NetSPI operates a penetration-testing-as-a-service platform staffed by security professionals and augmented with AI/ML tooling. The hiring mix is heavily skewed toward security practitioners (44 of 54 active roles) with minimal engineering (6 roles), reflecting a services-first model; however, active projects around AI/ML pipeline testing and prompt injection suggest the company is building proprietary security research capabilities and platform automation. Pain points centered on AI/ML vulnerabilities and scaling assessments signal a strategic pivot toward proactive, automated testing workflows rather than pure manual services.
NetSPI delivers penetration testing and attack surface management services to financial institutions and Fortune 500 enterprises. Founded in 2001, the company has grown to 501–1,000 employees across the United States, India, and Canada. The service catalog spans 50+ pentest types, including cloud assessments, mobile application testing, red-team engagements, and application code review. The platform combines manual testing by security experts with automation and ML-driven vulnerability prioritization to accelerate remediation cycles and surface hidden risks.
NetSPI uses industry-standard security tools (Burp Suite, Metasploit, Nessus, Kali Linux, Ghidra, Frida) alongside cloud infrastructure (AWS, Kubernetes, Lambda, Fargate), ML frameworks (PyTorch, TensorFlow, scikit-learn), and data pipeline components (Kafka, PostgreSQL, Redis).
Active projects include cloud penetration testing (especially against AWS), mobile application testing, development of new attack techniques and TTPs, and advanced testing of AI/ML pipelines including prompt injection. This reflects expansion beyond traditional pentesting into emerging attack surfaces and AI security.
Other companies in the same industry, closest in size