Pablo Ruiz scopes the engagement, runs it, and writes the report.
RagnarOps Security Labs is one senior operator working from Amsterdam, in offensive security since 2018. No bench, no handoff, and nobody between you and the person on the keyboard. This page is what you would otherwise have to ask for on the call, including the limits.
- Amsterdam · Netherlands
- Offensive security since 2018
- Remote, worldwide
No bench. The work does not get handed down.

Pablo Ruiz
Founder and Lead operatorOffensive security since 2018, across Spain, Norway, and the Netherlands.
The certification path is deliberate rather than decorative: OSCP first, then the full OSCE³ chain — OSEP for evasion, OSWE for the web layer, OSED for exploit development — with GPEN and GCIH covering the defensive side, CRTO for red-team operations, and AWS Security Specialty for the cloud work.
Read for his degree at Universidad de León part-time while working full-time, finishing with first-class honours.
OffSec lists him as an ambassador for its Netherlands chapter, where four of those credentials are published by the body that issued them. Certifications are a floor, not a finding — they say the method is sound, not that the work was.
Every engagement is run end to end by the person who scoped it. Nothing is subcontracted and no finding is handed to someone else to write up, so the operator who got in is the one who explains how, and the one your engineers sit with when it is time to close the path.
What is not covered by an NDA is published. The Labs carry the field notes, the teardowns and the live sessions — the same tradecraft, worked in the open rather than described after the fact.
The practice operates from the Netherlands and works remotely, worldwide.
Certified across offensive, defensive and cloud disciplines.
// 20+ held. The 11 below are the ones with badge artwork.
// Operator certifications
20+ certifications held
A selection of 11, across offensive, defensive and cloud disciplines.
Select a badge to inspect it
// Offensive
- OSCP
- Offensive Security Certified ProfessionalOffSec
- OSEP
- Offensive Security Experienced PentesterOffSec
- OSWE
- Offensive Security Web ExpertOffSec
- OSED
- Offensive Security Exploit DeveloperOffSec
- OSCE³
- Offensive Security Certified Expert 3OffSec
- OSWP
- Offensive Security Wireless ProfessionalOffSec
- GPEN
- GIAC Penetration TesterGIAC / SANS
// Collaboration
- CRTO
- Certified Red Team OperatorZero-Point Security
// Defensive
- GCIH
- GIAC Certified Incident HandlerGIAC / SANS
- AWS SEC
- AWS Certified Security — SpecialtyAmazon Web Services
- AWS SA
- AWS Certified Solutions ArchitectAmazon Web Services
OSCP, OSEP, OSED, OSWE verified by OffSecPablo Ruiz is listed on the OffSec Netherlands chapter page, alongside the other ambassadors for the country.
Figures we can evidence on request.
// Figures cover the operator's full career, not this practice alone. Typical engagement is a floor, not a cap.
What you get before anything is scoped.
Mutual NDA first
Signed before any technical discussion. Scope, targets, test windows and everything out of scope are agreed in writing before a packet moves.
48-hour response
Every engagement enquiry gets a reply inside 48 hours — a threat model and a proposed scope, or a straight answer that this is the wrong practice for it.
Aligned to
- MITRE ATT&CK
- Adversary behaviour taxonomy
- PTES
- Penetration Testing Execution Standard
- TIBER-EU
- Threat Intelligence-based Ethical Red Teaming
- TLPT
- Threat-Led Penetration Testing
- DORA
- Digital Operational Resilience Act
None of these is an accreditation, a certification or a membership. “Aligned to” and “works to” are the accurate words, and they describe how engagements are run.
Sectors where the blast radius is real
- Railway
- Public sector
- Financial
- Entertainment
- Critical infrastructure
Sectors, not clients. Naming a client needs their written permission, and an offensive-security engagement is close to the last thing a client wants attributed to them in public. The same rule protects you.
What one operator cannot do.
A single operator does not scale sideways. If your scope needs six testers hitting distinct environments inside the same two-week window — a pre-listing sweep, a group-wide annual across twelve subsidiaries — this is the wrong shape of practice for it, and we will say so on the scoping call rather than after the contract. Engagements run in sequence, so ask for a start date in the first email. It is usually the binding constraint.
- If we become unavailable
- The engagement pauses. If it cannot resume, you take the evidence collected to date and pay only for the work delivered. A solo practice cannot promise you a substitute operator, so it does not.
- Subcontracting
- None. Nobody but the named operator touches your engagement, and that will not change without telling you first.
- Your evidence
- Held local, full-disk encrypted, and copied to cloud storage only where you have agreed to it in writing. Destroyed 90 days after delivery.
- What we are not
- We do not staff a SOC, hold a retainer rota or answer a pager. The work is bounded projects with a start, an objective and a report.
// next step
Bring the objective. We will tell you if this is the wrong practice for it.
Mutual NDA first · 48h response · scope agreed in writing
Or read the work first — field notes and teardowns are public and unpaywalled. The same person writes them.