Managed detection and response platform with attack surface and compliance focus
NopalCyber operates an MXDR platform combining managed threat detection, attack surface management, and breach simulation with a proprietary risk-scoring system (CIQ). The tech stack spans cloud infrastructure (AWS, Azure, GCP, Kubernetes), defensive tools (Sentinel, Securonix, QRadar, SentinelOne, CrowdStrike), and offensive testing (Burp Suite, Metasploit, Cobalt Strike) — reflecting a dual-lens approach to offense and defense. Pain-point clustering around compliance readiness, attack surface discovery, and false-positive reduction signals the product roadmap is being shaped by mid-market security teams drowning in alert fatigue and fragmented tooling.
Notable leadership hires: Chief Information Security Officer
NopalCyber provides managed extended detection and response (MXDR), attack surface management (ASM), and breach simulation services for mid-market and enterprise companies. The platform consolidates detection, investigation, and response across cloud and on-premises infrastructure, paired with advisory services and external threat intelligence. The company targets organizations needing security operations scaled faster than hiring allows, offering pre-configured service packages alongside custom implementations. Founded in 2022 and based in New York, NopalCyber operates across 51–200 employees with active hiring in security roles in India, signaling delivery and support scaling.
NopalCyber uses Sentinel, Securonix, QRadar, SentinelOne, and CrowdStrike Falcon for detection; Wazuh for monitoring; Netskope, Varonis, and Forcepoint for data and network security; and Burp Suite, Metasploit, and Cobalt Strike for attack simulation testing.
NopalCyber operates across AWS, Azure, and GCP with containerized infrastructure (Kubernetes, Docker) and infrastructure-as-code tooling (Terraform, Ansible) for multi-cloud security assessments and architecture design.
Other companies in the same industry, closest in size
NopalCyber's technology stack, projects, and hiring signals are inferred from public hiring and company data — career pages, public listings, and company web presence — then clustered and de-duplicated. Figures are estimates that refresh over time. Read our full methodology →
This is not an official vendor or customer list. It is a technology-adoption signal inferred from public data, intended for B2B research.