Offensive Security

Umanhonlen Gabriel

You are the strength behind the system.

70+Security Audits Delivered
98%Client Success Rate
10+Enterprise Clients
24/7Support & Retesting

Hall of Fame

How it works

Click a stage to see the metrics and what it delivers

Every engagement follows the same cycle — define the scope, test it, validate the findings, and confirm the fixes. Select each stage to see its numbers.

Audit activity

Engagements delivered per year, 2021 — 2025.

70+Audits delivered
10+Enterprise clients
24/7Support & retesting

Service distribution

Share of work by service line under active testing.

40%Penetration testing
22%Secure code review
15%Vulnerability management

Findings by severity

Distribution across all completed engagements.

12Critical
34High
58Medium
41Low

Remediation trend

Vulnerabilities resolved per audit, rolling average.

98%Client success rate
FreeUnlimited retesting
100%Validated fixes
Services

Take advantage of every edge

Comprehensive offensive security solutions, ordered by attack surface — from deep testing to continuous management.

01

Penetration Testing

Simulate real-world attacks to identify and exploit vulnerabilities before malicious actors do.

$300 — $10,000
  • Web application testing
  • Mobile application testing
  • API security assessment
  • Network & cloud infrastructure testing
Book this service
02

Secure Code Review

Comprehensive source-level analysis to identify security flaws before they ship into production.

$300 — $10,000
  • Manual code analysis
  • SAST and SCA integration
  • Secure coding practices
  • Developer training
Book a quote
03

Vulnerability Management

Continuous identification, assessment and remediation guidance across your infrastructure.

$300 — $10,000
  • Vulnerability scanning
  • Risk prioritization
  • Remediation guidance
  • Ongoing monitoring
Book a quote
04

Training & Mentorship

Personalized guidance across the offensive security stack with practical exercises and feedback.

$500 — $5,000
  • Hands-on labs: web, mobile, API, network
  • Career roadmaps and milestones
  • Real-world project reviews
  • Interview prep & portfolio coaching
Book a session
05

Consultation & Advisory

Quick expert advice on strategy, tooling, triage and stakeholder buy-in.

$50 / hour
  • Strategy and roadmap review
  • Tooling and architecture advice
  • Triage of internal findings
  • Team escalation support
Schedule on Calendly
How it works

A calm path from scope to remediation

Every engagement follows the same cycle — define the scope, test it, validate the findings, and confirm the fixes.

01

Scope & goals

Clear scope, timelines and rules of engagement defined up front.

02

Launch

Reconnaissance and threat-driven testing begin against defined targets.

03

Identify

Findings are validated, deduplicated and prioritized by real business risk.

04

Remediate

Guided fixes with unlimited free retesting until every finding is resolved.

Research & publications

Published analysis on real security pressure points

Peer-reviewed papers and industry press coverage on cybercrime, privacy and AI security.

Research paper

The Impact of Bitcoin Cybercrime on the Financial System

Analyzing the role of crypto mining and criminological behavioral threats. IRE Journals.

Read the paper
Research paper

Research Paper II

Second peer-reviewed research contribution, IRE Journals.

Read the paper
Press

The privacy implications of accepting website cookies

Businessday NG — Technology. Analysis on consumer data exposure.

Read the article
Press

New NIN-linked credit system sparks promise and concern

Businessday NG — article on identity-linked credit risk in Nigeria.

Read the article
Press

AI integrity at stake as advanced models reshape cybersecurity

Businessday NG — article on offensive and defensive AI capability.

Read the article
Press

Cyberattacks expose the fragility of Nigeria's digital economy

Businessday NG — article on rising threats to digital growth.

Read the article

Professional certifications

Verified credentials on Credly — a global open badge platform.

View on Credly

Global recognition & award

Industry recognition for security research and responsible disclosure work.

View recognition
FAQ

Clear answers for common questions

100% hands-on. Engagements simulate real attack paths against your live environment — no slide decks, no surface-level checks. Every finding includes a working proof of concept.

Independent consultants work directly with you — no account managers, no ticket queues. You speak to the engineer who found the issue, and retesting is free and unlimited.

Yes. Every engagement includes guided remediation and free retesting until all findings are resolved — the retest is validated before you sign off.

Yes. Mentorship covers hands-on labs across web, mobile, API and network security — with roadmaps, review and interview preparation for any level.

Findings are documented with severity, impact, reproduction steps and remediation guidance in a clear executive-and-technical report. Full confidentiality is guaranteed.

Contact

Schedule a consultation

Tell me about your scope on a quick call — I will respond with a quote and a plan within 24 hours.

Book your free 15-minute consultation

A quick discovery call to understand your scope, stack and timeline — no commitment, no pressure.

Response time Within 24 hours, Monday–Friday
Community
Join the free cybersecurity community — applications always open.
Join now
Umanhonlen Gabriel
About

Umanhonlen Gabriel

Professional penetration testing and offensive security services.

I am a cybersecurity professional and security researcher who believes in turning seemingly impossible challenges into reality through strategic thinking, innovation, and collaboration.

My professional experience spans banking, fraud monitoring, application security, cybersecurity research, governance, risk and compliance, and cybersecurity resilience. I currently work as an independent security researcher and cybersecurity professional, conducting security research, vulnerability assessments, penetration testing, and responsible disclosure engagements. My work focuses on identifying security weaknesses, demonstrating their real-world impact, and helping organizations understand and address risks before they can be exploited.

My professional journey began in the banking sector, where I worked with one of Nigeria's recognized banks as a Fraud Risk Supervisor. In this role, I led a team of 15 professionals responsible for monitoring, investigating, and responding to potentially fraudulent transactions. This experience gave me a strong foundation in fraud detection, risk management, incident handling, operational controls, and team leadership, while also providing valuable insight into the security challenges faced by financial institutions.

I later progressed into application security as a Senior Application Security Engineer, where I worked across different stages of the application lifecycle, including security testing, pilot stages, and production deployment. I worked closely with developers and technology teams to identify and remediate security vulnerabilities, integrate security into development processes, and strengthen application security controls. My responsibilities also included managing and securing API services, conducting security assessments, supporting remediation efforts, and providing security guidance to development and engineering teams.

My experience extends beyond technical security into Governance, Risk, and Compliance (GRC). I have contributed to security risk assessments, control implementation, compliance requirements, security governance, and the alignment of technical security practices with organizational risk objectives. I understand the importance of connecting technical security findings with business risk and ensuring that security decisions support broader organizational objectives.

I have also worked closely with the Chief Information Security Officer (CISO) and senior management on cybersecurity resilience initiatives. This has included preparing and delivering presentations on cybersecurity resilience, security risks, emerging threats, and organizational security priorities. I believe effective cybersecurity requires more than identifying vulnerabilities. It requires communicating risk clearly to decision makers and helping organizations make informed decisions that strengthen their overall security posture and resilience.

In my current capacity as an independent security researcher, I continue to work with organizations of different sizes, from startups to enterprise platforms, across penetration testing, security research, code review, vulnerability management, and Al governance and responsible disclosure. I approach security from an adversarial perspective, looking beyond what automated scanners can identify. I focus on discovering vulnerabilities that require deeper analysis, demonstrating their practical impact through working exploits where appropriate, and working with organizations to achieve effective and lasting remediation.

With more than 70 security audits completed and a 98% client success rate, my work is measured by tangible outcomes: vulnerabilities identified, responsibly disclosed, remediated, and verified. Beyond individual engagements, I collaborate with security triage teams through responsible disclosure programs, communicating findings clearly, contributing to severity and impact assessments, and supporting the validation and remediation process. I believe a security report is only as valuable as the improvement it drives.

My security research has been published in peer-reviewed journals and national press, and my findings have been recognized on public Hall of Fame lists maintained by organizations including Microsoft, Zetes, GBTwente, SweetHawk, and others. These recognitions reflect my commitment to responsible security research and to helping organizations identify and address vulnerabilities before they can be exploited by malicious actors.

Beyond my professional work and research, I actively contribute to cybersecurity forums and communities through knowledge sharing, technical discussions, research, mentorship, and collaboration. I also manage and lead Cyber Odyssey, a cybersecurity community focused on bringing security professionals, researchers, students, and aspiring practitioners together to learn, collaborate, and grow.

Through Cyber Odyssey, I facilitate discussions, share practical security knowledge and resources, encourage research and knowledge exchange, and create opportunities for members to develop their technical and professional skills. I am particularly passionate about helping aspiring cybersecurity professionals gain practical experience and access to knowledge that can help them progress in the field.

I also mentor the next generation of cybersecurity talent through free training, hands-on labs, practical guidance, and community initiatives. I believe cybersecurity becomes stronger when knowledge is shared, experienced professionals support emerging talent, and organizations and individuals work together to build a more resilient digital ecosystem.

01

Responsible disclosure

Acknowledged on public Hall of Fame — Microsoft, Zetes and GBTwente — for reported and guided remediation of real vulnerabilities.

02

Published research

Peer-reviewed papers in IRE Journals and analyses in Businessday NG on cybercrime, privacy and AI security.

03

Community-first

Building a free cybersecurity community and mentoring the next generation of offensive security researchers.

04

Proven results

70+ security audits, a 98% client success rate, and enterprise clients across the world delivered remotely.

Testimonials

What clients & students say

T
Tosin Mentorship student — bug bounty hunter

I started as a complete beginner in Gabriel's mentorship program. Months later I earned my first real bug bounty — the training was hands-on, practical, and personal.

Coolidge Solutions logoCS
Coolidge Solutions Canadian company — penetration testing client

Gabriel found critical vulnerabilities our previous vendor missed. Clear reports, fast retesting, and real business context in every finding.

Klick-Tipp logoK
Klick-Tipp Security Team Security team — responsible disclosure response

This is in no way a reflection on the quality of your work. Your report was clear, well-structured and carried out responsibly within the limits of our policy — we appreciate the care you took in documenting it.