Studying security is not the same as doing it.
1:1 mentorship into pentest, VAPT and red team work. Beginner or halfway there, the plan starts with a diagnosis of where you actually are.
Free, and nothing gets booked or charged. Or ask on WhatsApp first.
- We talkA call. I tell you honestly whether I can help.
- I diagnoseA short intake: what you know, what you have tried, where you stopped.
- We workYour plan, live sessions, marked assignments, interview prep.
Starting points
Find your starting point
People arrive here from very different places and need very different plans. Open the one that sounds like you.
New to cybersecurity, starting from zero
- Missing
- A starting point, and a way to tell useful material from noise.
- We start with
- Networks, Linux and how the web really works, in the order you actually need them.
- Ready means
- You work a target end to end on your own, without being walked through it.
Coming from IT, support or development
- Missing
- Security fundamentals, and a lab habit you actually keep.
- We start with
- Foundations, a weekly lab, and notes an engineer could follow.
- Ready means
- You find a real vulnerability on an unfamiliar target and explain why it matters.
Certified, but never tested anything live
- Missing
- Hands. The vocabulary is there; the target is not a walkthrough.
- We start with
- Live targets under time pressure, starting inside your depth.
- Ready means
- You work an unfamiliar target to a finding with nothing open in the next tab.
Moving from SOC or GRC into offensive work
- Missing
- The offensive method. It does not transfer from defensive work.
- We start with
- The method for the domain you are entering, and nothing you already carry.
- Ready means
- You run the core workflow end to end and hold your own in its interviews.
Intermediate, stuck below professional
- Missing
- Depth, and delivery. You find things; the write-up does not carry them.
- We start with
- Advanced technique, plus report writing trained as its own skill.
- Ready means
- You produce a report a client signs off without rework.
People are frequently not in the row they assume. The intake is what settles it.
Method
Diagnose first. Then mentor.
The same sequence an engagement follows: scope what is there before deciding what to do about it.
Intake
A structured questionnaire, before anything is planned or priced.
Your plan
Written from the intake, not pulled off a shelf. Duration and cost become knowable here.
Live 1:1 sessions
Direct time with me, not a batch of thirty. You bring what you are stuck on.
Accountability
Assignments with real deadlines, which I read and mark.
Interview prep
Resume, portfolio and interview practice for the role you are targeting.
Fit
Who this is for
Worth being direct before either of us spends time on an intake.
This is for you if
- You want to work in security and cannot do the job yet, whether that is from scratch or from halfway.
- You can attend live sessions on IST hours.
- You want a plan built around where you are, not an eight-week outline.
This is not for you if
- You want a certificate. EC-Council, CompTIA, etc. are not included.
- You want a watch-along course. There is work between sessions.
- You need a fixed price before you begin. Pricing follows the intake.
Background
Who you would be working with
Mentorship is a small part of my week. The rest is the work I would be teaching you to do.
- 9+ years across penetration testing, application security and instructor-led training.
- On-site work in 10 countries, across central banking, government, healthcare and Fortune 500.
- 20+ organisations trained, and 1,600+ instruction hours delivered.
- Lab work runs on ShopEasy and my public labs, free whether or not you hire me.
- The full record: clients, engagements and published labs →
Certifications held
Questions
Questions people ask first
Including the two everyone wants answered before anything else.
Who is this for?
Anyone who wants to work in cybersecurity and cannot do the job yet. That covers people starting from nothing, students, people who finished a bootcamp or institute program, and working professionals moving over from IT, SOC or GRC. The one hard requirement is that you can attend live sessions on IST hours.
How long does it take, and what does it cost?
Both are set after I read your intake. Someone moving between security domains often needs about a month, someone coming from general IT needs considerably longer, and someone starting from nothing needs longer still. If you need a fixed number before any conversation, this is genuinely not the right program.
Do I need an IT background to start?
No. Some people arrive with years of IT behind them, some arrive with nothing but the decision to change careers. The intake tells me which, and the plan starts wherever that is. Starting from zero means a longer road, not a closed one.
Does this include certification?
No. EC-Council, CompTIA, etc. are not included. If a specific job requires one, we can plan for it separately. What this builds is the practical capability those programs often do not.
How is the plan decided?
Diagnosis before curriculum. The intake establishes what you know, what you have tried, where you stopped, and what "job-ready" means for the role you are targeting. The plan is written from that.
What is ShopEasy?
A hands-on API security lab I built and maintain: the same e-commerce app in a vulnerable and a fixed version, covering BOLA, JWT flaws, broken authentication and debug data leaks. Free and public: see the lab, or browse the rest at labs.sarathg.me.
What happens between sessions?
Assignments with real deadlines, which I read and mark. This is the piece most programs skip, and the reason most people who enroll elsewhere never finish.
How do I start?
Book a call, or send the questionnaire if you would rather start in writing. Both routes end at the same place, and pricing is shared once I have read your intake. Quick question first? WhatsApp is fastest.
Start with a conversation.
Either route ends in the same place: a plan built around your actual starting point.