About

GingerBeard Security is Nathan Smith’s practice, and it’s been running since 2020. When you hire us, the person who scopes the engagement is the person who does the testing and writes the report. There’s no bench of junior testers behind the sales call.

Who is doing the testing

Fifteen-plus years in IT and information security. The offensive side of that isn’t a sideline. It’s ongoing, contracted, and vetted by people outside this company.

  • Synack Red Team. Security researcher since 2020, finding vulnerabilities across a wide range of applications on a platform that vets its testers before it lets them near a client.
  • Webcheck Security. Associate Director, Red Team and Lead Penetration Tester since 2021. Network, web application, mobile application, and social engineering engagements.
  • Pima Community College. Wrote and taught the college’s ethical hacking course from 2021 to 2025. Teaching a subject is a different bar than doing it.

Certifications: CISSP (ISC2) and OSWP, the Offensive Security Wireless Professional. Earlier training includes Black Hat’s Web Hacking course and CompTIA Security+, Network+ and A+.

The defensive half matters too

Most people who test your network have never had to fix one. That’s the difference you feel when the report lands.

The day job is running security operations and engineering for a large publicly traded enterprise. Before that: Director of Information Security at a global data protection vendor, building security across AWS, Azure, GCP and on-premise. Regional security manager for a multinational diagnostics company. Senior security roles at a cloud contact center provider and a statewide education network, covering HITRUST, auditor engagement, incident response, and vulnerability management.

Several of those programs got built from nothing. That’s why findings come back with remediation your team can actually ship, prioritized against the constraints real security teams work under. Budget, headcount, change windows, and a backlog that was already full before we showed up.

How we work

  • We’ll tell you when you’re buying the wrong thing. If a configuration review would serve you better than a full penetration test, we say so before you sign, not after.
  • Findings get validated by hand. If a scanner flagged it and we couldn’t reproduce it, it doesn’t go in the report as a finding.
  • Security is a partner, not a roadblock. Reports are written to help engineers ship fixes, not to justify the invoice by page count.
  • You get a named tester. You’ll know who’s on your network and when.

Our full methodology is published, including the rules about what we won’t do to a production environment.

Where we are

Based in Utah, working with clients remotely across the United States. On-site work gets arranged as the scope requires.

Tell us what needs testing and we’ll come back with a fixed price and a testing window.