Skip to content
All systems nominal
//  —  About the practice

Pablo Ruiz scopes the engagement, runs it, and writes the report.

RagnarOps Security Labs is one senior operator working from Amsterdam, in offensive security since 2018. No bench, no handoff, and nobody between you and the person on the keyboard. This page is what you would otherwise have to ask for on the call, including the limits.

// 01  —  Operator

No bench. The work does not get handed down.

Pablo Ruiz

Founder and Lead operator

Offensive security since 2018, across Spain, Norway, and the Netherlands.

The certification path is deliberate rather than decorative: OSCP first, then the full OSCE³ chain — OSEP for evasion, OSWE for the web layer, OSED for exploit development — with GPEN and GCIH covering the defensive side, CRTO for red-team operations, and AWS Security Specialty for the cloud work.

Read for his degree at Universidad de León part-time while working full-time, finishing with first-class honours.

OffSec lists him as an ambassador for its Netherlands chapter, where four of those credentials are published by the body that issued them. Certifications are a floor, not a finding — they say the method is sound, not that the work was.

Every engagement is run end to end by the person who scoped it. Nothing is subcontracted and no finding is handed to someone else to write up, so the operator who got in is the one who explains how, and the one your engineers sit with when it is time to close the path.

What is not covered by an NDA is published. The Labs carry the field notes, the teardowns and the live sessions — the same tradecraft, worked in the open rather than described after the fact.

The practice operates from the Netherlands and works remotely, worldwide.

Based
Amsterdam, Netherlands
Practising since
2018
Languages
Spanish · English · Norwegian
Reach
Remote, worldwide
// 02  —  Credentials

Certified across offensive, defensive and cloud disciplines.

// 20+ held. The 11 below are the ones with badge artwork.

// Operator certifications

20+ certifications held

A selection of 11, across offensive, defensive and cloud disciplines.

Select a badge to inspect it

// Offensive

OSCP
Offensive Security Certified ProfessionalOffSec
OSEP
Offensive Security Experienced PentesterOffSec
OSWE
Offensive Security Web ExpertOffSec
OSED
Offensive Security Exploit DeveloperOffSec
OSCE³
Offensive Security Certified Expert 3OffSec
OSWP
Offensive Security Wireless ProfessionalOffSec
GPEN
GIAC Penetration TesterGIAC / SANS

// Collaboration

CRTO
Certified Red Team OperatorZero-Point Security

// Defensive

GCIH
GIAC Certified Incident HandlerGIAC / SANS
AWS SEC
AWS Certified Security — SpecialtyAmazon Web Services
AWS SA
AWS Certified Solutions ArchitectAmazon Web Services

OSCP, OSEP, OSED, OSWE verified by OffSecPablo Ruiz is listed on the OffSec Netherlands chapter page, alongside the other ambassadors for the country.

// 03  —  Record

Figures we can evidence on request.

8+ yrsIn offensive security
100+Engagements delivered
91%Objective rate
3 wks→ monthsTypical engagement

// Figures cover the operator's full career, not this practice alone. Typical engagement is a floor, not a cap.

// 04  —  Practice

What you get before anything is scoped.

Mutual NDA first

Signed before any technical discussion. Scope, targets, test windows and everything out of scope are agreed in writing before a packet moves.

48-hour response

Every engagement enquiry gets a reply inside 48 hours — a threat model and a proposed scope, or a straight answer that this is the wrong practice for it.

Aligned to

MITRE ATT&CK
Adversary behaviour taxonomy
PTES
Penetration Testing Execution Standard
TIBER-EU
Threat Intelligence-based Ethical Red Teaming
TLPT
Threat-Led Penetration Testing
DORA
Digital Operational Resilience Act

None of these is an accreditation, a certification or a membership. “Aligned to” and “works to” are the accurate words, and they describe how engagements are run.

Sectors where the blast radius is real

  • Railway
  • Public sector
  • Financial
  • Entertainment
  • Critical infrastructure

Sectors, not clients. Naming a client needs their written permission, and an offensive-security engagement is close to the last thing a client wants attributed to them in public. The same rule protects you.

// 05  —  Limits

What one operator cannot do.

A single operator does not scale sideways. If your scope needs six testers hitting distinct environments inside the same two-week window — a pre-listing sweep, a group-wide annual across twelve subsidiaries — this is the wrong shape of practice for it, and we will say so on the scoping call rather than after the contract. Engagements run in sequence, so ask for a start date in the first email. It is usually the binding constraint.

If we become unavailable
The engagement pauses. If it cannot resume, you take the evidence collected to date and pay only for the work delivered. A solo practice cannot promise you a substitute operator, so it does not.
Subcontracting
None. Nobody but the named operator touches your engagement, and that will not change without telling you first.
Your evidence
Held local, full-disk encrypted, and copied to cloud storage only where you have agreed to it in writing. Destroyed 90 days after delivery.
What we are not
We do not staff a SOC, hold a retainer rota or answer a pager. The work is bounded projects with a start, an objective and a report.

// next step

Bring the objective. We will tell you if this is the wrong practice for it.

Mutual NDA first · 48h response · scope agreed in writing

Schedule a scoping call

Or read the work first — field notes and teardowns are public and unpaywalled. The same person writes them.