ABOUT US

Built by
Operators

ShadowCore was founded by cybersecurity operators who build, break, and defend. Penetration testing, compliance, SOC — one team covering your entire attack surface.

100+
Security Assessments
15+
Certifications Held
4+
Sectors Served
Gov · Fintech · SaaS · Energy
EU
Delivery Focus
Compliance-aligned
Values

Our Principles

The operational doctrine that guides every engagement.

01

Offense Informs Defense

We attack to protect. Our red team insights directly improve our defensive capabilities.

02

Transparency Over Obscurity

We publish our methodologies, maintain a public trust center, and hold ourselves accountable.

03

Continuous Evolution

The threat landscape shifts daily. Our team trains weekly, researches constantly, and adapts.

04

Client Confidentiality

Zero tolerance for data exposure. Strict need-to-know access. All engagements sanitized.

Team

Our Team

Security professionals with hands-on experience across pentest, compliance, SOC, and application security.

Founder
DS

Denys S.

Founder, Head of Security

5 yrs
BSCP | Pentest· Compliance· Application Security· DevSecOps

Web & Mobile Application Security, Penetration Testing, NIS2 Compliance, DevSecOps. Worked in gov, product & fintech sectors. Conducted 20+ full-scope penetration tests, built Secure SDLC from zero, supported NIS2 audit for a major pharmacy company.

Co-Founder
MS

Mykhailo Sh.

Co-Founder · AI Direction

AI Security· AI Engineering· Security Automation

Leads AI direction at ShadowCore — AI-driven security automation, agent workflows for security operations, and integration of AI tooling into pentest and SOC delivery.

Co-Founder
YY

Yehor Y.

Co-Founder · SOC, Threat Intelligence & Incident Response

CDSA * | SOC· Threat Intelligence· Incident Response

Leads SOC, Threat Intelligence, and Incident Response direction. Two years of SOC analytics for government agencies and large energy companies; built a Vulnerability Management process for a critical-infrastructure government entity; ~10 penetration tests conducted.

PO

Philip O.

Senior AppSec Engineer

7 yrs
OSCP OSWE
Pentest· Application Security

7+ years in security and bug bounty. Detected hundreds of critical vulnerabilities, Mozilla Hall of Fame, authored cybersecurity researches. Performed Red Team Engagement for product company, detected critical vulnerability in Mozilla Firefox.

NH

Nykyta H.

Security Engineer

4 yrs
eCPPT CompTIA Pentest+ eWPTX ICCA BSCP
Pentest· Application Security· SecOps

Application and infrastructure penetration testing, vulnerability management, and secure SDLC practices. Performed code review and secure SDLC integration for a fintech startup, conducted vulnerability assessment and hardening of cloud-hosted infrastructure.

EH

Elkhan H.

Security Engineer

4 yrs
CompTIA Security+ eJPT eCPPT eWPTX
Pentest· Application Security

Web and API penetration tests, code reviews, and security assessments for SaaS and fintech clients. Conducted internal network pentesting and Active Directory security review, executed web application and API penetration testing for a SaaS analytics platform.

Capability

Extended delivery team

Application Security Compliance SOC Cloud

Supported by vetted security engineers for project delivery, research, documentation, and remediation support under senior supervision.

Join the team

We're always looking for talented security professionals.

Get in Touch