About OnSecOps

A specialist security company, led by the person who does the work

OnSecOps is an application security company built on a simple idea — that the best testing is done by senior practitioners, by hand, and explained clearly enough for engineers to fix.

The company

Specialized and senior, by design

Engagements are led by a tester with 8+ years of offensive security experience, holding the OSCP and OSCE certifications and a PhD in Cybersecurity. We deliberately stay specialized and senior: no junior analysts, no outsourced scanning, no account-manager layer between you and the work.

We operate as Oualid Z. — and when you hire OnSecOps, the person you talk to on the scoping call is the person testing your application and writing your report.

Oualid Z.

Founder & Principal Security Tester

OSCPOSCEPhD in Cybersecurity8+ yrs offensive security
How we work

Our philosophy

Manual-first

Real exploitation and chained attack paths — we report what's actually exploitable, not a scanner's raw output.

Developer-friendly

Findings written so your engineers can reproduce, understand the root cause, and ship the fix.

Evidence-driven

Every claim is backed by reproduction steps and proof, and mapped to the compliance control it touches.

Work directly with a senior tester.

Book a 30-minute discovery call to scope the right engagement for your stack.

Book a Discovery Call