Company
About us
Offensive security from Lima: certified pentesters, international frameworks and knowledge of the Peruvian context.
Who we are
A Peruvian consultancy specialized in offensive security
Kamaya Secure was founded in Lima on one conviction: the best way to protect an organization is to know how a real adversary would attack it. That is why our work starts with offensive security.
We are a team of certified penetration testers combining international technical expertise with first-hand knowledge of Peruvian regulation and operating context. We work with mining companies, financial institutions, fintechs and public entities.
Every engagement is carried out with formal authorization, clear rules and full confidentiality, and ends with concrete evidence your team can use to decide, remediate and comply.
Our values
Certified. Ethical. Rigorous. Trusted.
Four principles that guide every assessment, every report and every conversation with our clients.
Certified
Our consultants back their expertise with hands-on certifications that require compromising real systems, not just passing theory exams.
Ethical
We only act with authorization and within the agreed scope. We report the vulnerabilities we find through responsible disclosure.
Rigorous
Every finding is documented with reproducible evidence, prioritized by real impact and mapped to recognized frameworks such as MITRE ATT&CK.
Trusted
We protect our clients’ information with non-disclosure agreements, secure data handling and transparent communication.
Why Kamaya
Offensive expertise with local backing
01
Certified pentesters
A team holding certifications such as OSCP, OSCP+, CRTP, eCPPT, eWPTX, eWPT, eMAPT and eJPT.
02
Research community
We have our own community of security researchers for bug bounty programs and specialized testing.
03
Responsible disclosure
Our consultants have reported vulnerabilities to Peruvian and international organizations following responsible disclosure practices.
04
Public sector supplier
We are registered with Peru’s National Registry of Suppliers (RNP) and have worked directly with public entities such as the Universidad Nacional de Ingeniería.
05
Local presence
From Lima, in your language and time zone, with on-site capability, including remote operations.
06
From assessment to solution
Beyond assessing, we can supply and implement the technology your organization needs to close the gaps.
Certifications
A team certified in offensive security
Hands-on certifications held by our consultants, issued by OffSec, Altered Security and INE Security.
Responsible disclosure
Organizations our consultants have reported vulnerabilities to
Vulnerabilities reported by our consultants through responsible disclosure. Trademarks belong to their respective owners; their mention does not imply a commercial relationship or endorsement.
Our team
The team that attacks to protect
Pentesters, researchers and engineers who design, run and validate every assessment and every Kynapt finding.
-
Alejandro Manuel Vega Vásquez
Managing Partner · Head of Offensive Security
Managing partner at Kamaya Secure and head of offensive security. He leads the technical relationship with clients in mining, banking and the public sector, aligning every pentest and Red Team exercise with the business. Telecommunications Engineer (UNI).
-
-
Paulo Puicón Gallardo
Project Director
As project director, he coordinates the planning and execution of every assessment, from scoping to the delivery of results. He is the client’s point of contact throughout the engagement and oversees timelines and the quality of deliverables.
-
Jesús Arturo Espinoza Soto
Senior Penetration Tester · Associate Consultant
Penetration tester with over 7 years of experience in web, mobile and infrastructure assessments, recognized in responsible disclosure programs. Certified OSCP, CEH, eCPPTv2, CREST CPSA and Burp Suite Certified Practitioner. Master’s in Cybersecurity.
Let’s define the right scope for your organization
Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.






