Cybersecurity

10 penetration testing consultants

These ten penetration testing consultants run or have run penetration tests and ethical hacking engagements for clients, either independently or at security consulting firms. Readers can learn how experienced pentesters scope a test, which web, API, cloud and network weaknesses they look for, and how findings should be reported and fixed.

10 professionals9 companiesData retrieved September 29, 2026

Professionals to explore

01—10
  1. Abbas Mamoun

    LinkedIn

    Experience: Security Consultant Code Review & Penetration Testing · NTG Clarity

    Security Consultant Code Review & Penetration Testing at NTG Clarity since 2024. He was Sr. Cybersecurity VAPT Consultant at SecurEyes (2021–2023) and Penetration Tester at Respond Team (2018–2021). His profile lists code review and penetration testing work and the Certified Ethical Hacker (CEH) certification from EC-Council.

  2. Antal Németh

    LinkedIn

    Experience: Security Advisor and Penetration Tester · Self-employed

    Self-employed Security Advisor and Penetration Tester since 2019, and former Penetration Tester and Security Advisor at KPMG Hungary (2015–2017). His profile says that as a freelancer he helps organizations across various sectors identify, manage and mitigate their security risks and vulnerabilities. He was Cyber Defence, Assurance and Prevent Manager at Vodafone (2020–2023).

  3. Harsh Bothra

    LinkedIn

    Experience: Core Lead Pentester · Cobalt

    Core Lead Pentester at Cobalt since 2020, where his profile says the work includes performing regular pentests over a variety of technology stacks. His profile describes him as an independent security consultant covering web, API, mobile, cloud and AI/LLM security. He was Senior Security Consultant at RedHunt Labs (2021–2022) and Security Consultant at RedHunt Labs (2021).

  4. Ir. Paul Derksen MSc

    LinkedIn

    Experience: Senior Offensive Security Consultant (Ethical Hacker) & Owner · RedPack Cyber Security

    Senior Offensive Security Consultant (Ethical Hacker) & Owner at RedPack Cyber Security since 2024. He was Senior Offensive Security Consultant (Ethical Hacker) & Technical Team Lead NL at Atos Cyber Security Services NL (2023–2024) and Senior Security Consultant & Ethical Hacker at Atos Cyber Security Services NL (2006–2022). His profile lists certifications including CISSP-ISSAP, CEH, LPT and OSCP.

  5. Mark Roy

    LinkedIn

    Experience: Senior Security Consultant · NetSPI

    Senior Security Consultant at NetSPI since 2026. His profile describes him as a penetration tester specializing in web application security, holding OSCP and OSWE certifications, who identifies and exploits vulnerabilities such as authentication bypasses, injection flaws, misconfigurations and privilege escalation paths. He was Ethical Hacker at Packetlabs (2025–2026) and Ethical Hacker Penetration Tester at Packetlabs (2023–2024).

  6. Raymond Vanyi

    LinkedIn

    Experience: CEO, lead Penetration Tester · Superior Pentest

    CEO, lead Penetration Tester at Superior Pentest since 2018. His profile describes him as a certified professional penetration tester who helps businesses strengthen their IT security by showing vulnerabilities. He was Senior IT Security Consultant at Deloitte (2017–2018), IT Security Consultant at Deloitte (2015–2017) and IT Security Consultant at EY (2014–2015).

  7. Razvan Nitu

    LinkedIn

    Experience: Freelance Penetration Tester & Security Consultant · Self-employed

    Self-employed Freelance Penetration Tester & Security Consultant since 2020, and Founder & Offensive Security Lead at CYBERSOL since 2026. His profile describes him as an ethical hacker who has worked in penetration testing across web applications, APIs, mobile applications, cloud environments and internal and external infrastructure. He was Senior Penetration Tester at NTT DATA (2025–2026) and at Cyber Smart Defence (2019–2023).

  8. Rodolpho Concurde (ROd0X)

    LinkedIn

    Experience: Senior Penetration Tester & Red Team Operator · INFINITE Digital Security

    Senior Penetration Tester & Red Team Operator at INFINITE Digital Security since 2025, and former self-employed Senior Penetration Tester & Red Team Operator (2017–2025). His profile describes him as a security consultant focused on penetration tests against applications and enterprise networks, with security analysis and tests for industries such as telecommunications, aviation and financial institutions. He was Penetration Tester at IBLISS Digital Security (2015–2016).

  9. Vaibhav Mhatre

    LinkedIn

    Experience: Senior Security Consultant · EY

    Senior Security Consultant at EY since 2026. His profile describes application security, penetration testing, VAPT and secure code review work, including penetration testing and vulnerability assessments for clients as a Certified Ethical Hacker. He was Security Analyst at Accenture (2022–2025) and Cyber Security Analyst at Tata Consultancy Services (2025–2026).

  10. Yash Gautam

    LinkedIn

    Experience: Co-Founder IT Security Consultant · Expert Pentesting

    Co-Founder IT Security Consultant at Expert Pentesting since 2021. His profile describes work in cyber security, ethical hacking and penetration testing, and lists internal penetration testing of web applications and APIs among his duties at Expert Pentesting. He was Cyber Security Engineer at Ola (2018–2021).

Choose the right perspective

Match the tester's specialty, such as web applications and APIs, cloud, mobile, internal networks or red teaming, to the systems you need tested. Ask how they scope the engagement, which methods and certifications they rely on and what a finished report and retest look like.

Questions to take into the conversation

  1. 01How should we scope a penetration test so it covers our real risks without wasting budget?
  2. 02What is the difference between a vulnerability scan, a penetration test and a red team exercise, and when do we need each?
  3. 03What should a good penetration test report include, and how should we verify fixes afterward?

About this directory

This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.

Request a correction or removal

Other perspectives in Cybersecurity