Cybersecurity and penetration testing services
Cybersecurity and penetration testing services: penetration tests of web and mobile applications, APIs, networks and cloud accounts, application security and secure code review, cloud security posture, security monitoring and incident response, and the technical side of ISO 27001, SOC 2 and PCI DSS, with dedicated security engineers and penetration testers for your team.
Security services we provide
Web application penetration tests
Authentication, sessions, access control, business logic and injection tested by hand against the OWASP Web Security Testing Guide, with automated scanning as a starting point rather than the result.
Mobile and API penetration tests
iOS and Android apps tested against the OWASP MASVS, and REST, GraphQL and gRPC APIs against the OWASP API Security Top 10: object-level authorisation, mass assignment, rate limits and tokens that outlive their purpose.
Network and Active Directory penetration tests
External perimeter and internal network tests, Active Directory and Entra ID attack paths mapped with BloodHound, Wi-Fi testing, and phishing simulations when you ask for them, each run under written authorisation.
Application security and secure code review
Threat models for new features, manual review of the authentication, authorisation and data-handling code, static analysis in CodeQL or Semgrep tuned until developers trust its findings, and secure-coding training built on the issues found in your own code.
Cloud security posture
AWS, Azure and Google Cloud accounts checked continuously with Security Hub, Defender for Cloud, Security Command Center, Prowler or Wiz for public storage, over-broad roles, long-lived keys and logging that is switched off, with the fixes written as infrastructure as code.
Security monitoring and SOC
Logs from cloud, identity, endpoints and applications collected in Microsoft Sentinel, Splunk, Elastic Security or Wazuh, detection rules mapped to MITRE ATT&CK, EDR on every device, and alerts triaged by analysts on a rota you agree.
Incident response
Containment, evidence preserved for forensics, the root cause found and systems restored from clean backups, then a written report and the detection that would have caught it sooner. Tabletop exercises test the plan before it is needed.
Compliance automation
The technical side of ISO 27001, SOC 2, PCI DSS, HIPAA, NIS2 and DORA: controls built into your systems, evidence collected from them automatically through Vanta, Drata or your own scripts, and access reviews, backups and change control proved from records rather than screenshots.
Hardening
Servers, containers, clusters and laptops brought to CIS Benchmarks and industrial control networks segmented into IEC 62443 zones, with settings applied by code and checked on a schedule so they do not drift back.
Hire security engineers and penetration testers
Dedicated security engineers and penetration testers
Security engineers and penetration testers who join your team full time, work in your tools and process, and report to your lead. You interview them; we carry the Ukrainian contract, payroll, invoicing and leave.
Security engineering projects
A defined piece of security engineering with a scope, a fixed plan and a named lead on our side who owns the result and reports progress in your channels.
Ongoing security engineering
Security engineering as a continuing service: the same people every month, a backlog you prioritise, and hours you can see in our portal and on the invoice.
The dedicated team page explains how specialists join your team, and the outsourcing page covers project delivery, take-overs and how we charge.
Who works on your security engineering
Penetration testers
Web, mobile, API, network and cloud testing
Application security engineers
Secure code review, threat models and pipeline scanning
Cloud security engineers
Posture, identity and fixes as infrastructure as code
SOC analysts and incident responders
Detection, triage and response
Compliance engineers
ISO 27001, SOC 2 and PCI DSS controls and evidence
How we work on security
Every test starts with a written scope: which systems and accounts, which hours, who to call if something breaks, and written authorisation from the owner of each system. Testing runs against staging wherever it can, each finding is reported with its severity, a reproduction and a fix, and a retest after the fixes confirms each one is closed.
Findings are fixed where they live: code changes by developers, cloud and network changes as infrastructure as code, and a regression test or a detection rule for each, so a closed finding stays closed. We hold our own systems to the same standard: our laptops are checked by an agent we wrote in Rust against our security baseline, on Windows, macOS and Ubuntu, with checks mapped to ISO 27001, CIS, Cyber Essentials, Essential Eight and SOC 2.
Other cloud, DevOps and security services
AWS development
AWS development services: EKS and ECS containers, serverless, landing zones, migrations, databases, data platforms, Bedrock generative AI, security and cost optimisation, with dedicated AWS engineers or project delivery.
Google Cloud development
Google Cloud development services: Cloud Run and GKE, BigQuery, Firebase backends, Cloud SQL and AlloyDB, Gemini on Agent Platform, security and migrations, with dedicated Google Cloud engineers or project delivery.
Kubernetes consulting
Kubernetes consulting and development: clusters on EKS, AKS, GKE and on premises, Helm, GitOps with Argo CD or Flux, cluster security, upgrades and GPU workloads, with dedicated Kubernetes engineers or project delivery.
DevOps and CI/CD
DevOps and CI/CD services: pipelines, Terraform infrastructure as code, observability, SRE and on-call, DevSecOps, platform engineering and FinOps, with dedicated DevOps and SRE engineers or ongoing DevOps work.
IT infrastructure
IT infrastructure and system administration services: Windows and Linux servers, networks, Microsoft 365 and Entra ID, virtualisation, backups and telecom, with dedicated system administrators or ongoing support.
Site reliability engineering
Site reliability engineering services: SLOs, OpenTelemetry observability, on-call and incident management, load testing, disaster recovery and chaos engineering, with dedicated SRE engineers or project delivery.
Platform engineering
Platform engineering services: internal developer platforms, Backstage portals, golden paths and templates, self-service infrastructure and Kubernetes platforms, with dedicated platform engineers or project delivery.
Cloud architecture
Cloud architecture and consulting services: designs for AWS, Azure and Google Cloud, migration plans, landing zones, Well-Architected reviews, resilience and cost, with dedicated cloud architects or project delivery.
FinOps
FinOps and cloud cost optimisation services: cost allocation, rightsizing, savings plans and reservations, Kubernetes, data and AI costs, budgets and anomaly alerts, with dedicated FinOps engineers or project delivery.
Terraform and IaC
Terraform and infrastructure as code services: Terraform and OpenTofu modules, imports, plan and apply pipelines, drift control, policy as code and Ansible, with dedicated Terraform engineers or project delivery.
Linux administration
Linux administration services: Ubuntu, Debian, RHEL, Rocky Linux and AlmaLinux servers set up, patched, hardened, monitored and backed up, and end-of-life upgrades, with dedicated Linux administrators or ongoing support.
Network engineering
Network engineering services: routing and switching, firewalls, SD-WAN and zero-trust access, cloud networking, Wi-Fi and automation on Cisco, Juniper and Fortinet, with dedicated network engineers or project delivery.
Cloud security
Cloud security services: CSPM and CNAPP, IAM reviews, Kubernetes security, network and data protection and cloud compliance on AWS, Azure and Google Cloud, with dedicated cloud security engineers or project delivery.
SOC and security monitoring
SOC as a service and security monitoring: managed SOC, SIEM deployment, log onboarding, detection engineering, EDR, threat hunting and incident response retainers, with dedicated SOC analysts or ongoing monitoring.
Security compliance
Security compliance and audit readiness: ISO 27001, SOC 2, GDPR, PCI DSS, HIPAA, NIS2 and DORA controls, gap assessments and audit evidence, with dedicated compliance engineers or a readiness project.
Questions about cybersecurity and penetration testing
Which industries do your security engineers work in?
Mostly cybersecurity product companies, on detection content, product testing and security research; fintech and banking, under PCI DSS and DORA; industrial and energy companies, separating control networks from office IT; e-commerce, protecting checkout and customer accounts; SaaS companies preparing for SOC 2 audits and customer security reviews; and hosting and telecom providers and public-sector systems.
What does a penetration test report contain?
A summary for management, then every finding with its CVSS severity, the affected system, the steps to reproduce it, the evidence and a recommended fix. After your team deploys the fixes, a retest records which findings are closed.
Can you get us ISO 27001 or SOC 2 certified?
Certification is issued by an accredited certification body, and a SOC 2 report by an independent audit firm, so no supplier can promise either. We do the technical side: implement the controls the auditor will test, fix the gaps a readiness review finds, and keep the evidence ready to export.
Will testing disrupt our production systems?
Not by default. Testing runs against staging where one exists. Where production has to be tested, it happens in an agreed window, at an agreed rate, without destructive payloads, and with a named contact on each side.
How quickly can security engineers and penetration testers start?
When the right security engineer is available, the start is gated only by your interview and the NDA and IP assignment. Otherwise we run a search, which typically produces candidate profiles within two to three weeks, and nobody starts until you have said yes.
How do we hire security engineers and penetration testers through BigTree108?
Tell us the work, the seniority and the hours you need. We propose one or two people with their profiles, you interview them the way you would interview your own hire, and you sign one agreement with BIG TREE 108 LLC and receive one invoice a month.
Who owns the work they produce?
You do. Every specialist has a signed contract with BigTree108 that assigns all work product to the company, and our agreement with you assigns it onward. Code, designs and documents are delivered into your own repositories and tools, not kept where only we can change them.
Need a penetration test or security engineers?
Tell us which systems are in scope, where they run and any audit date you are working towards. You get an answer within one business day: a proposed scope, a test plan, or candidate profiles.