Available for projects

Penetration Tester
& Security Consultant

5+ years of experience. 200+ security projects completed. Specializing in web & mobile application security, API testing, and secure code review. Helping organizations understand and fix their real vulnerabilities.

Filip Kecman - Penetration Tester and Security Consultant
Scroll

Security professional with a hands-on mindset

I'm a penetration tester with 5+ years of experience across 200+ security projects, specializing in the security of web and mobile applications, APIs, and cloud infrastructure. I participate in the entire process, from scoping and execution to reporting, focusing on identifying real vulnerabilities and providing clear, actionable recommendations.

Beyond testing, I'm the CEO & Founder of The Free Security, a non-profit organization providing free penetration tests to organizations that need them, performed by people I personally mentor and train.

I also served as a Teaching Assistant at the Faculty of Computing in Belgrade, helping shape the next generation of security professionals through hands-on education.

  • Web Application Security
  • Mobile App Pentesting
  • API Security Testing
  • Cloud Security
  • Secure Code Review
  • Network Pentesting
  • Social Engineering
  • OSINT & CTI
0+
Projects Completed
0
Certifications
0+
Years Experience
Free Pentests Given

Every assessment is treated like a real attack

Industry-standard methodologies, manual testing, actionable results

🎯

I think like an attacker

I approach every engagement from the adversary's perspective. Instead of running automated scans and calling it a day, I dig deep to find the vulnerabilities that real attackers would exploit, including the ones tools miss entirely.

📋

Reports you can actually use

Security findings only matter if you can act on them. I write clear, prioritized reports that explain what was found, why it matters, and exactly how to fix it. No jargon, no hundred-page fluff.

⚙️

Adapted to your needs

Whether you're a startup preparing for your first pentest or an enterprise running quarterly assessments, I adapt my methodology to your size, budget, and risk profile while keeping the same rigorous quality.

Industry Standards & Methodologies

OWASP WSTG Web Security Testing Guide
OWASP Top 10 Web Application Risks
OWASP API Top 10 API Security Risks
OWASP Mobile Top 10 Mobile Application Risks
OWASP MASVS Mobile App Security Verification
PTES Penetration Testing Execution Standard

The Process

From first contact to final retest, here is what working with me looks like

01

Contact

You reach out with your requirements. I share a sample report and methodologies relevant to your project so you can see exactly how I work.

02

Scoping

We define the exact targets, testing boundaries, methodology, and timeline together.

03

Proposal

You receive a clear proposal with scope, approach, deliverables, timeline, and pricing.

04

Kickoff

Access is granted, credentials are shared securely, and testing rules of engagement are confirmed.

05

Pentest

Thorough manual and automated testing following OWASP and PTES. Critical findings reported immediately.

06

Report

Detailed report with findings, risk ratings, proof-of-concept exploits, and actionable remediation steps.

07

Retest

After your team applies fixes, I verify that vulnerabilities are properly remediated. Available for calls throughout remediation to walk through the report and help developers fix vulnerabilities.

Continuous learning & professional growth

Industry-recognized credentials that validate deep technical expertise

Professional journey

From education to leading security assessments

Penetration Tester

SecureIT · 2025 - Present
  • Conducting penetration tests of networks, web & mobile applications, APIs and cloud infrastructures
  • Performing social engineering tests and phishing engagements
  • Executing OSINT and Cyber Threat Intelligence investigations
  • Leading penetration testing projects from planning to delivery
  • Performing secure code reviews, static/dynamic analysis and reverse engineering

Teaching Assistant

Faculty of Computing, Belgrade · 2024 - 2026
  • Co-designed and delivered the "Introduction to Computer Security" course
  • Created assignments, midterm and final exam tasks
  • Supported students in understanding core security concepts through hands-on experience

Penetration Tester

UN1QUELY · 2023 - 2025
  • Identified and addressed vulnerabilities in networks, web and mobile applications
  • Wrote detailed reports with clear explanations and actionable solutions
  • Collaborated with clients to tailor testing approaches to their needs

Penetration Tester

Freelance · 2021 - Present
  • Conducting comprehensive web and mobile application penetration tests for international clients
  • Delivering detailed reports with proof-of-concept exploits and actionable remediation strategies

Giving back to the community

Non-profit pentesting & mentorship initiative

Free security assessments for those who need them

As the CEO & Founder of The Free Security, I lead a non-profit initiative that provides free penetration tests to organizations that can't afford professional security assessments.

Every test is conducted by aspiring penetration testers whom I personally mentor and train. This creates a unique cycle: organizations get real security improvements, and the next generation of security professionals gets hands-on experience under expert guidance.

🎓

Mentoring & Training

Teaching real-world pentesting skills through supervised live engagements

🤝

Community Impact

Helping organizations improve their security posture at zero cost

🔒

Professional Standards

All engagements follow industry methodologies and standards

Free
Every Engagement
100%
Non-Profit
Mentees Trained
Live
Real Engagements

Security insights & write-ups

Pentesting stories, techniques, and lessons learned

Have a project in mind?

Whether you need a security assessment, have a question, or want to collaborate, I'd love to hear from you. I typically reply within 24 hours.

Based in Belgrade, Serbia, working remotely worldwide. Available for penetration testing, security consulting, and training engagements.