Patrick Keller
Head of Merlon's Purple Team. Patrick spends his days attacking Merlon the way a real adversary would — and his signature is the last thing every release passes before it reaches production. Fifteen years of offensive security, distilled into one job: turning "we think we're protected" into "we've proven it."
Why the gate exists
"A control that has never been attacked isn't a defence — it's a hope. My job is to remove hope from the equation before it ever reaches a customer."
Patrick joined Merlon to build something most SaaS companies outsource or skip entirely: a permanent, in-house adversary that never stops testing. He runs controlled attack simulations against Merlon's own environment, verifies that the Blue Team's detections actually fire, and owns the hard release gate that stands between any change and production. Nothing ships until he can prove it holds.
Fifteen years on the offensive side
Patrick's career has been spent thinking like an attacker — first breaking systems for a living, then building the defences that stop people like his former self.
From red team to release gate
Patrick started out in penetration testing, moved into full-scope red teaming for financial-services and healthcare clients, and spent five years leading an adversary-emulation practice before joining Merlon. Along the way he learned the lesson that shapes how he works today: the most dangerous vulnerability is the untested assumption, and the fastest way to kill it is to attack it on purpose.
At Merlon he built the Purple Team from a discipline into a department — pairing offensive testing with the Blue Team's detection engineering so every finding becomes a permanent improvement, not a one-off report. He is deliberately not a siloed red teamer: attacker and defender share findings in real time, on one team, in one loop.
- Built Merlon's adversary-emulation programme from the ground up
- Owns the release security gate — every deploy, no exceptions
- Runs a closed detect → test → harden loop with the Blue Team
gate.sign v2.14.0 · status=PASSED
finding.close PT-0416 · re-tested · verified
What Patrick specialises in
The disciplines he brings to Merlon every day — the same ones he uses to keep the platform's defences honest.
Adversary emulation
Designing realistic, threat-informed attack scenarios drawn from how real intruders behave — not a static checklist — and running them against Merlon's own systems.
Control validation
Proving that detection rules, access controls and segmentation actually work under attack — and rebuilding them with the Blue Team when they don't.
Release assurance
Owning the hard security gate: every change is simulated, validated and verified before promotion, with a failed check stopping the release automatically.
Threat modelling
Mapping where an attacker would go next across the full intrusion lifecycle, so a control that holds at the front door but fails at lateral movement is caught first.
Detection engineering
Translating every finding into concrete, durable detection content so the next simulation always starts from a higher baseline than the last.
Security leadership
Running the Purple Team as a permanent, collaborative in-house function — mentoring engineers and keeping offence and defence on the same side of the table.
Career & credentials
A path built entirely on the offensive side of security, and the certifications that back it.
Founded and leads Merlon's in-house Purple Team. Built the adversary-emulation programme and the hard release gate that validates every deploy, working shoulder-to-shoulder with the Blue Team on a continuous detect–test–harden loop.
Led full-scope red-team engagements for regulated enterprises across the DACH region, maturing client detection capabilities through structured, ATT&CK-mapped emulation.
Web, network and cloud penetration testing; began specialising in translating raw findings into detection content rather than static PDF reports.
Cut his teeth on SOC triage and vulnerability assessment — the defender's-eye view that still shapes how he attacks today.