Boutique offensive security
Direct, fast, and hands-on testing of web, API, mobile, cloud, and infrastructure — findings framed in business and compliance risk, not just CVSS.
Who you work with
Senior offensive security consultant with 20+ years in IT and 10+ years in penetration testing — 500+ pentests delivered. Former Application Security Team Leader at Veeam and Business Information Security Officer at Citi, so findings arrive in business and compliance terms, not just CVSS. Active researcher and a top contributor to the OWASP Mobile Security Testing Guide.
OSCE³ · OSCP · CISSP · CISA — among 10+ offensive-security and governance certifications, all independently verifiable.
Verify: OSCE³ · OSWE · OSWP · OSCE · OSCP · eWPTX · eMAPT · CISSP · CISA · CISM
What I do
No account managers, no handoffs. You work directly with the person doing the testing.
Web, API, mobile, cloud, and infrastructure. Manual, senior-led, with clear reproduction and real business-risk context. Retest included.
Ongoing triage and validation of incoming findings by an active researcher — not a report reader. Available as a monthly retainer.
Targeted, realistic social-engineering campaigns that measure real exposure and build the case for deeper testing.
Need SOC 2 or compliance guidance? Just ask — I'll point you in the right direction.
How I work
The way I engage is also how I qualify: it suits teams that value senior attention and speed over meetings and discounts.
Selected writing & research
Technical write-ups published on Synack and Trustwave, plus coordinated security advisories. Full index at lwierzbicki.github.io.
Start here
Send scope, targets, and timing. I reply within a day, in CET hours.
contact@willowrootsec.com