The Penva Security Team Credentials
Penva Security’s penetration testers are CREST CRT, CPSA, CCT, OSCP, OSCE3, and CRTO certified – Australian-based, anonymous-by-policy. We do publish every credential the team holds, all independently verifiable through CREST International, CREST Australia New Zealand, and Offensive Security.
Credential-led team model
- ✓ All Australian-Based
- ✓ CREST-Verifiable
- ✓ More than 5 years of Experience
Verification snapshot
The Credentials Penva Security Testers Hold
Every credential below is independently verifiable through the issuing body. We can provide individual certificate numbers during procurement.
CREST CRT
CREST CPSA
CREST CCT
OSCP
OSCE3
CRTO
GIAC GPEN
ACSC E8
Four Capability Roles
What the team can do, not who individuals are. Each role lists the credential profile of the senior tester filling it.
Web & API Security Lead
- CREST CRT
- OSCP
- OSCE3
Cloud & Network Security Lead
- CREST CRT
- CREST CCT Inf
- OSCP
- AWS Certified Security
Mobile & AI/LLM Specialist
- CREST CRT
- OSCP
- CRTO
Red Team & Adversary Emulation
- CREST CCT
- CRTO
- OSCE3
The Team in Numbers
What we can publish about team composition – and what we won’t.
Skills Level
Five Principles Behind the Team Model
How Penva Security’s anonymous-by-policy team model actually works in practice. None of this is hidden from clients – it’s just not published openly.
Testers Are Anonymous By Policy
Credentials Are Independently Verifiable
Same Testers, Multiple Engagements
Tester Allocation Is Disclosed in Scoping
Named Testers Available on Request
The Team — Common Questions
Direct answers to the questions buyers ask about Penva Security’s anonymous-team model. Updated May 2026.
Every CREST credential held by Penva Security testers is independently verifiable through CREST International or CREST Australia New Zealand. We can provide credential verification documentation during procurement – including individual CREST certificate numbers, OSCP / OSCE3 verification codes, and ABN-linked corporate registration as a CREST-aligned firm. The collective credentials shown on this page are real and verifiable; we just don’t publish the individuals.
Small, by design. We’re a boutique penetration testing specialist – smaller than a Big-4 enterprise security practice, larger than a one-person consultancy. The exact size we don’t publish, but you can expect tester continuity across your engagements rather than a rotating pool. Tester allocation for your specific engagement is disclosed during scoping.
Wherever possible, yes. Penva Security’s small-team model means tester continuity across engagements. The team that delivers your annual pentest is typically the team that delivers the free retest 60 days later, and the team that delivers your next annual engagement. Continuity helps – testers build context about your application across engagements, which makes subsequent testing more efficient and more thorough.
Yes, where scheduling allows. If you’ve worked with a specific Penva Security tester before and you’re booking a follow-up engagement, mention it in the scoping call. We’ll prioritise the same tester team where possible. We also work the other direction – if you want a fresh perspective on a system the previous tester team has tested before, we can deliberately rotate testers for a different set of eyes.
The senior-tester credentials on the team include CREST CCT (Certified Tester), OSCE3 (Offensive Security’s expert triple-cert covering web exploitation, evasion, and exploit development), and CRTO (Certified Red Team Operator). These are held by the senior tester roles – Web/API lead, Cloud/Network lead, Red Team lead. Junior testers are typically OSCP and CREST CPSA, working alongside the senior testers.
No. Every Penva Security engagement is delivered by Penva Security’s in-house Australian-based tester team. We don’t outsource to contractor pools, offshore labour, or crowdsourced platforms. This is the same answer for every engagement type and every client size – it’s a structural choice, not a premium tier. If your scope requires a specialist we don’t have in-house (e.g., specific hardware security work), we’ll tell you directly and recommend a credible partner rather than pretend we cover it ourselves.
Yes – during the scoping call you’ll meet at least one senior tester from the capability area relevant to your engagement (Web/API lead, Cloud lead, etc.).
We’re always open to conversations with CREST-certified or OSCP-certified Australian pentesters interested in joining a boutique firm. The bar is high: we look for CREST CRT minimum, with OSCP-level practical exploitation skill, plus a demonstrable track record of human-led testing (not scanner-led ‘pentesting’). Reach out via [email protected].
Want to Meet the Team Under NDA?
Book a free 30-minute scoping call. You’ll meet the capability lead for your engagement, see their credentials, and (under NDA) verify their identity. Fixed-price quote within 24 hours.