Attackers and builders, in the same room.
RASTTSec exists because the gap between a penetration test report and a working fix is where most security programmes quietly fail. We staff both sides of that gap.
A security practice with an engineering bench.
Most firms specialise in one direction: they either test, or they build. Our testers hand findings to engineers who work in the same stand-ups, so remediation guidance is realistic, prioritised and, when you want it, delivered rather than described.
We are deliberately selective about engagements. Deep testing on a small number of targets produces better security outcomes than shallow coverage of everything.
Evidence over opinion
If we cannot reproduce it, we do not report it as a confirmed finding. Severity is argued from impact, not from a tool's default label.
Senior work only
No pyramid staffing. The consultant who scopes your engagement is the one testing it and writing the report.
Fix-side accountability
We stay through the fix window. A perfect report that never becomes a code change is a failed engagement.
Discretion as standard
NDAs before scoping, minimum necessary access, encrypted evidence handling and agreed destruction timelines.
People you will actually work with.
A small, senior team. You work directly with the people who do the testing — profiles are shared during scoping and named in every proposal.
What our people hold, and what our process follows.
We map every engagement to a recognised methodology. Individual certifications are listed per consultant on request.
Work on problems that have a right answer.
We hire people who can explain their reasoning, reproduce what they claim, and write it down clearly. Certifications help; demonstrated work matters more.
| Role | Type | Location | Status |
|---|---|---|---|
| Senior Penetration Tester | Full time | Remote / hybrid | Open |
| Web & API Security Consultant | Full time | Remote / hybrid | Open |
| LLM / AI Security Researcher | Full time | Remote | Open |
| Full Stack Engineer (secure products) | Full time | Remote / hybrid | Open |
| Security Internship | Internship | On site | Waitlist |
Sample vacancy data for preview — replace with live openings or remove the section.
Partnership models.
MSP & MSSP
White-label testing capacity for managed service providers, with your branding on reporting and named delivery contacts.
Technology
Integration and joint delivery with cloud, identity and developer-tooling vendors where a shared customer needs both.
Advisory & audit
Technical testing partner for audit, legal and compliance firms that need qualified evidence from a named tester.
Let's talk about your attack surface.
A scoping call costs nothing and usually changes what you test first.