Offensive Security
Network, application, API, cloud, wireless, social engineering, and approved physical security testing.
About TruSec
TruSec Consulting combines offensive security, risk management, audit, privacy, and resilience experience to help organizations understand and reduce meaningful cyber risk.
Our Approach
The goal is not to produce the longest possible list of findings. The goal is to show which weaknesses create practical risk and help the client address them.
TruSec works collaboratively with technical teams, business leaders, and compliance stakeholders. We define clear rules of engagement, communicate material risks during testing, and deliver reports that combine executive context with the technical evidence needed for remediation.
Each engagement benefits from direct senior involvement, practical judgment, and experience spanning cybersecurity testing, information risk management, audit, business resiliency, and regulated environments.
Founder & Principal Security Assessor
Direct accountability from scope through reporting.
Connect on LinkedInEric Gomez is the founder and principal security assessor at TruSec Consulting. He brings more than 25 years of experience across information security, IT auditing, risk management, compliance assurance, and technology consulting.
Eric remains directly involved throughout TruSec engagements, from defining the scope and evaluating security controls through communicating material findings and reviewing the final deliverables. His work emphasizes careful validation, practical remediation guidance, and reporting that is useful to leadership, technical teams, and auditors.
His experience includes penetration testing, social engineering assessments, information security audits, business continuity planning, incident response, forensic investigations, and security-awareness training. He has worked extensively with financial institutions and other organizations operating in regulated environments.
Eric holds a Bachelor of Business Administration in Accounting from Florida Atlantic University and is a member of InfraGard, the Information Systems Security Association (ISSA), and ISACA. He has earned multiple professional certifications across information security, IT audit, business continuity, and ethical hacking.
Capabilities
TruSec’s work combines hands-on technical assessment with the governance and business context needed to support defensible decisions.
Network, application, API, cloud, wireless, social engineering, and approved physical security testing.
Security program assessments, IT audits, regulatory alignment, privacy, and third-party risk support.
Incident preparedness, tabletop exercises, business resiliency, investigation support, and remediation planning.
Professional Standards
TruSec applies structured assessment methods, disciplined rules of engagement, and practical judgment throughout every engagement. Testing approaches are informed by recognized security and risk practices, including PTES, OWASP, NIST, PCI DSS, and other requirements relevant to the client’s environment.
Frameworks provide consistency, but the work is never treated as a checklist. Each assessment is tailored to the organization’s actual systems, threat exposure, operational constraints, and business priorities.
Engagement Commitments
Start with a short scoping conversation about your environment, concerns, and requirements.