2+ years of hands-on offensive security experience. I find the vulnerabilities in your systems before the adversaries do — delivering actionable intelligence, not just reports.
I'm Marcus Veil, a freelance penetration tester with over 2 years of specialized experience in offensive security. I help startups, SMEs, and enterprises understand their actual attack surface — not just the theoretical one.
My approach is methodology-first, tool-second. Every engagement is scoped precisely, executed thoroughly, and reported in a way that your technical and executive teams can both act on. No fluff, no filler — just clean, verified findings with proof-of-concept exploits and real remediation paths.
I've conducted assessments for SaaS companies, fintech startups, healthcare platforms, and government contractors. If something can be broken into, I want to find it before your adversaries do.
Every engagement is custom-scoped. I don't offer cookie-cutter assessments — I offer real adversarial simulation tailored to your threat model.
Full OWASP Top 10 coverage plus logic flaws, business flow abuse, authentication bypass, and API security. Black-box, grey-box, or white-box scoping available.
Internal and external network assessments. Firewall evasion, lateral movement simulation, privilege escalation, and Active Directory attacks. Real attacker perspective.
Goal-based adversarial simulation. Full kill-chain attack simulation against your people, processes, and technology — measuring real-world detection and response capabilities.
AWS, Azure, and GCP misconfigurations, IAM privilege escalation, exposed storage buckets, serverless function abuse, and container escape scenarios.
iOS and Android security assessments — static and dynamic analysis, insecure data storage, improper session handling, deep link abuse, and reverse engineering.
Targeted phishing campaigns, vishing simulations, pretexting, and physical access assessments. Measure your human firewall before attackers exploit it.
A structured, transparent process from kickoff to remediation verification. No surprises, no scope creep, no ambiguity.
Discovery call to understand your environment, threat model, and objectives. We define in-scope assets, testing windows, emergency contact procedures, and legal authorization documents — every engagement starts with a signed Statement of Work.
Passive and active information gathering. Domain enumeration, employee OSINT, technology fingerprinting, leaked credential searches, and attack surface mapping to build a comprehensive target picture before touching a single system.
Methodical, controlled testing against agreed scope. Every finding is exploited to maximum impact to demonstrate real business risk — not just CVSS scores. All activity is logged with timestamps for your incident response team.
Executive summary for leadership and technical deep-dive for your engineering team — in the same document. Risk-rated findings, step-by-step reproduction, business impact analysis, and prioritized remediation roadmap with effort estimates.
I don't disappear after handing over the report. Free 30-day remediation Q&A window included with every engagement. Optional retest to verify fixes were applied correctly and no regressions were introduced.
Industry-standard tooling combined with custom scripts and techniques. The right tool for the right job — always.
Real words from real engagements. Every client relationship is built on discretion, professionalism, and measurable results.
Marcus found a critical authentication bypass in our fintech API that three other firms had missed. His report was the clearest and most actionable pentest output we've ever received. Already re-engaged for this year.
We hired Marcus for a red team simulation ahead of our SOC 2 audit. He got full domain admin in under 4 hours. Painful to see — but exactly what we needed to fix before auditors arrived. Absolutely professional throughout.
The cloud assessment uncovered 12 misconfigured IAM roles and two publicly readable S3 buckets we didn't know about. Marcus walked our DevOps team through every fix personally. That extra support is worth the price alone.
Fixed-scope engagements with clear deliverables. No hidden retainers, no billable hour surprises. Need something custom? Let's talk.
Perfect for startups and small web apps needing a baseline security assessment before launch or investor due diligence.
The most popular option. Comprehensive web app + network assessment with full reporting and a retest cycle included.
Full red team operations, multi-week engagements, cloud assessments, social engineering, and bespoke adversarial simulations.
All communications are treated with strict confidentiality. I typically respond within 24 hours with a proposed scoping call.