healthcare, state & local government, and energy. Authored the practice's methodology and most of its knowledge base, alongside secure-SDLC / DevSecOps enablement, PCI-DSS and HITRUST audit support, and interim ISSO duties.

2015–2018
Security GRC Consultant / SME
Financial services

Built the security-testing methodology and secure-SDLC processes for financial-services engagements, supported PCI and ISO audits, and authored security roadmap and program documentation.

Earlier
Defense / Homeland Security / Intelligence
Federal & IC programs

Earlier roles across defense, homeland security, and the intelligence community — supporting a Department of Defense (War) program (secure knowledge systems, deputy security manager, trained operations-center watch officer), an intelligence-community identity-and-access-management program (Oracle IdAM on Red Hat Linux), homeland-security screening systems, and a defense weapons-systems program office. The roots of OP4's adversary-informed, compliance-fluent approach.

05Credentials
Certifications
CompTIA Security+Core Impact Certified ProfessionalRapid7 Metasploit ProRapid7 AppSpider ProQualys VMDRQualys CSAMSplunk Fundamentals 1DAU ACQ 101
Education
B.A., Political Science — Virginia Tech
Methodologies
OWASPPTESNIST SP 800-115MITRE ATT&CKCVSSCWEPCI-DSSCIS Controls v8Secure SDLC / DevSecOps

Want that perspective on your program?

Tell us where your security stands today — we'll point you at the most useful next step, whether or not it's with OP4.