Operators first. Everything else follows from that.
BNO Security Group is built by people who'd rather be exploiting a finding than writing a slide about it — and it shows in how we scope, test, and report.
A small team, deliberately.
BNO Security Group, LLC (d/b/a BlackN0de Security Group) runs manual, adversary-driven security testing and advisory work. We stay small so every engagement is led by people who actually do the testing — not account managers relaying findings from a subcontractor.
We started BNOSG because too much of the industry runs on unauthenticated scans repackaged as penetration tests. Our engagements are scoped in writing, executed by hand against real attacker tradecraft, and reported in a way that both engineers and executives can act on. A retest is included on every offering — not sold back to you as a second assessment.
-
Manual by default
Automated tooling supports the work; it never replaces a human validating and chaining findings.
-
Scoped honestly
We price against real complexity and tell you when a cheaper offering is the right fit — even if it's not ours.
-
Remote-first, nationwide
Engagements are scoped and delivered remotely by default, with on-site work available where the assessment calls for it.
We hire operators, not titles.
We're a small, deliberately-staffed team. When we're hiring, it's for people who can scope an engagement, do the work by hand, and explain it clearly afterward — not to fill a headcount target.
No open roles right now
We don't have active openings at the moment, but we're always glad to hear from people with real offensive-security experience. Send a short note and your background to the address below and we'll keep it on file for when that changes.