With 16 years in offensive security, a PhD in Computer Science from the Université de Montréal, and certifications including OSCP, OSEP, and OSWE, the majority of my career has been spent finding vulnerabilities that automated tools miss. That work included leading global red team operations at General Motors, simulating nation-state-level adversaries across cloud, on-premises, and hybrid environments. The discipline behind all of it is the same: think like an attacker, verify everything by hand, and never trust a scanner output without a trained engineer behind it.
Most businesses that hire a penetration testing firm receive a report full of unverified scanner findings. The deliverable looks thorough. It rarely is. Automated vulnerability scanners cannot determine whether a finding is actually exploitable in your specific environment, that requires a certified engineer running a manual penetration test. At Pluto Security, every engagement is scoped and led by a senior tester who conducts the assessment by hand, validates each finding with proof-of-concept evidence, and stays accountable through your remediation cycle. When you fix something, we retest. Nothing closes on a scan result alone.
The team on this page holds the certifications that clients, auditors, and cyber insurers recognize, OSCP, OSEP, OSWE, CISSP, CEH, and more, across web application, API, network, cloud, and red team disciplines. What those credentials represent is a standard of work: findings that hold up under scrutiny, reports you can actually act on, and an engagement that does not end at delivery. That is why our clients stay, and it is the commitment behind every name here.