The team that audits is the team that signs the report
We do not subcontract. When you engage us for an audit, the same people who design it run it, document it and walk you through the results. That is the difference between receiving a PDF exported from a tool and receiving an analysis done by someone who genuinely knows how to attack.
We work with private companies and public administration. Part of our team holds Personnel Security Clearance, a requirement for handling classified information in defence and public sector projects.
What sets us apart
Offensive capability we can prove, not just claim. We compete against the community and publish the results: Top 1% of Atenea, the training platform of Spain’s National Cryptologic Centre, first place in Web Hacking at the CCN-CERT STIC Conference 2025, and winning team at the Navaja Negra CTF 2025.
Reports you can read and act on. One executive report for the board, with risk in business language, and one technical report with every finding, its evidence, its severity and how to fix it. With a prioritised remediation plan, not a list of CVEs.
Court-admissible forensics. Our forensic reports are produced with chain of custody and built to stand up in court, not just for internal use.
We will also tell you what you do not need. If your problem can be solved with something cheaper than what we sell, we will say so.
Team certifications
In this industry the auditor’s certification is the product. These are ours.
Offensive security and Red Team
OSCP · CRTO · CRTO II · eWPTX · eCPPT (100/100) · API Penetration Testing · Hack The Box Pro Labs (Dante, Cybernetics, APTLabs, RastaLabs) · Professional malware development certificate (Maldev Academy)
Digital forensics and incident response
eCDFP · Incident Forensic Analysis Technician (INCIBE) · Court-appointed forensic expert
Governance, risk and compliance
CISSP · ISO 27001 Lead Auditor · CCSP and CDPP (ISMS Forum) · Spanish National Security Framework (ENS) and Risk Analysis (CCN) · PMP (PMI)
Industrial and OT
Spanish Industrial Cybersecurity Centre (CCI), Black Level Professional · OT Industrial Cybersecurity certificate (Ciberwall Academy) · University Postgraduate Course in Industrial Cybersecurity
Intelligence
Cyber Intelligence and Open Source Intelligence (OSINT), Spanish National Cryptologic Centre
Leadership and founders
Juan M.
Engineer with three master’s degrees in cybersecurity. He has led Red Team operations, penetration testing engagements, forensic investigations and black, grey and white box audits. Court-appointed forensic expert. Certified OSCP, CRTO II, eWPTX, eCPPT, eCDFP, CCSP and CDPP, among others.
Fernando Romero Urdiain, PMP · LinkedIn
Computer Engineer from the Polytechnic University of Madrid (UPM) and Project Management Professional (PMI), with more than 20 years leading technology projects. Specialised in penetration testing, risk analysis, regulatory compliance and security auditing.
We teach what we do
Teaching on the Cybersecurity Degree at UNIR and technical supervision of bachelor’s and master’s theses at Universidad Camilo José Cela, University of Murcia, University of Oviedo, UNIR and UOC. More than 50 technical articles published and a book due in late 2026.
We are a registered company in the catalogue of the Spanish National Cybersecurity Institute (INCIBE) and members of CyberMadrid.
Shall we talk about your case?
Tell us what you need and we will tell you whether we can help. And if we cannot, we will say so too.
Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET)
Email: info@jaymonsecurity.com


