Hire security people who can actually do the job.
The cybersecurity talent shortage is real — and the biggest risk is not an empty seat, it is the wrong hire who looks good on paper. I help you find, technically vet, and hire security professionals, assessed by someone who does the work itself.
// roles i help you fill
From analysts to CISOs
Across the full spectrum of security roles — technical individual contributors through security leadership.
CISO & Security Leadership
Chief Information Security Officers, VP/Director of Security — technical credibility plus board-level communication.
Penetration Testers
Offensive security specialists — web, API, network, cloud, red team. Vetted on real exploitation skill, not certifications alone.
SOC Analysts & Threat Hunters
Detection and response talent — SIEM, EDR, threat hunting, and incident triage across all tiers.
Security Architects & Engineers
Cloud security, DevSecOps, network and application security engineering — the people who build the defences.
GRC & Compliance
Governance, risk and compliance analysts — ISO 27001, SOC 2, PCI DSS, and audit-readiness specialists.
Incident Response
DFIR specialists and IR leads — the people you want calm and capable when something is on fire.
// how it works
A four-step, practitioner-led process
Role scoping
We define what the role actually needs — real technical requirements, not a copy-pasted job description of buzzwords.
Sourcing
Reaching the right candidates, including passive professionals who are not scrolling job boards but are open to the right role.
Technical vetting
Scenario-based assessment of real skill — can they actually run the test, hunt the threat, design the control? Judged by a practitioner.
Shortlist & support
You meet only genuinely qualified candidates, with an honest assessment of each — strengths, gaps, and fit.
// why practitioner-led
Vetted by someone who does the work
Most recruiters match keywords on a CV. They cannot tell a real penetration tester from someone who memorised the vocabulary. I can — because it is my own trade.
| Capability | Practitioner-led (me) | Generic IT recruiter |
|---|---|---|
| Judges real technical skill | Yes — hands-on assessment | Keyword / CV match |
| Understands security roles | Lived the work | Surface familiarity |
| Spots buzzword bluffing | Immediately | Often missed |
| Scenario-based vetting | Real attack paths | Rarely |
| Honest candidate assessment | Strengths + gaps | Sell the placement |
// ways to engage
Flexible engagement models
Technical vetting only
// you source, I assess
- You bring candidates, I run the technical assessment
- Scenario-based skills evaluation
- Honest written assessment of each candidate
- Ideal if you have applicants but cannot judge skill
Source & vet
// end-to-end shortlist
- I define the role, source, and vet candidates
- Access to passive security professionals
- You meet only qualified, assessed people
- Honest shortlist with strengths and gaps
Team build advisory
// build a function
- Designing a security team from scratch
- Role sequencing — who to hire first and why
- Structure, seniority, and reporting lines
- Ideal for scaling companies building security
Building or hiring for a security team?
Whether you need one vetted specialist or a whole function designed, let us talk about what you actually need — and how to hire people who can do the job.