Built by operators,
not auditors.
REDOPS Security is a boutique offensive security consultancy registered in Cyprus EU. We do focused, technically deep engagements — and nothing else.
From the trenches.
Asier Barranco is a senior offensive security operator with over 6 years of full-time experience in the field. His background spans Spanish telecom security (Telefónica Tech), boutique consultancies, and international red team engagements.
Currently a Senior Offensive Security Consultant at VerSprite Cybersecurity (USA), with prior tenure as Senior Offensive Security Engineer at Telefónica Tech where he led penetration tests across Active Directory, web applications, cloud (AWS/Azure/GCP), mobile, IoT, and infrastructure assessments.
Specializations include modern Active Directory attack chains, EDR evasion against mature solutions (Sophos, CrowdStrike, SentinelOne), custom shellcode loader development, and web application security at depth.
Verifiable expertise.
Field history.
Red team operations, Active Directory penetration testing, web application security, infrastructure assessments for international clients.
Full-spectrum pentesting across Active Directory, web, API, cloud (Azure/AWS/GCP), mobile, IoT, wireless, and infrastructure. LLM/AI security testing, social engineering campaigns.
Hands-on offensive security training: ethical hacking, penetration testing with Burp Suite, AWS security assessments, OSINT, threat modeling.
Pentesting, web and API audits, vulnerability management, incident response. Both offensive and defensive operations including SOC monitoring.
REDOPS Security Ltd.
EU-registered, Cyprus.
REDOPS Security operates as a clean B2B entity registered in the European Union. All engagements are invoiced through the Cyprus Ltd., with standard MSA + SOW agreements available in English and Spanish.
We work with clients across the EU, UK, USA, and Latin America. NDAs are signed before any technical scope discussion. Standard payment terms are 50% upfront, 50% on delivery.
Serious organizations.
- ▸ SaaS & FintechCompanies with real attack surface and customer data to protect.
- ▸ Regulated industriesFinance, healthcare, energy — compliance + actual security.
- ▸ Mid-market enterprises50–2000 employees with internal IT/security teams.
- ▸ Boutique consultanciesSubcontracting senior capacity for client engagements.
A few things.
- ✗ Automated scan reportsIf a Nessus license can do it, we're not the right vendor.
- ✗ Mass compliance tickboxesWe work with organizations that want depth, not checkboxes.
- ✗ Junior-led engagementsEvery engagement is led by senior operators only.
- ✗ Unethical scopeNo work without proper authorization. No grey-zone engagements.
Want to talk
scope?
Engagements scoped within 48 hours. NDAs signed before technical discussion.
Request Engagement →