Secure every application with flexible pentesting that combines expert-led testing, autonomous validation, and actionable results.
Learn moreIdentify exploitable risk across external networks, internal infrastructure, and cloud environments.
Learn moreExtend your offensive security program with specialized assessments, adversarial testing, code review, and program-level support.
Learn moreThrough customer interviews and case studies, ESG validated that Cobalt’s Pentest as a Service (PtaaS) model provides a cost-effective way to reduce risk and accelerate results compared to traditional pentesting models.
Watch the on-demand webinar to learn more about:
Read the full results in the report, ESG Economic Validation: Analyzing the Economic Benefits of Cobalt’s Pentest as a Service (PtaaS) Model and discover the benefits of having a real-deal pentesting partner that delivers the speed, security and savings your organization deserves.
Jay Paz, Senior Director of Delivery | Cobalt
Jay Paz is Cobalt’s Senior Director of Delivery. He has more than 12 years of experience in information security and 20+ years of information technology experience including system analysis, design and implementation for enterprise level solutions. He has a robust background in developer supervision and training as well as in major programming languages, operating hardware and software, and major infrastructure application development. At Cobalt, he lays the groundwork for innovation and scale as he oversees operations and day-to-day management for Cobalt’s pentester community.
Aviv Kaufmann, Principal IT Validation Analyst | ESG
Aviv uses his education in engineering and technology and background as a competitive and performance analyst to generate robust independent validations of emerging IT hardware and software products. He is especially skilled at finding technical and economic models that illustrate product value.
Melinda Marks, Senior Analyst | ESG
Senior Analyst Melinda Marks covers application and cloud security at ESG, helping organizations scale safely while adopting faster cloud-native development cycles. Her coverage area includes cloud-native application protection platforms, cloud workload protection, cloud security posture management, DevSecOps, and application security, including web application security testing (SAST, DAST, IAST, SCA) and API security.
David Kosorok, Director of Application Security | Hyland
David Kosorok is responsible for application security at Hyland Software. David has over 25 years experience in software and security testing and over 13 years experience working specifically in security. Prior to joining Hyland, David ran the Application Security and Vulnerability Management teams at DocuSign and has pioneered growth in application security programs for Align Technologies, SAP Concur, The Church of Jesus Christ of Latter Day Saints, and a few start-up companies.
David holds a number of professional security certifications including a few such as CISSP, CSSLP, GWAPT, CHFI, CEH and a Master of Science in Information Security and Assurance. He has also been a volunteer Beta editor for PenTestMag for a number of years, and recently joined EC Council’s Global Advisory Board for CEH (Certified Ethical Hacking). When not reading great SciFi/Fantasy novels or struggling to write one with his brother, David enjoys volunteering in his community, hiking, camping and generally enjoying the outdoors. Married 33 years to Kimberly, he is a father of 9 children and has 2 grandchildren.