Hire an ethical hacker who tests your systems by hand, the way a real attacker would.
I'm Marco Candeo, an independent security researcher and penetration tester. I've found more than 100 vulnerabilities across public bug bounty programs and private engagements, and I sit in the top 12 of HackerOne's Brazil leaderboard. When you hire me, I'm the one testing your application, from the scoping call to the final debrief.
Most engagements cover one or two of these. We agree the scope before anything starts, and I don't touch what falls outside it.
Authenticated and unauthenticated testing across each user role you have: broken access control, injection, authentication and session handling, and the business-logic flaws scanners miss. Most of my highest-severity findings come from chaining a small logic gap with an endpoint your team forgot was there.
REST, GraphQL, and WebSocket APIs, tested against the calls your client makes and the ones it doesn't. IDORs, missing authorization checks, mass assignment, and injection paths that the front end filters but the API accepts.
Configuration review of the cloud accounts and services exposed around your application: over-permissive IAM, public storage and admin interfaces, wider network exposure than you need, and secrets I can read from outside.
I reverse-engineer your Android and iOS builds to find hardcoded credentials, deprecated endpoints still live in production, weak certificate pinning, and sensitive data sitting in local storage.
We go through what you've built, what worries you, and what falls in and out of scope. You leave with a fixed price and a date range, not an hourly estimate that drifts.
I spend weeks working through the application by hand. Automated tooling handles recon and coverage, not the testing itself.
You get every finding with a severity rating, reproduction steps, evidence, and a concrete fix. I write it so your engineers can act on it and so you can hand it to a customer asking how you test.
Once your team ships the fixes, I verify each one and update the report. That retest is part of the engagement, not a separate invoice.
I run the scoping call, I test your app, and I run the debrief. No junior tester takes over once you sign.
I cap the client count on purpose. That cap is what buys each client weeks of manual testing instead of a three-day sweep.
I was a software engineer before I did this full time. I read your code the way your team wrote it, which is how I find the flaws that come from how you built the system.
If a tool could have found it alone, I'm not billing you for it. You get findings that took someone sitting down and thinking about your application.
It depends on scope: the size of the application, how many user roles and integrations it has, and whether you want mobile or infrastructure covered. After the scoping call you get a fixed price for the whole engagement, retest included.
Most engagements run two to four weeks of testing plus reporting. I'd rather turn work down than compress a test into a few days. The findings that matter are not the ones you reach in the first afternoon.
A written report with every finding, its severity, reproduction steps, evidence, and a remediation recommendation, plus a debrief call with whoever needs to be on it. After your team ships fixes, I retest and update the report.
Yes. Anything under NDA stays out of my writeups, my videos, and this site. Everything here comes from public bug bounty programs that cleared me to talk after the patch shipped.
Yes, in most cases, with rate limits and a testing window we both sign off on. If your staging environment mirrors production I'll use it, but the interesting bugs live in the real data flows, and staging doesn't carry them.
I write it for a third-party reader: scope, methodology, findings, and retest results are all in it, which covers what most enterprise security questionnaires ask for. I'm not an accredited audit firm, so a formal certification audit still needs a certified assessor. An independent pentest report sits alongside that rather than replacing it.
Yes. I work remotely, in English or Portuguese. Most of the programs I hunt on belong to companies outside Brazil.
Send a rough scope and a timeline. I answer my own email. Expect a reply inside two days.
Start a conversation