SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsRazvan-Costin Ionescu | Head of Offensive Security Services at Pentest-Tools.com | 11 GIAC Certifications | 1 SANS Course Completed

I’m Razvan Ionescu, Head of Offensive Security Services at Pentest-Tools.com. I’ve spent the last decade-plus deep in the world of ethical hacking and application security, breaking into complex systems so teams can build and ship software that’s secure.
My work focuses on uncovering business-impacting vulnerabilities in web apps, APIs, and AI-powered systems—especially the logic flaws, privilege issues, and hidden assumptions that tools rarely catch.
My interest in cybersecurity really started during my MSc in Security of Complex Networks. In a Network Security Auditing lab, I was introduced to BackTrack, the predecessor of Kali Linux, and that was my first real exposure to penetration testing.
What really got me hooked, though, was the lab exam: Instead of a traditional test, we had a live CTF competition against our fellow students. I found the whole experience fascinating — the combination of technical knowledge, problem solving, and thinking creatively to find ways into a system. That was the moment I realized this was a field I wanted to pursue further.
I took my first SANS course back in 2018, initially as a prerequisite for pursuing the path of becoming a SANS instructor. During that experience, I had the privilege of meeting and learning from the late Dr. Eric Cole, who was one of the best instructors SANS had. His passion for teaching was remarkable, and, in my opinion, remains one of his greatest qualities. The way he could keep people engaged while sharing his knowledge is something that is very difficult, if not impossible, to match.
My journey toward the GSE started in a much less formal way — as a friendly challenge between a former colleague and me. We basically made a bet to see who could earn the GSE designation first. But behind that challenge was also a genuine respect for what the certification represented. The GSE was, and still is, a very rare cert, which only a few hundred professionals worldwide have, and that exclusivity made the challenge even more appealing to us.
The path to GSE was clearly challenging. For me, though, the value of the certification has always been less about the badge itself and more about everything it takes to get there: years of hands-on work, solving real-world security problems, and constantly trying to better understand how systems fail.
One of the biggest obstacles came completely unexpectedly with the COVID-19 outbreak. I was ready to travel to Washington, D.C. for the GSE Lab when the exams were suspended. The uncertainty that followed was probably one of the most difficult parts of the entire journey. After investing so much time and effort in preparing, I suddenly had no idea when I’d be able to take the final exams, or if it would ever happen.
What kept me motivated was simply looking back at how far I’d come. I had put too much work into the journey to stop there. Eventually, I was able to complete the final exams and earn GSE #298, which made the whole experience even more meaningful.
Indeed, from my research, I found that I am the third Romanian in the world to earn this certification and the only one living in Romania actually.
Personally, earning the GSE was a very meaningful achievement because it represented the conclusion of a long journey that required a lot of persistence, preparation, and hands-on work. Knowing that only a very small number of security professionals reach this level made it even more rewarding, but the value for me was never only in having another certification or title.
Professionally, the GSE gave me a strong validation of the knowledge and experience I had accumulated over the years. It covers a broad range of security disciplines, and, especially through the practical exams, it forces you to apply that knowledge under pressure rather than simply demonstrate theoretical understanding.
I chose this path partly because I’ve always enjoyed challenging myself technically. The GSE had a reputation for being one of the most difficult and uncommon certifications in the industry, and that naturally attracted me. What initially started as a friendly challenge with a former colleague eventually became a personal goal: to see whether I could push myself far enough to complete the entire journey.
Looking back, the GSE itself is something I am proud of, but I value even more the knowledge, discipline, and experience I gained while preparing for it.
SANS training changed the way I approach security problems by making me much more structured and methodical. Before attending SANS, I was already working hands-on in penetration testing, but the training helped me connect individual techniques to a much broader understanding of how systems, networks, and attacks work together.
My first SANS course was SEC401: Security Essentials, taught by the late Dr. Eric Cole, and it had a significant impact on the way I looked at cybersecurity. Instead of seeing penetration testing mainly as a collection of tools, exploits, and techniques, I started to better understand how the different layers of security are interconnected and how weaknesses in one area can influence the security of an entire environment.
That broader perspective stayed with me and influenced the way I approach penetration tests today: not only looking for vulnerabilities, but also trying to understand the underlying cause, how different weaknesses can be chained together, and what they could realistically mean for an organization.
My main advice would be to approach the SANS and GSE journey as a long-term learning process, not simply as a certification goal. The amount of material can be overwhelming at times, especially when you start moving toward the GSE, so consistency and patience are extremely important.
I would also recommend focusing on understanding the concepts deeply rather than trying to memorize information just for an exam. Build labs, break things, troubleshoot them, and apply what you learn in real environments whenever possible. For me, the hands-on experience was just as important as the course material itself.
Another important aspect is not to be discouraged by the difficulty of the journey. There will probably be moments when you question whether the time and effort are worth it. I certainly had those moments myself. Breaking the journey into smaller milestones and focusing on one objective at a time makes it much more manageable.
Finally, enjoy the process. The GSE is a great achievement, but the real value comes from everything you learn along the way, and from the people you meet along the way. The knowledge, discipline, and problem-solving skills you develop during that journey will remain useful long after the exams are over.