I am an OSCP+ and CEH certified Professional Penetration Tester specializing in Web Application, API, Mobile Application, and Infrastructure Security Testing.
Over the last years, I have completed more than 600 penetration tests and security assessments for clients across finance, SaaS, healthcare, e-commerce, and enterprise environments. My main focus is helping companies identify real security risks before attackers do, with clear evidence, practical remediation guidance, and professional reports suitable for compliance, audit, and internal security teams.
Core services I provide:
• Web Application Penetration Testing
• API Security Testing
• Mobile Application Penetration Testing for Android and iOS
• SOC 2, ISO 27001, PCI DSS, AMAZON SP and Compliance-Oriented Penetration Test Reports
• OWASP Top 10 Security Testing
• OWASP WSTG-Based Assessments
• Vulnerability Assessment and Security Hardening
• Retesting and Remediation Validation
I perform Black Box, Gray Box, and White Box penetration testing depending on the client’s needs. My reports are structured, professional, and easy to understand by both technical teams and management. Each finding includes clear evidence, risk rating, business impact, CVSS scoring where applicable, and actionable remediation steps.
Clients usually hire me when they need:
• A professional penetration test before a product launch
• A security report for SOC 2, ISO 27001, PCI DSS, AMAZON SP vendor review, or investor due diligence
• Web, API, or mobile app testing by an experienced OSCP-certified tester
• A practical security assessment focused on real exploitability, not only scanner output
• Fast communication, clear reporting, and reliable retesting after fixes
My goal is not only to find vulnerabilities, but to help your team understand, prioritize, and fix them properly.
Sample penetration testing reports can be provided upon request.
Florjan L. earns an estimated $7.2k/mo. That's 5.2× the typical freelancer and more than 99.75% of everyone we track.