Start a build Book an assessment
Services Work Trust Insights Company Contact Start a build Book an assessment

Attackers and builders, in the same room.

RASTTSec exists because the gap between a penetration test report and a working fix is where most security programmes quietly fail. We staff both sides of that gap.

Who we are

A security practice with an engineering bench.

Most firms specialise in one direction: they either test, or they build. Our testers hand findings to engineers who work in the same stand-ups, so remediation guidance is realistic, prioritised and, when you want it, delivered rather than described.

We are deliberately selective about engagements. Deep testing on a small number of targets produces better security outcomes than shallow coverage of everything.

0Engagements
0Service lines
0Industries served

Evidence over opinion

If we cannot reproduce it, we do not report it as a confirmed finding. Severity is argued from impact, not from a tool's default label.

Senior work only

No pyramid staffing. The consultant who scopes your engagement is the one testing it and writing the report.

Fix-side accountability

We stay through the fix window. A perfect report that never becomes a code change is a failed engagement.

Discretion as standard

NDAs before scoping, minimum necessary access, encrypted evidence handling and agreed destruction timelines.

The team

People you will actually work with.

A small, senior team. You work directly with the people who do the testing — profiles are shared during scoping and named in every proposal.

Certifications & standards

What our people hold, and what our process follows.

We map every engagement to a recognised methodology. Individual certifications are listed per consultant on request.

OWASP Top 10 / ASVSWeb application testing baseline
OWASP API Security Top 10API testing baseline
OWASP LLM Top 10AI system testing baseline
PTESPenetration testing execution standard
NIST SP 800-115Technical security testing guide
MITRE ATT&CKAdversary technique mapping
CVSS v4.0Finding severity scoring
CIS BenchmarksCloud and OS hardening reference
Careers

Work on problems that have a right answer.

We hire people who can explain their reasoning, reproduce what they claim, and write it down clearly. Certifications help; demonstrated work matters more.

RoleTypeLocationStatus
Senior Penetration TesterFull timeRemote / hybridOpen
Web & API Security ConsultantFull timeRemote / hybridOpen
LLM / AI Security ResearcherFull timeRemoteOpen
Full Stack Engineer (secure products)Full timeRemote / hybridOpen
Security InternshipInternshipOn siteWaitlist

Sample vacancy data for preview — replace with live openings or remove the section.

Partners

Partnership models.

MSP & MSSP

White-label testing capacity for managed service providers, with your branding on reporting and named delivery contacts.

Technology

Integration and joint delivery with cloud, identity and developer-tooling vendors where a shared customer needs both.

Advisory & audit

Technical testing partner for audit, legal and compliance firms that need qualified evidence from a named tester.

Let's talk about your attack surface.

A scoping call costs nothing and usually changes what you test first.