Skip to content
Client access

Company

About us

Offensive security from Lima: certified pentesters, international frameworks and knowledge of the Peruvian context.

Who we are

A Peruvian consultancy specialized in offensive security

Kamaya Secure was founded in Lima on one conviction: the best way to protect an organization is to know how a real adversary would attack it. That is why our work starts with offensive security.

We are a team of certified penetration testers combining international technical expertise with first-hand knowledge of Peruvian regulation and operating context. We work with mining companies, financial institutions, fintechs and public entities.

Every engagement is carried out with formal authorization, clear rules and full confidentiality, and ends with concrete evidence your team can use to decide, remediate and comply.

Our values

Certified. Ethical. Rigorous. Trusted.

Four principles that guide every assessment, every report and every conversation with our clients.

Certified

Our consultants back their expertise with hands-on certifications that require compromising real systems, not just passing theory exams.

Ethical

We only act with authorization and within the agreed scope. We report the vulnerabilities we find through responsible disclosure.

Rigorous

Every finding is documented with reproducible evidence, prioritized by real impact and mapped to recognized frameworks such as MITRE ATT&CK.

Trusted

We protect our clients’ information with non-disclosure agreements, secure data handling and transparent communication.

Why Kamaya

Offensive expertise with local backing

01

Certified pentesters

A team holding certifications such as OSCP, OSCP+, CRTP, eCPPT, eWPTX, eWPT, eMAPT and eJPT.

02

Research community

We have our own community of security researchers for bug bounty programs and specialized testing.

03

Responsible disclosure

Our consultants have reported vulnerabilities to Peruvian and international organizations following responsible disclosure practices.

04

Public sector supplier

We are registered with Peru’s National Registry of Suppliers (RNP) and have worked directly with public entities such as the Universidad Nacional de Ingeniería.

05

Local presence

From Lima, in your language and time zone, with on-site capability, including remote operations.

06

From assessment to solution

Beyond assessing, we can supply and implement the technology your organization needs to close the gaps.

Certifications

A team certified in offensive security

Hands-on certifications held by our consultants, issued by OffSec, Altered Security and INE Security.

  • OSCP — OffSec Certified Professional (OffSec)
  • OSCP+ — OffSec Certified Professional Plus (OffSec)
  • CRTP — Certified Red Team Professional (Altered Security)
  • eWPTXv2 — Web Application Penetration Tester eXtreme (INE Security)
  • eCPPTv2 — Certified Professional Penetration Tester (INE Security)
  • eWPT — Web Application Penetration Tester (INE Security)
  • eMAPT — Mobile Application Penetration Tester (INE Security)
  • eJPT — Junior Penetration Tester (INE Security)

Responsible disclosure

Organizations our consultants have reported vulnerabilities to

Vulnerabilities reported by our consultants through responsible disclosure. Trademarks belong to their respective owners; their mention does not imply a commercial relationship or endorsement.

Our team

The team that attacks to protect

Pentesters, researchers and engineers who design, run and validate every assessment and every Kynapt finding.

  • Alejandro Manuel Vega Vásquez

    Alejandro Manuel Vega Vásquez

    Managing Partner · Head of Offensive Security

    Managing partner at Kamaya Secure and head of offensive security. He leads the technical relationship with clients in mining, banking and the public sector, aligning every pentest and Red Team exercise with the business. Telecommunications Engineer (UNI).

  • Percy Jayo

    Percy Jayo

    CTO

    As CTO, he leads Kamaya Secure’s technical area. He is a bug hunter and penetration tester with experience finding vulnerabilities in real-world environments. He speaks at academic events on offensive techniques such as data exfiltration over DNS.

  • Paulo Puicón Gallardo

    Paulo Puicón Gallardo

    Project Director

    As project director, he coordinates the planning and execution of every assessment, from scoping to the delivery of results. He is the client’s point of contact throughout the engagement and oversees timelines and the quality of deliverables.

  • Jesús Arturo Espinoza Soto

    Jesús Arturo Espinoza Soto

    Senior Penetration Tester · Associate Consultant

    Penetration tester with over 7 years of experience in web, mobile and infrastructure assessments, recognized in responsible disclosure programs. Certified OSCP, CEH, eCPPTv2, CREST CPSA and Burp Suite Certified Practitioner. Master’s in Cybersecurity.

Let’s define the right scope for your organization

Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.

Chat on WhatsApp (opens in a new tab)