Cybersecurity
10 penetration testing consultants
These ten penetration testing consultants run or have run penetration tests and ethical hacking engagements for clients, either independently or at security consulting firms. Readers can learn how experienced pentesters scope a test, which web, API, cloud and network weaknesses they look for, and how findings should be reported and fixed.
Professionals to explore
01—10Abbas Mamoun
LinkedInExperience: Security Consultant Code Review & Penetration Testing · NTG Clarity
Security Consultant Code Review & Penetration Testing at NTG Clarity since 2024. He was Sr. Cybersecurity VAPT Consultant at SecurEyes (2021–2023) and Penetration Tester at Respond Team (2018–2021). His profile lists code review and penetration testing work and the Certified Ethical Hacker (CEH) certification from EC-Council.
Antal Németh
LinkedInExperience: Security Advisor and Penetration Tester · Self-employed
Self-employed Security Advisor and Penetration Tester since 2019, and former Penetration Tester and Security Advisor at KPMG Hungary (2015–2017). His profile says that as a freelancer he helps organizations across various sectors identify, manage and mitigate their security risks and vulnerabilities. He was Cyber Defence, Assurance and Prevent Manager at Vodafone (2020–2023).
Harsh Bothra
LinkedInExperience: Core Lead Pentester · Cobalt
Core Lead Pentester at Cobalt since 2020, where his profile says the work includes performing regular pentests over a variety of technology stacks. His profile describes him as an independent security consultant covering web, API, mobile, cloud and AI/LLM security. He was Senior Security Consultant at RedHunt Labs (2021–2022) and Security Consultant at RedHunt Labs (2021).
Ir. Paul Derksen MSc
LinkedInExperience: Senior Offensive Security Consultant (Ethical Hacker) & Owner · RedPack Cyber Security
Senior Offensive Security Consultant (Ethical Hacker) & Owner at RedPack Cyber Security since 2024. He was Senior Offensive Security Consultant (Ethical Hacker) & Technical Team Lead NL at Atos Cyber Security Services NL (2023–2024) and Senior Security Consultant & Ethical Hacker at Atos Cyber Security Services NL (2006–2022). His profile lists certifications including CISSP-ISSAP, CEH, LPT and OSCP.
Mark Roy
LinkedInExperience: Senior Security Consultant · NetSPI
Senior Security Consultant at NetSPI since 2026. His profile describes him as a penetration tester specializing in web application security, holding OSCP and OSWE certifications, who identifies and exploits vulnerabilities such as authentication bypasses, injection flaws, misconfigurations and privilege escalation paths. He was Ethical Hacker at Packetlabs (2025–2026) and Ethical Hacker Penetration Tester at Packetlabs (2023–2024).
Raymond Vanyi
LinkedInExperience: CEO, lead Penetration Tester · Superior Pentest
CEO, lead Penetration Tester at Superior Pentest since 2018. His profile describes him as a certified professional penetration tester who helps businesses strengthen their IT security by showing vulnerabilities. He was Senior IT Security Consultant at Deloitte (2017–2018), IT Security Consultant at Deloitte (2015–2017) and IT Security Consultant at EY (2014–2015).
Razvan Nitu
LinkedInExperience: Freelance Penetration Tester & Security Consultant · Self-employed
Self-employed Freelance Penetration Tester & Security Consultant since 2020, and Founder & Offensive Security Lead at CYBERSOL since 2026. His profile describes him as an ethical hacker who has worked in penetration testing across web applications, APIs, mobile applications, cloud environments and internal and external infrastructure. He was Senior Penetration Tester at NTT DATA (2025–2026) and at Cyber Smart Defence (2019–2023).
Rodolpho Concurde (ROd0X)
LinkedInExperience: Senior Penetration Tester & Red Team Operator · INFINITE Digital Security
Senior Penetration Tester & Red Team Operator at INFINITE Digital Security since 2025, and former self-employed Senior Penetration Tester & Red Team Operator (2017–2025). His profile describes him as a security consultant focused on penetration tests against applications and enterprise networks, with security analysis and tests for industries such as telecommunications, aviation and financial institutions. He was Penetration Tester at IBLISS Digital Security (2015–2016).
Vaibhav Mhatre
LinkedInExperience: Senior Security Consultant · EY
Senior Security Consultant at EY since 2026. His profile describes application security, penetration testing, VAPT and secure code review work, including penetration testing and vulnerability assessments for clients as a Certified Ethical Hacker. He was Security Analyst at Accenture (2022–2025) and Cyber Security Analyst at Tata Consultancy Services (2025–2026).
Yash Gautam
LinkedInExperience: Co-Founder IT Security Consultant · Expert Pentesting
Co-Founder IT Security Consultant at Expert Pentesting since 2021. His profile describes work in cyber security, ethical hacking and penetration testing, and lists internal penetration testing of web applications and APIs among his duties at Expert Pentesting. He was Cyber Security Engineer at Ola (2018–2021).
Choose the right perspective
Match the tester's specialty, such as web applications and APIs, cloud, mobile, internal networks or red teaming, to the systems you need tested. Ask how they scope the engagement, which methods and certifications they rely on and what a finished report and retest look like.
Questions to take into the conversation
- 01How should we scope a penetration test so it covers our real risks without wasting budget?
- 02What is the difference between a vulnerability scan, a penetration test and a red team exercise, and when do we need each?
- 03What should a good penetration test report include, and how should we verify fixes afterward?
About this directory
This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.
Request a correction or removal