WhatsAppGet a quoteEmail usCall us
Pluto Security
// Our team

The People Behind Pluto Security

Certified offensive-security engineers, security consultants, and governance specialists, the people who scope your engagement are the people who run it. No juniors, no outsourcing.

Benjamin Arnaud, Chief Executive Officer of Pluto Security
Benjamin Arnaud
Chief Executive Officer
// A MESSAGE FROM OUR CEO

Why every penetration test we run is verified by hand.

An automated scanner tells you what might be vulnerable. A certified offensive security engineer tells you what actually is, and delivers the proof.

With 16 years in offensive security, a PhD in Computer Science from the Université de Montréal, and certifications including OSCP, OSEP, and OSWE, the majority of my career has been spent finding vulnerabilities that automated tools miss. That work included leading global red team operations at General Motors, simulating nation-state-level adversaries across cloud, on-premises, and hybrid environments. The discipline behind all of it is the same: think like an attacker, verify everything by hand, and never trust a scanner output without a trained engineer behind it.

Most businesses that hire a penetration testing firm receive a report full of unverified scanner findings. The deliverable looks thorough. It rarely is. Automated vulnerability scanners cannot determine whether a finding is actually exploitable in your specific environment, that requires a certified engineer running a manual penetration test. At Pluto Security, every engagement is scoped and led by a senior tester who conducts the assessment by hand, validates each finding with proof-of-concept evidence, and stays accountable through your remediation cycle. When you fix something, we retest. Nothing closes on a scan result alone.

The team on this page holds the certifications that clients, auditors, and cyber insurers recognize, OSCP, OSEP, OSWE, CISSP, CEH, and more, across web application, API, network, cloud, and red team disciplines. What those credentials represent is a standard of work: findings that hold up under scrutiny, reports you can actually act on, and an engagement that does not end at delivery. That is why our clients stay, and it is the commitment behind every name here.

On behalf of the whole team,
Benjamin Arnaud , Chief Executive Officer

// The roster

Certified Specialists, Not a Rotating Bench

A cross-functional team spanning offensive security, security consulting, governance and risk, and client delivery, holding the certifications that auditors and boards recognize. The people who scope your engagement are the people who run it.

Across the team:OSCPCISSPCISMCEHECSACPTECIPP/CCOBIT 5GSIPBSCPCompTIA Security+CompTIA PenTest+CompTIA CySA+Certified in Cybersecurity (CC)PMPAWS Solutions Architect
Filza Arsh

Filza Arsh

Cyber Security Consultant

Cybersecurity consultant focused on offensive security, cloud security assessments, and compliance, helping startups, healthcare providers, financial institutions, and SaaS platforms across Canada build resilient, manual-first security programs.

Abdul Jalil

Abdul Jalil

Senior Security Consultant

8+ years in offensive security and manual penetration testing across web applications, APIs, AI chatbots/LLMs, cloud platforms, and internal/external networks for government and enterprise clients.

Chloe Matthews

Chloe Matthews

Senior Cyber Security Consultant

Over a decade in cybersecurity, leading end-to-end security assessments across cloud, network, application, and internal IT environments.

Karan Gill

Karan Gill

GRC Consultant

11+ years leading security governance programs, risk assessments, and compliance readiness for organizations across finance, SaaS, telecom, and public-sector environments.

Eric Dawson

Eric Dawson

Senior Penetration Tester

Senior penetration tester specializing in IoT devices, embedded systems, firmware, and wireless protocols, with broad experience across web apps, APIs, networks, cloud, and full enterprise infrastructures.

Abdul Basit Baloch

Abdul Basit Baloch

Senior Penetration Tester

6+ years in penetration testing and vulnerability assessment for healthcare, fintech, and other critical-sector clients across web, mobile, cloud, and internal networks.

Riley Eastwood

Riley Eastwood

Penetration Tester

Penetration tester with deep manual-testing experience across web apps, APIs, mobile, networks, cloud (AWS/Azure), and on-prem environments, focused on the logic flaws and chained exploits scanners miss.

Caleb Anderson

Caleb Anderson

Penetration Tester

Penetration tester serving finance, SaaS, e-commerce, government, and healthcare clients with manual-first testing aligned to OWASP, PTES, NIST SP 800-115, and MITRE ATT&CK.

Ava Whitmore

Ava Whitmore

Penetration Tester

Penetration tester in Pluto Security's UK practice running manual-first assessments across web applications, APIs, mobile apps, cloud environments (AWS/Azure), and corporate networks.

Kevin Hoang

Kevin Hoang

Penetration Tester & Cybersecurity Analyst

Penetration tester and cybersecurity analyst with an MSc in Cybersecurity & Information Assurance and a software-engineering background spanning enterprise systems, IT infrastructure, and EDI.

Malek Slimi

Malek Slimi

Penetration Tester

Penetration tester with a background in cybersecurity analysis and architecture, conducting threat analysis and vulnerability testing across operating systems and networks.

Harvey Langford

Harvey Langford

Associate Ethical Hacker

Associate ethical hacker building hands-on offensive security skills across networks and web applications, actively progressing toward advanced offensive certifications.

Wyatt Callahan

Wyatt Callahan

Cyber Security Consultant

Consultant in Pluto Security's UK office, previously an Information Security Analyst at KPMG UK, delivering assessments across cloud, network, application, and identity environments.

Adam Al-Masri

Adam Al-Masri

Cyber Security Specialist

Cyber security specialist focused on threat detection, vulnerability management, and incident response, helping organizations build resilient security foundations.

Benjamin Luke Caldwell

Benjamin Luke Caldwell

Solutions Consultant

Solutions consultant with nine years helping organizations across SaaS, finance, retail, and public-sector adopt and operationalize cybersecurity solutions that fit their real business needs.

Chizuruoke C.

Chizuruoke C.

Junior Cybersecurity Analyst

MSc Cybersecurity candidate and systems administrator contributing to ISMS development and structured risk assessments aligned with ISO/IEC 27001.

Luqman Sattar

Luqman Sattar

Cyber Security Project Manager

Cyber security project manager with a Master's in Project Management, leading cross-functional teams and delivering security-focused projects in high-stakes environments.

Samuel Matthew Doyle

Samuel Matthew Doyle

Corporate Business Manager

Corporate business manager driving strategic growth and enterprise relationships, aligning complex cybersecurity requirements with business outcomes.

Asad Qadir

Asad Qadir

Business Development Manager

Business development manager generating new business for Pluto Security's VAPT, Managed SOC, Cloud Security, and vCISO offerings across SMBs, enterprises, MSPs, and international partners.

Olan Rewaju

Olan Rewaju

Business Development Manager

Business development manager and cybersecurity professional helping organizations strengthen their security posture across penetration testing, vulnerability management, and cloud security.

Jonathan Zachary

Jonathan Zachary

Onboarding Solutions

Owns the client onboarding lifecycle at Pluto Security, turning complex kickoff steps into a smooth, predictable experience for every new engagement.

Labib Kamran

Labib Kamran

Full-Stack DevOps & Cloud Engineer

Full-stack, DevOps, and cloud engineer building and maintaining scalable web applications and cloud infrastructure for Pluto Security's security-focused products.

// Work with this team

Get a Test Run by People You Can Name

// typical reply within one business day