Pentesting · Compliance · Security Engineering
18+ years in IT security. I build the tools I use. Every finding goes through human review. No boilerplate. No offshore teams. Just results.
What I do
Consulting delivered as a solo operator. No layers, no account managers — you talk directly to the person doing the work.
Open Source
Public tools born from real engagements. I use them on every assessment.
Published Work
TerraGoat is the industry-standard intentionally-vulnerable Terraform repository, widely used to test IaC security scanners. I ran it through a multi-scanner pipeline and documented what falls through the cracks — including cryptographic exposures that no standard scanner classifies today.
The gap matrix methodology is now part of every IaC engagement I run.
Read the Research →Solo operator
Mike Martínez Oroz — Founder & Security Specialist, MK ScorpioSec.
18+ years in IT security. I don't run a company with account managers and subcontractors. When you hire MK ScorpioSec, you work directly with me — the person writing the code, running the scans, and reviewing every finding.
I build the tools I use. pq-audit and the IaC research pipeline weren't academic exercises — they came out of real engagements where existing tools left gaps I couldn't accept.
Every assessment applies Privacy-by-Design from the start: client data stays in controlled local environments and never moves to cloud infrastructure without explicit anonymization.
"I don't hunt threats. I am the threat."
Get in touch
Ready to discuss an engagement? No sales funnel, no intake form that goes nowhere.
Opens your email client · No data collected server-side