HexCipher Security is an independent penetration testing practice based in Melbourne, Australia — built on hands-on experience across consultancy, in-house, and founder roles, not a large team or a sales pitch.
I've spent the last several years moving between consultancy, in-house, and founder roles in security — which means I've seen how the same finding looks from a client's side, an internal security team's side, and an engineering team's side.
Right now I'm mainly looking to take on overflow and subcontract work for consultancies with more demand than bench capacity — sign an agreement, agree scope and rate, and start quickly, remote-first, with travel available anywhere in Australia if an engagement needs it.
HexCipher Security operates under a PTY LTD, and carries AUD $5,000,000 professional indemnity and liability insurance per claim — that figure can be increased for engagements that require higher cover.
Delivered network, application, and red team assessments across banking, utilities, healthcare, and mining clients.
Led an internal security assessment function, then moved into leading NAB's red team practice.
Delivering contract penetration testing engagements while building out HexCipher Security.
Achieved full domain compromise starting from an internet-facing foothold during a black-box network penetration test.
Gained full domain control during an on-site internal penetration test, connecting directly into onboard network infrastructure.
Some of these were issued several years ago and may be due for renewal — happy to confirm current status for any specific requirement.
Signed agreement, clear scope, and I can start within days — remote-first, with travel available Australia-wide.