KobReySec Logo

Built by Testers.
Run by Testers.

KobReySec was built around a simple idea: clients should work directly with experienced security professionals who understand the work from start to finish. The people you speak with are the people doing the testing, from scoping through reporting and retesting.

Real People You know who is doing the work.
Real Experience Experienced testers lead every engagement.
Direct Access Work with the people performing the assessment.
KobReySec founders Eric Kobelski and Randy Duprey
Why KobReySec Exists

Security Testing Without the Layers

KobReySec grew out of two different sides of technology. Application development and architecture on one side, infrastructure and systems on the other.

That combination gives us a practical perspective on security. We understand how systems are built, how they fail, and how weaknesses in one part of an environment can affect another.

We also spent enough time around technology and security engagements to know that technical ability is only part of what makes an assessment useful. The way the work is delivered matters too.

Too often, clients meet one person during the sales process, another during scoping, and someone else once testing begins. Questions get routed between teams, context gets lost, and the people making decisions end up several steps removed from the person who performed the work.

No oversized project teams. No tester hidden behind an account manager. No assessment treated like a checklist.

We built KobReySec to work differently. Experienced testers stay involved throughout the engagement, so questions stay close to the source, context is preserved, and communication remains straightforward.

The goal is simple: do technically strong work, communicate clearly, and help clients understand what matters.

The People Behind KobReySec
Eric Kobelski

Eric Kobelski

Founder | Offensive Application Engineer

Eric brings more than 20 years of experience across software development, information technology, application architecture, and eCommerce, along with years of focused application security and penetration testing.

Before moving fully into offensive security, he spent more than a decade working in eCommerce, where his responsibilities included software development, database administration, infrastructure architecture, and payment systems. That background gives him a practical understanding of how applications are designed, how developers think, and where security weaknesses tend to emerge.

Today, Eric focuses primarily on web application and API penetration testing, business logic testing, source-assisted analysis, and complex application security issues. His approach combines an attacker’s perspective with the experience of someone who spent years building and supporting the same types of systems he now tests.

Web ApplicationsAPIsBusiness LogicSource Review

Outside of security, Eric is usually cooking something, working on a project, or finding something to put together, take apart, or tinker with.

Randy Duprey

Randy Duprey

Founder | Offensive Infrastructure Engineer

Randy brings decades of experience across infrastructure, information technology, and security, including a 20-year military career and more than 15 years of hands-on infrastructure penetration testing.

His work focuses on external and internal network penetration testing, credential attacks, privilege escalation, lateral movement, wireless security, and infrastructure assessment.

Randy also brings extensive experience working directly with clients to help them understand not only what was vulnerable, but why it mattered and what should be done about it. His approach is methodical, practical, and focused on making technical findings useful.

ExternalInternalWirelessInfrastructure

Outside of work, Randy spends much of his time with his family and at the hockey rink.

Why Small Works

Small by Design

KobReySec is intentionally small. That allows us to stay close to each engagement, keep communication simple, and focus on the quality of the work instead of the volume of projects moving through a pipeline.

No Outsourced Testing

The people representing KobReySec are the people performing the work. We do not subcontract assessments to third-party testing teams.

No Junior Tester Handoff

Client environments are not training grounds. Engagements are performed by experienced security professionals, not handed off after the sale to someone still learning the ropes.

Direct Access

Clients can reach the person who performed the work when questions come up. That makes technical conversations faster and keeps important context intact.

Depth Over Volume

We are not trying to process as many engagements as possible. We would rather spend the time needed to understand the environment, investigate meaningful issues, and produce results the client can use.

Professional Credentials

Experience First. Credentials Back It Up.

Certifications are not a substitute for hands-on experience, but they provide an independent measure of the technical knowledge behind the work. Our backgrounds span offensive security, application security, infrastructure security, architecture, software development, and information technology.

OffSecOSWEOffSec Web Expert
ISC2CISSPCertified Information Systems Security Professional
GIACGPENGIAC Penetration Tester
GIACGICSPGlobal Industrial Cyber Security Professional
CompTIAPenTest+CompTIA PenTest+
CompTIASecurity+CompTIA Security+
EC-CouncilCEHCertified Ethical Hacker
CompTIASecurityXCompTIA SecurityX (formerly CASP+)

Talk Directly With the People Who Do the Testing

Have a question about an assessment, scope, or whether KobReySec is the right fit? Start a conversation with the people who would be doing the work.