Hire a Penetration Tester — Direct, Not Through an Agency
You're hiring the person who does the work, not a name on a proposal. OSCP+ certified, 6+ years in cybersecurity, fixed-price engagements, remote worldwide — talk to the tester, not an account manager.
Whether you call it penetration testing, ethical hacking, offensive security testing, or a red team engagement — same rigorous work, plain-language reporting.
What to look for when hiring a penetration tester
Not every "penetration test" is the same work. Before hiring anyone — freelancer or firm — it's worth checking for a few things that separate a real assessment from a re-branded vulnerability scan:
- Manual testing, not just automated scanning. Ask what tools are used and how findings are verified. A report that's purely scanner output, unconfirmed, misses business logic flaws and chained attack paths entirely.
- A named, verifiable tester. Certifications should be independently checkable — OSCP/OSCP+, eCPPT, OSWE, and similar all have public verification. Ask for the credential wallet link before you sign anything.
- A fixed scope and price in writing before testing starts, not an open-ended hourly arrangement that can run over budget.
- A report built for two audiences — an executive summary leadership can act on, and a technical section your engineers can actually implement.
- A signed NDA and rules of engagement defining exactly what's authorized, before any testing begins.
Freelancer vs. agency: the real tradeoff
Agencies offer bench depth and a support structure — useful for very large, multi-team engagements. For a single application, a network assessment, or an Active Directory review, that structure often just adds a management layer between you and the person actually doing the work, plus a markup to pay for it.
Hiring directly means the person on the scoping call is the person testing your systems and writing your report — no handoff, no diluted context, no junior tester filling in while a senior name signs off. It also means faster turnaround: no internal scheduling across a team, no account-manager relay for questions mid-engagement.
Why cybershells.com
- 8 independently verifiable certifications — OSCP/OSCP+, eCPPT, eWPT, eCIR, AZ-500, SC-200, SC-300
- Background in detection engineering — tests the way real attackers move, because the tester used to write the detection rules meant to catch them
- Published security researcher on phishing tradecraft and trusted-infrastructure abuse
- A public methodology — the Arsenal is the same reference material used on real engagements, published openly rather than kept as a black box
- Fixed price, written before testing starts — see pricing
Services available
Questions about hiring
Start with a free scoping call — 30 minutes to walk through your environment, goals, and any compliance drivers. You'll get a written proposal within 24 hours with exact scope, a fixed price, and a timeline. No procurement process required to get started, though I'm happy to work within yours if you have one.
With a freelancer, the person who scopes the engagement is the person who runs it and writes the report — no account manager, no junior tester doing the actual work while a senior name is on the proposal. That usually means faster turnaround, direct communication throughout, and pricing without an agency markup layered on top.
Both. Engagements range from a single-application test for an early-stage startup to full Active Directory assessments for larger environments. Pricing scales with scope, not with the size of your company.
Yes. Every engagement starts with a mutual NDA and a signed rules-of-engagement document. Vendor questionnaires and a standard MSA are handled as part of onboarding — send them over during scoping.
A rough sense of what's in scope (application, network, Active Directory), approximate size (user roles, host count, domain complexity), and any deadline you're working against — a compliance audit date, for example. If you're not sure yet, that's fine; the scoping call fills in the gaps.
Yes, 100% remote, clients across the UK, Europe, the Middle East, and worldwide. Based in Amman, Jordan (GMT+3), with hours adjusted to overlap with your team.
Talk to the person who'll actually do the work
Free scoping call, fixed-price proposal within 24 hours.