Blog Framework Contact Us
OSCP+ CPTS GWAPT PNPT CRTP
Core technical team

The senior penetration testers behind every ClarenSec Engagement

Penetration testing is manual work. The people doing it matter more than the logo on the cover, so this page deals in what can be checked: the certifications the team holds and how your engagement gets staffed.

Who actually does the testing

ClarenSec's testing is delivered by a core team of senior penetration testers, working across Nigeria and West Africa. Banking and finance, capital markets, fintech, healthcare, government, telecom: the team has tested in all of them. Internet banking, trading platforms, hospital systems, government portals.

A certificate confirms that an exam was passed, not who turns up to your engagement. At ClarenSec, a senior tester leads each engagement from the scoping call to the retest report, and that person is named in your proposal alongside their CV and the certifications they hold, and you get to meet them before you sign up for the pentest.

Illustration of a security team working together on laptops, the ClarenSec penetration testing team

Certifications held across the team

We weight certifications that are examined hands-on, against live machines and under time pressure, over classroom ones. As at July 2026, the team holds:

01

Offensive security and red team

Network, infrastructure and objective-driven testing

The exam formats behind these are practical: compromise the environment or fail. This group covers external and internal network testing, Active Directory attack paths, and the red team work we run against agreed objectives.

OSCP+ (OffSec) OSCP (OffSec) OSEP (OffSec) CPTS (Hack The Box) PNPT (TCM Security) CRTP (Altered Security) CompTIA PenTest+ CCRTA (Cyberwarfare Labs) HTB Offshore ProLab eJPTv2 (INE) CNSP (The SecOps Group)
02

Application, API and mobile security

Web, API and mobile testing to OWASP standards

Web, API and mobile credentials.

GWAPT (GIAC) CBBH (Hack The Box) CEH Practical (EC-Council) API Security Architect (API Academy) API Penetration Testing (APISec University) ASCP CASP CAP PT1 (TryHackMe) CompTIA Security+
03

Standards and incident response

Management systems and what happens after a breach

The assurance side. Incident response experience keeps the remediation guidance grounded in what defenders actually face.

ISO 27001:2013 SentinelOne IR Engineer Certificate CC (ISC2) eJPT (INE)

Work you can check

Independent security research by team members has produced over 10 published CVEs. On the infrastructure side, members of the team have tested central banks, commercial banks and financial regulators in nine countries, including Nigeria, Kenya, Rwanda, Botswana and the United Kingdom.

The tester in your proposal does the work

VAPT engagements in this market are routinely sold based on established names and then delivered by whoever is available. We wrote about the practice, and the questions that expose it, in who actually tests your network. Ask us those same questions.

Put names to your next test

Tell us what you need tested and we will name the testers in the proposal, with the skillset each one brings to your engagement.

Request a Proposal