⬢ The Penva Security Team · CREST & OSCP Certified

The Penva Security Team Credentials

Penva Security’s penetration testers are CREST CRT, CPSA, CCT, OSCP, OSCE3, and CRTO certified – Australian-based, anonymous-by-policy. We do publish every credential the team holds, all independently verifiable through CREST International, CREST Australia New Zealand, and Offensive Security.

Credential-led team model

Built around trust signals Australian buyers actually verify: CREST credentials, OSCP-level exploitation skill, local jurisdiction, and evidence that procurement and auditors can review.
At-a-glance

Verification snapshot

A compact view of how Penva Security presents trust, credentials and engagement assurance before a project starts.
Verifiable Credentials

The Credentials Penva Security Testers Hold

Every credential below is independently verifiable through the issuing body. We can provide individual certificate numbers during procurement.

Multiple holders

CREST CRT

CRT
CREST CRT CREST Registered Penetration Tester The internationally recognised baseline credential for penetration testing. Required by APRA, Australian Government procurement, and most enterprise security programs. Multiple holders
Multiple holders

CREST CPSA

CPSA
CREST CPSA CREST Practitioner Security Analyst CREST’s foundational credential covering security assessment fundamentals. Often the prerequisite for CRT-level testing engagements. Multiple holders
Senior team

CREST CCT

CCT
CREST CCT CREST Certified Tester Advanced CREST-level certification across CCT App (application security) and CCT Inf (infrastructure security). The senior-tester credential. Senior team
Multiple holders

OSCP

Offensive Security Certified Professional
OSCP Offensive Security Certified Professional A hands-on offensive security certification via Offensive Security’s 24-hour practical exam. Demonstrates real exploitation skill, not just theory. Multiple holders
Senior team

OSCE3

Offensive Security Certified Expert 3
OSCE3 Offensive Security Certified Expert 3 Offensive Security’s expert-level triple-certification (OSWE, OSEP, OSED) covering web exploitation, evasion, and exploit development. Held by senior testers. Senior team
Senior team

CRTO

Certified Red Team Operator
CRTO Certified Red Team Operator Zero-Point Security’s offensive operations certification covering modern red team tradecraft, evasion, and lateral movement. Relevant for adversary-simulation engagements. Senior team
Verifiable credential

GIAC GPEN

GPEN
GIAC GPEN GIAC Penetration Tester GIAC’s penetration testing certification, widely recognised in US enterprise and government environments. Useful for HealthTech and US-adjacent engagements. Where relevant
Verifiable credential

ACSC E8

E8
ACSC E8 Essential Eight Aligned Penva Security testers are aligned to ASD’s Essential Eight maturity model methodology, with deep familiarity for Australian Government supply-chain engagements. Team-wide
Capability Roles

Four Capability Roles

What the team can do, not who individuals are. Each role lists the credential profile of the senior tester filling it.

Capability role

Web & API Security Lead

Senior tester role focused on web application and API security testing. Authorisation, business-logic, IDOR, BOLA, SSRF and the full OWASP WSTG v4.2 / API Security Top 10 coverage.
Capability role

Cloud & Network Security Lead

Senior tester role focused on cloud configuration and network infrastructure testing. IAM weaknesses, exposed storage, metadata abuse, segmentation testing, internal lateral movement.
Capability role

Mobile & AI/LLM Specialist

Specialist tester role covering iOS and Android mobile application testing and AI/LLM-powered systems. OWASP MASVS, OWASP LLM Top 10, FHIR / HL7 integration security.
Capability role

Red Team & Adversary Emulation

Senior offensive operations role for red team engagements, threat-led testing, and adversary emulation. Maps engagements to MITRE ATT&CK TTPs and works with client blue teams on detection-coverage validation.
Proof points

The Team in Numbers

What we can publish about team composition – and what we won’t.

100%
Australian-based testers
30+
Combined years of pentest experience
14+
Industry credentials held
100%

Skills Level

How We Operate

Five Principles Behind the Team Model

How Penva Security’s anonymous-by-policy team model actually works in practice. None of this is hidden from clients – it’s just not published openly.

01

Testers Are Anonymous By Policy

We don’t publish individual tester names, photos, or LinkedIn profiles. Penetration testers face real targeting risks – attackers research named testers to bypass their detection patterns. Some clients prefer anonymous engagement teams for confidentiality reasons. Our team identity is the collective credential set, not individual public profiles.
02

Credentials Are Independently Verifiable

Every CREST credential held by Penva Security testers is independently verifiable through CREST International or CREST Australia New Zealand – by request to either body, or to Penva Security directly. OSCP credentials are similarly verifiable through Offensive Security’s verification system. We can provide credential verification documentation under NDA during procurement.
03

Same Testers, Multiple Engagements

Penva Security’s small team size means continuity across engagements. Unlike crowdsourced PTaaS platforms where you may get different testers each engagement, Penva Security clients typically work with the same one-to-three-person tester team across their annual pentests. Continuity matters for context, finding-quality, and the kind of partnership-driven relationship most clients prefer.
04

Tester Allocation Is Disclosed in Scoping

During the scoping call, we disclose which capability roles will be involved in your engagement. For a web app + API + cloud scope, that’s typically the Web/API lead and the Cloud lead working together. For a multi-product FinTech engagement, it may include three or four roles. You’ll know the credentials of every tester on your engagement before contract signing – you just won’t know their names.
05

Named Testers Available on Request

For specific compliance requirements (some APRA tripartite reviews, some IRAP assessments) that require named tester attestation, we will provide named tester information under NDA. This is the exception, not the default – and we’ll ask whether your compliance regime actually requires named attestation before invoking the exception.
FAQ

The Team — Common Questions

Direct answers to the questions buyers ask about Penva Security’s anonymous-team model. Updated May 2026.

How do I know your team is real and credentialled?

Every CREST credential held by Penva Security testers is independently verifiable through CREST International or CREST Australia New Zealand. We can provide credential verification documentation during procurement – including individual CREST certificate numbers, OSCP / OSCE3 verification codes, and ABN-linked corporate registration as a CREST-aligned firm. The collective credentials shown on this page are real and verifiable; we just don’t publish the individuals.

How big is the Penva Security team?

Small, by design. We’re a boutique penetration testing specialist – smaller than a Big-4 enterprise security practice, larger than a one-person consultancy. The exact size we don’t publish, but you can expect tester continuity across your engagements rather than a rotating pool. Tester allocation for your specific engagement is disclosed during scoping.

Will the same testers do our annual retest?

Wherever possible, yes. Penva Security’s small-team model means tester continuity across engagements. The team that delivers your annual pentest is typically the team that delivers the free retest 60 days later, and the team that delivers your next annual engagement. Continuity helps – testers build context about your application across engagements, which makes subsequent testing more efficient and more thorough.

Can I request a specific tester I worked with previously?

Yes, where scheduling allows. If you’ve worked with a specific Penva Security tester before and you’re booking a follow-up engagement, mention it in the scoping call. We’ll prioritise the same tester team where possible. We also work the other direction – if you want a fresh perspective on a system the previous tester team has tested before, we can deliberately rotate testers for a different set of eyes.

What's the most senior credential anyone on the team holds?

The senior-tester credentials on the team include CREST CCT (Certified Tester), OSCE3 (Offensive Security’s expert triple-cert covering web exploitation, evasion, and exploit development), and CRTO (Certified Red Team Operator). These are held by the senior tester roles – Web/API lead, Cloud/Network lead, Red Team lead. Junior testers are typically OSCP and CREST CPSA, working alongside the senior testers.

Do you outsource any work to other testers or partners?

No. Every Penva Security engagement is delivered by Penva Security’s in-house Australian-based tester team. We don’t outsource to contractor pools, offshore labour, or crowdsourced platforms. This is the same answer for every engagement type and every client size – it’s a structural choice, not a premium tier. If your scope requires a specialist we don’t have in-house (e.g., specific hardware security work), we’ll tell you directly and recommend a credible partner rather than pretend we cover it ourselves.

Can we meet the team before signing?

Yes – during the scoping call you’ll meet at least one senior tester from the capability area relevant to your engagement (Web/API lead, Cloud lead, etc.). 

Are you hiring? How do testers join Penva Security?

We’re always open to conversations with CREST-certified or OSCP-certified Australian pentesters interested in joining a boutique firm. The bar is high: we look for CREST CRT minimum, with OSCP-level practical exploitation skill, plus a demonstrable track record of human-led testing (not scanner-led ‘pentesting’). Reach out via [email protected].

Next step

Want to Meet the Team Under NDA?

Book a free 30-minute scoping call. You’ll meet the capability lead for your engagement, see their credentials, and (under NDA) verify their identity. Fixed-price quote within 24 hours.

Want to Meet the Team Under NDA?

Book a free 30-minute scoping call. You’ll meet the capability lead for your engagement, see their credentials, and (under NDA) verify their identity. Fixed-price quote within 24 hours.