Offensive security, compliance, and vCISO services for SaaS
Rhymetec operates a services-driven security firm built around three core pillars: penetration testing, vCISO advisory, and compliance program design. The hiring mix—split evenly between security and sales—reflects a consulting model that scales through both technical delivery (red-team exercises, cloud security audits, incident response) and client acquisition. Heavy reliance on cloud platforms (AWS, Azure, GCP) and endpoint-management tools (Jamf, JumpCloud) suggests clients are primarily cloud-native SaaS businesses managing distributed infrastructure and compliance obligations.
Rhymetec delivers security and compliance services to SaaS businesses, operating as a managed security partner rather than a platform vendor. The company provides vCISO programs (fractional chief information security officer), ISO 27001 and SOC 2 audit management, penetration testing (web, mobile, network), and custom compliance program design. Projects span cloud security posture improvement, incident response tabletop exercises, and risk management program architecture. Core clients appear to be growth-stage SaaS firms balancing speed with regulatory requirements (SOC 2, ISO 27001, PCI compliance). Based in New York with 11–50 employees, the company was founded in 2015.
Rhymetec provides penetration testing (web, mobile, and network), vCISO advisory programs, ISO 27001 and SOC 2 audit management, compliance program design, and incident response exercises tailored to SaaS businesses.
Rhymetec deploys across AWS, Azure, and GCP, with supporting tools including Datadog (monitoring), JumpCloud and Jamf (endpoint management), and Microsoft Endpoint Manager.
Other companies in the same industry, closest in size