Forcent DevSecOps

Security & infrastructure consultancy · Romania · EU · UK · US · UAE

Infrastructure and security work that goes all the way down.

Independent since 2018. DevSecOps, cloud and infrastructure architecture, penetration testing and technical recruitment — for banks, government, healthcare and technology companies across Europe and the US. The person who scopes your work is the person who does it.

Where we operate
PERIMETER Penetration testing PLATFORM Cloud & infrastructure PIPELINE DevSecOps PEOPLE Technical recruitment
2018Independent since
10+ yearsBuilding and breaking
OSCP · CRESTCertified testing
EU · UK · USBanking, gov, health

Practices

Four things, done properly.

We'd rather be the right answer for a narrow set of problems than a plausible answer for all of them.

Perimeter

Penetration testing

Manual, scoped testing of applications, networks and cloud estates. Findings come ranked by what an attacker would realistically do next, with reproduction steps and a fix — not a scanner export with the severity column sorted.

  • Web application & API testing
  • Internal and external network
  • Cloud configuration review
  • Incident response & forensics
Read more

Platform

Cloud & infrastructure architecture

The platform underneath your product: network segmentation, identity and trust boundaries, infrastructure as code, and migrations planned so the cutover isn't the risky part.

  • Architecture & migration planning
  • Network segmentation
  • Infrastructure as code
  • Hardening & baseline review
Read more

Pipeline

DevSecOps

Security controls that live inside the pipeline instead of blocking it at the end. Scanning wired into CI with policy that fails builds on real findings and stays quiet the rest of the time, so developers keep trusting it.

  • CI/CD pipeline hardening
  • Secrets management
  • Supply chain & dependency scanning
  • Policy as code
Read more

People

Technical recruitment

Hiring support from people who can read the code. We screen for engineers in the same fields we work in, so the shortlist is short and your technical interview isn't the first real filter.

  • Sourcing & technical screening
  • Assessment design
  • Contract and permanent
  • Team scale-up
Read more

Approach

How an engagement runs.

01

Scoping

We work through what needs doing and why, directly with the people who own the system. Fast, and without a discovery phase you pay for separately.

02

Planning

Resources, milestones and the business objective, written down and agreed before anyone starts building or testing.

03

Execution

The consultant who scoped it does the work. Tailor-made tooling, a platform build, or a full assessment of your security posture — same people throughout.

04

Handover

You get the artifacts: documentation, runbooks and the reasoning behind each decision, so your team can carry it forward without us.

Why a small firm

Small on purpose.

No account layer

You talk to the engineers. The person who scopes your project is the person who delivers it, and they stay reachable after handover.

Range across the stack

Consultants working across development, infrastructure and offensive security, so a problem doesn't get handed off at the boundary between them — which is usually exactly where it lives.

Comfortable in unfamiliar territory

New ideas turned into something scalable, and legacy systems brought forward without a rewrite you can't justify.

Finance Regulated environments, audit evidence
Healthcare Sensitive data, strict access boundaries
Retail Public-facing scale, payment paths
Public sector Procurement-friendly, documented

Contact

Tell us what's on fire.

Or what isn't yet. Scoping conversations are free and usually short — we'll tell you quickly if we're not the right fit.

Direct contact@forcent.io
Forcent · Romania

We use what you send here to reply to you, nothing else. No newsletter, no CRM, no third-party form vendor.