Hire Direct

Hire a Penetration Tester — Direct, Not Through an Agency

You're hiring the person who does the work, not a name on a proposal. OSCP+ certified, 6+ years in cybersecurity, fixed-price engagements, remote worldwide — talk to the tester, not an account manager.

Whether you call it penetration testing, ethical hacking, offensive security testing, or a red team engagement — same rigorous work, plain-language reporting.

See all services

What to look for when hiring a penetration tester

Not every "penetration test" is the same work. Before hiring anyone — freelancer or firm — it's worth checking for a few things that separate a real assessment from a re-branded vulnerability scan:

  • Manual testing, not just automated scanning. Ask what tools are used and how findings are verified. A report that's purely scanner output, unconfirmed, misses business logic flaws and chained attack paths entirely.
  • A named, verifiable tester. Certifications should be independently checkable — OSCP/OSCP+, eCPPT, OSWE, and similar all have public verification. Ask for the credential wallet link before you sign anything.
  • A fixed scope and price in writing before testing starts, not an open-ended hourly arrangement that can run over budget.
  • A report built for two audiences — an executive summary leadership can act on, and a technical section your engineers can actually implement.
  • A signed NDA and rules of engagement defining exactly what's authorized, before any testing begins.

Freelancer vs. agency: the real tradeoff

Agencies offer bench depth and a support structure — useful for very large, multi-team engagements. For a single application, a network assessment, or an Active Directory review, that structure often just adds a management layer between you and the person actually doing the work, plus a markup to pay for it.

Hiring directly means the person on the scoping call is the person testing your systems and writing your report — no handoff, no diluted context, no junior tester filling in while a senior name signs off. It also means faster turnaround: no internal scheduling across a team, no account-manager relay for questions mid-engagement.

Why cybershells.com

  • 8 independently verifiable certifications — OSCP/OSCP+, eCPPT, eWPT, eCIR, AZ-500, SC-200, SC-300
  • Background in detection engineering — tests the way real attackers move, because the tester used to write the detection rules meant to catch them
  • Published security researcher on phishing tradecraft and trusted-infrastructure abuse
  • A public methodology — the Arsenal is the same reference material used on real engagements, published openly rather than kept as a black box
  • Fixed price, written before testing starts — see pricing

Services available

Questions about hiring

Start with a free scoping call — 30 minutes to walk through your environment, goals, and any compliance drivers. You'll get a written proposal within 24 hours with exact scope, a fixed price, and a timeline. No procurement process required to get started, though I'm happy to work within yours if you have one.

With a freelancer, the person who scopes the engagement is the person who runs it and writes the report — no account manager, no junior tester doing the actual work while a senior name is on the proposal. That usually means faster turnaround, direct communication throughout, and pricing without an agency markup layered on top.

Both. Engagements range from a single-application test for an early-stage startup to full Active Directory assessments for larger environments. Pricing scales with scope, not with the size of your company.

Yes. Every engagement starts with a mutual NDA and a signed rules-of-engagement document. Vendor questionnaires and a standard MSA are handled as part of onboarding — send them over during scoping.

A rough sense of what's in scope (application, network, Active Directory), approximate size (user roles, host count, domain complexity), and any deadline you're working against — a compliance audit date, for example. If you're not sure yet, that's fine; the scoping call fills in the gaps.

Yes, 100% remote, clients across the UK, Europe, the Middle East, and worldwide. Based in Amman, Jordan (GMT+3), with hours adjusted to overlap with your team.

Talk to the person who'll actually do the work

Free scoping call, fixed-price proposal within 24 hours.

See pricing