KobReySec Logo

Built by Testers.
Run by Testers.

KobReySec was built around a simple idea: clients should work directly with experienced security professionals who understand the work from start to finish. The people you speak with are the people doing the testing, from scoping through reporting and follow-up.

Real People You know who is doing the work.
Real Experience Experienced owners perform the testing.
Direct Access Work with the people performing the assessment.
KobReySec founders Eric Kobelski and Randy Duprey
Why KobReySec Exists

Security Testing Without the Layers

KobReySec grew out of two different sides of technology. Application development and architecture on one side, infrastructure and systems on the other.

That combination gives us a practical perspective on security. We understand how systems are built, how they fail, and how weaknesses in one part of an environment can affect another.

We also spent enough time around technology and security engagements to know that technical ability is only part of what makes an assessment useful. The way the work is delivered matters too.

Direct Access

Keep the Work Close to the Tester

No oversized project teams. No tester hidden behind an account manager. No assessment treated like a checklist.

Experienced testers stay involved throughout the engagement, keeping questions close to the source and important context intact.

Understand the Why

Testing Is Expensive. It Should Leave You Better Informed.

We’re not interested in dropping a report over the wall and disappearing. We explain how findings were discovered, why they matter, and the reasoning behind our remediation guidance so you understand both what to fix and why it matters.

Built to Be Useful

No Form. No Registration Wall.

We build things to be used. That applies to the tools and resources we publish here, and to the reports we deliver after an engagement. No gated downloads, required calls, or follow-up campaigns just because you wanted to learn something or use a tool.

Browse Security Resources
The People Behind KobReySec
Eric Kobelski

Eric Kobelski

Founder | Offensive Application Engineer

Eric brings more than 20 years of experience across software development, information technology, application architecture, and eCommerce, along with years of focused application security and penetration testing.

Before moving fully into offensive security, he spent more than a decade working in eCommerce, where his responsibilities included software development, database administration, infrastructure architecture, and payment systems. That background gives him a practical understanding of how applications are designed, how developers think, and where security weaknesses tend to emerge.

Today, Eric focuses primarily on web application and API penetration testing, business logic testing, source-assisted analysis, and complex application security issues. His approach combines an attacker’s perspective with the experience of someone who spent years building and supporting the same types of systems he now tests.

Web ApplicationsAPIsBusiness LogicSource Review

Outside of security, Eric is usually cooking something, working on a project, or finding something to put together, take apart, or tinker with.

Randy Duprey

Randy Duprey

Founder | Offensive Infrastructure Engineer

Randy brings decades of experience across infrastructure, information technology, and security, including a 20-year military career and more than 15 years of hands-on infrastructure penetration testing.

His work focuses on external and internal network penetration testing, credential attacks, privilege escalation, lateral movement, wireless security, and infrastructure assessment.

Randy also brings extensive experience working directly with clients to help them understand not only what was vulnerable, but why it mattered and what should be done about it. His approach is methodical, practical, and focused on making technical findings useful.

ExternalInternalWirelessInfrastructure

Outside of work, Randy spends much of his time with his family and at the hockey rink.

Why Small Works

Small by Design

KobReySec is intentionally small. That allows us to stay close to each engagement, keep communication simple, and focus on the quality of the work instead of the volume of projects moving through a pipeline.

No Outsourced Testing

The people representing KobReySec are the people performing the work. We do not subcontract assessments to third-party testing teams.

No Junior Tester Handoff

Client environments are not training grounds. Testing is performed directly by KobReySec’s experienced owners, not handed off after the sale to someone still learning the ropes.

Direct Access

Clients can reach the person who performed the work when questions come up. That makes technical conversations faster and keeps important context intact.

Depth Over Volume

We are not trying to process as many engagements as possible. We would rather spend the time needed to understand the environment, investigate meaningful issues, and produce results the client can use.

Professional Credentials

Experience First. Credentials Back It Up.

Certifications are not a substitute for hands-on experience, but they provide an independent measure of the technical knowledge behind the work. Our backgrounds span offensive security, application security, infrastructure security, architecture, software development, and information technology.

OffSecOSWEOffSec Web Expert
ISC2CISSPCertified Information Systems Security Professional
GIACGPENGIAC Penetration Tester
GIACGICSPGlobal Industrial Cyber Security Professional
CompTIAPenTest+CompTIA PenTest+
CompTIASecurity+CompTIA Security+
EC-CouncilCEHCertified Ethical Hacker
CompTIASecurityXCompTIA SecurityX (formerly CASP+)

Talk Directly With the People Who Do the Testing

Have a question about an assessment, scope, or whether KobReySec is the right fit? Start a conversation with the people who would be doing the work.