KEYSTONE CYBER

Home Disciplines Penetration testers

OFFENSIVE SECURITY

Penetration tester recruitment

Offensive security is the discipline where credentials mislead most easily. We screen on findings and research rather than on the certification list, and let your technical panel probe the depth.

What we place

Infrastructure testingInternal and external network assessment, Active Directory attack paths, build reviews.
Application testingWeb and API assessment, mobile, thick client, and source-assisted review.
Red teamingAdversary simulation, objectives-based operations, evasion. A separate pool from pen testing.
Cloud & container testingAWS and Azure configuration attack paths, Kubernetes and container escape assessment.
Consultancy deliveryBillable testers for MSSP and consultancy teams, where report quality and client handling matter as much as technique.
Offensive leadershipPractice leads and heads of offensive security who can build a team and sell the value internally.

How we screen

The best signal in offensive security is specific: a finding the candidate is proud of, and a clear account of how they got there. Strong testers tell that story in technical detail without prompting. Weaker ones describe methodology.

The second signal is written output. Testing that cannot be communicated is close to worthless — a client acts on the report, not on the exploit. We ask about report writing and client debriefs, and it is the most common reason a technically capable candidate is a poor fit for a consultancy role.

We do not run technical assessments ourselves and will not claim to. What we do is arrive at your panel with candidates whose accounts of their own work hold up, so your panel time is spent on real depth rather than filtering.

South Africa and the UK

South Africa has a small but genuinely strong offensive community, concentrated in Cape Town and Johannesburg, with a well-established conference and research culture. The pool is small enough that reputation travels, which cuts both ways in a search.

In the United Kingdom, and London especially, the market is larger and more structured around CREST and CHECK. Where your work requires registered status we screen for it explicitly rather than treating it as a nice-to-have.

Common questions

Which certifications actually matter for pen testers?

OSCP remains the practical baseline most clients recognise, with OSWE, OSEP and CRTO indicating specialisation. In the UK, CREST registration and CHECK team member or team leader status matter where the work requires them. A strong candidate with public research and no certification is still a strong candidate.

Do you place red teamers as well as pen testers?

Yes, and they are different searches. Pen testing is scoped assessment against a target; red teaming is adversary simulation against a defended environment, including evasion and objectives-based operations. The pools barely overlap.

Can you find testers for a consultancy delivery team?

Yes. Consultancy testing is a different job from in-house — report quality, client-facing delivery and utilisation pressure all matter, and we screen for whether a candidate has done billable work before.

How do you verify technical ability?

We ask about specific findings they are proud of and how they found them, look at any public research, CTF results or disclosure history, and let your technical panel test depth. We do not pretend to run the technical assessment ourselves.

Do you handle vetting and clearance requirements?

We establish clearance status and eligibility up front and state it on the shortlist. Sponsoring or obtaining clearance remains the responsibility of the employer.

Related disciplines

Talk to us about your search

A short conversation is usually enough to tell you whether we can help.