AVAILABLE FOR NEW ENGAGEMENTS — Q2 2026
Freelance Penetration Tester & Security Researcher

Marcus Veil Breaking Defenses,
Securing Futures.

2+ years of hands-on offensive security experience. I find the vulnerabilities in your systems before the adversaries do — delivering actionable intelligence, not just reports.

60+ Engagements
Completed
400+ CVEs &
Findings
2yr Industry
Experience
SCROLL
marcus@kali ~ whoami
$ whoami --verbose marcus.veil — Offensive Security Specialist   $ cat profile.json { "role": "Freelance Penetration Tester", "experience": "2+ years", "certifications": ["OSCP", "CEH", "CompTIA Sec+"], "focus": ["Web Apps", "Network", "Red Team"], "status": "AVAILABLE" }   $ nmap -sV target.client.io_

Adversarial
Thinking at Scale

I'm Marcus Veil, a freelance penetration tester with over 2 years of specialized experience in offensive security. I help startups, SMEs, and enterprises understand their actual attack surface — not just the theoretical one.

My approach is methodology-first, tool-second. Every engagement is scoped precisely, executed thoroughly, and reported in a way that your technical and executive teams can both act on. No fluff, no filler — just clean, verified findings with proof-of-concept exploits and real remediation paths.

I've conducted assessments for SaaS companies, fintech startups, healthcare platforms, and government contractors. If something can be broken into, I want to find it before your adversaries do.

[✓]
Offensive Security Certified Professional
Offensive Security (OffSec)
OSCP
[✓]
Certified Ethical Hacker
EC-Council
CEH
[✓]
CompTIA Security+
CompTIA
SEC+

Security Services

Every engagement is custom-scoped. I don't offer cookie-cutter assessments — I offer real adversarial simulation tailored to your threat model.

01
🌐
Web Application Testing

Full OWASP Top 10 coverage plus logic flaws, business flow abuse, authentication bypass, and API security. Black-box, grey-box, or white-box scoping available.

OWASP TOP 10API SECURITY AUTHENTICATIONBUSINESS LOGIC
02
🔌
Network Penetration Testing

Internal and external network assessments. Firewall evasion, lateral movement simulation, privilege escalation, and Active Directory attacks. Real attacker perspective.

ACTIVE DIRECTORYLATERAL MOVEMENT FIREWALL EVASIONPIVOTING
03
🎯
Red Team Operations

Goal-based adversarial simulation. Full kill-chain attack simulation against your people, processes, and technology — measuring real-world detection and response capabilities.

KILL-CHAINC2 FRAMEWORKS PHISHING SIMPERSISTENCE
04
☁️
Cloud Security Assessment

AWS, Azure, and GCP misconfigurations, IAM privilege escalation, exposed storage buckets, serverless function abuse, and container escape scenarios.

AWS / AZURE / GCPIAM ESCALATION CONTAINERSS3 EXPOSURE
05
📱
Mobile Application Testing

iOS and Android security assessments — static and dynamic analysis, insecure data storage, improper session handling, deep link abuse, and reverse engineering.

iOS / ANDROIDSTATIC ANALYSIS REVERSE ENG.FRIDA
06
🔎
Social Engineering & Phishing

Targeted phishing campaigns, vishing simulations, pretexting, and physical access assessments. Measure your human firewall before attackers exploit it.

PHISHINGVISHING PRETEXTINGPHYSICAL ACCESS

How I Work

A structured, transparent process from kickoff to remediation verification. No surprises, no scope creep, no ambiguity.

01
Scoping & Rules of Engagement

Discovery call to understand your environment, threat model, and objectives. We define in-scope assets, testing windows, emergency contact procedures, and legal authorization documents — every engagement starts with a signed Statement of Work.

Signed SOW, Rules of Engagement Document, Emergency Contact Sheet
02
Reconnaissance & OSINT

Passive and active information gathering. Domain enumeration, employee OSINT, technology fingerprinting, leaked credential searches, and attack surface mapping to build a comprehensive target picture before touching a single system.

Attack Surface Map, OSINT Report, Identified Entry Vectors
03
Active Testing & Exploitation

Methodical, controlled testing against agreed scope. Every finding is exploited to maximum impact to demonstrate real business risk — not just CVSS scores. All activity is logged with timestamps for your incident response team.

Exploitation Logs, Screen Captures, Proof-of-Concept Code
04
Reporting & Debrief

Executive summary for leadership and technical deep-dive for your engineering team — in the same document. Risk-rated findings, step-by-step reproduction, business impact analysis, and prioritized remediation roadmap with effort estimates.

Full Pentest Report (Executive + Technical), Risk Matrix, Remediation Roadmap
05
Remediation Support & Retest

I don't disappear after handing over the report. Free 30-day remediation Q&A window included with every engagement. Optional retest to verify fixes were applied correctly and no regressions were introduced.

Remediation Q&A (30 days), Retest Report, Clearance Letter

Tools & Techniques

Industry-standard tooling combined with custom scripts and techniques. The right tool for the right job — always.

Burp Suite Pro Metasploit Nmap Cobalt Strike BloodHound Impacket Responder Nuclei ffuf Havoc C2 Frida Wireshark Burp Suite Pro Metasploit Nmap Cobalt Strike BloodHound Impacket Responder Nuclei ffuf Havoc C2 Frida Wireshark
sqlmap John the Ripper Hashcat Gobuster CrackMapExec Mimikatz Evil-WinRM Nikto Shodan theHarvester Subfinder Amass sqlmap John the Ripper Hashcat Gobuster CrackMapExec Mimikatz Evil-WinRM Nikto Shodan theHarvester Subfinder Amass
// Recon
Shodan & Censys
Amass / Subfinder
theHarvester
OSINT Framework
LinkedIn OSINT
// Web & API
Burp Suite Pro
OWASP ZAP
sqlmap
ffuf / Gobuster
Nuclei Templates
// Network & AD
Nmap / Masscan
BloodHound / SharpHound
Impacket Suite
Responder / ntlmrelayx
CrackMapExec
// Post-Exploit
Metasploit / MSFvenom
Havoc / Cobalt Strike
Mimikatz / LaZagne
Evil-WinRM
Custom Python C2

What Clients Say

Real words from real engagements. Every client relationship is built on discretion, professionalism, and measurable results.

Marcus found a critical authentication bypass in our fintech API that three other firms had missed. His report was the clearest and most actionable pentest output we've ever received. Already re-engaged for this year.

JS
James S.
CTO — Series B Fintech, UK

We hired Marcus for a red team simulation ahead of our SOC 2 audit. He got full domain admin in under 4 hours. Painful to see — but exactly what we needed to fix before auditors arrived. Absolutely professional throughout.

RP
Rachel P.
Head of Security — SaaS Platform, US

The cloud assessment uncovered 12 misconfigured IAM roles and two publicly readable S3 buckets we didn't know about. Marcus walked our DevOps team through every fix personally. That extra support is worth the price alone.

AK
Arjun K.
VP Engineering — Healthcare Tech, CA

Transparent Pricing

Fixed-scope engagements with clear deliverables. No hidden retainers, no billable hour surprises. Need something custom? Let's talk.

Starter
$1,800 / engagement

Perfect for startups and small web apps needing a baseline security assessment before launch or investor due diligence.

  • Web App Pentest (up to 5 endpoints)
  • OWASP Top 10 Coverage
  • Executive + Technical Report
  • 30-Day Remediation Q&A
  • Network/Internal Assessment
  • Red Team Simulation
  • Retest Included
GET STARTED
Enterprise
Custom / engagement

Full red team operations, multi-week engagements, cloud assessments, social engineering, and bespoke adversarial simulations.

  • Everything in Professional
  • Red Team / APT Simulation
  • Cloud Security Assessment
  • Social Engineering Campaigns
  • Mobile App Testing
  • Unlimited Retests
  • Dedicated Slack Channel
LET'S TALK

Start an Engagement

All communications are treated with strict confidentiality. I typically respond within 24 hours with a proposed scoping call.

Email
marcus@marcusveil.sec
🔐
Secure / Encrypted
PGP Key available on Keybase
💬
Signal
Available on request
📍
Location
Remote — Worldwide
🕐
Response Time
Within 24 hours