Boutique offensive security

Penetration testing by a senior who has sat on both sides of the report.

Direct, fast, and hands-on testing of web, API, mobile, cloud, and infrastructure — findings framed in business and compliance risk, not just CVSS.

500+ pentests delivered OWASP MSTG top contributor OSCE³ · OSCP CISSP · CISA · CISM 20+ yrs in IT

Who you work with

Senior offensive security consultant with 20+ years in IT and 10+ years in penetration testing — 500+ pentests delivered. Former Application Security Team Leader at Veeam and Business Information Security Officer at Citi, so findings arrive in business and compliance terms, not just CVSS. Active researcher and a top contributor to the OWASP Mobile Security Testing Guide.

OSCE³ · OSCP · CISSP · CISA — among 10+ offensive-security and governance certifications, all independently verifiable.

Verify: OSCE³ · OSWE · OSWP · OSCE · OSCP · eWPTX · eMAPT · CISSP · CISA · CISM

What I do

Focused engagements, senior-led end to end.

No account managers, no handoffs. You work directly with the person doing the testing.

Penetration testing

Web, API, mobile, cloud, and infrastructure. Manual, senior-led, with clear reproduction and real business-risk context. Retest included.

Core engagement

Bug validation

Ongoing triage and validation of incoming findings by an active researcher — not a report reader. Available as a monthly retainer.

Recurring

Phishing simulation

Targeted, realistic social-engineering campaigns that measure real exposure and build the case for deeper testing.

Entry engagement

Need SOC 2 or compliance guidance? Just ask — I'll point you in the right direction.

How I work

Built to be low-friction for serious buyers.

The way I engage is also how I qualify: it suits teams that value senior attention and speed over meetings and discounts.

Selected writing & research

Published work and advisories.

Technical write-ups published on Synack and Trustwave, plus coordinated security advisories. Full index at lwierzbicki.github.io.

Start here

Tell me what you need tested.

Send scope, targets, and timing. I reply within a day, in CET hours.

contact@willowrootsec.com