855-TRUSEC-1 (878-7321) [email protected]

About TruSec

Experienced leadership. Practical security outcomes.

TruSec Consulting combines offensive security, risk management, audit, privacy, and resilience experience to help organizations understand and reduce meaningful cyber risk.

Our Approach

More than identifying vulnerabilities.

The goal is not to produce the longest possible list of findings. The goal is to show which weaknesses create practical risk and help the client address them.

TruSec works collaboratively with technical teams, business leaders, and compliance stakeholders. We define clear rules of engagement, communicate material risks during testing, and deliver reports that combine executive context with the technical evidence needed for remediation.

Each engagement benefits from direct senior involvement, practical judgment, and experience spanning cybersecurity testing, information risk management, audit, business resiliency, and regulated environments.

How TruSec adds value

  • Direct senior involvement throughout the assessment
  • Manual validation separates meaningful risk from scanner noise
  • Testing is tailored to production constraints and business objectives
  • Reports are usable by executives, auditors, and technical teams
  • Clients can communicate directly with the assessor responsible for the work
Eric Gomez, founder and principal security assessor at TruSec Consulting

Founder & Principal Security Assessor

Eric Gomez

Direct accountability from scope through reporting.

Connect on LinkedIn

Eric Gomez is the founder and principal security assessor at TruSec Consulting. He brings more than 25 years of experience across information security, IT auditing, risk management, compliance assurance, and technology consulting.

Eric remains directly involved throughout TruSec engagements, from defining the scope and evaluating security controls through communicating material findings and reviewing the final deliverables. His work emphasizes careful validation, practical remediation guidance, and reporting that is useful to leadership, technical teams, and auditors.

His experience includes penetration testing, social engineering assessments, information security audits, business continuity planning, incident response, forensic investigations, and security-awareness training. He has worked extensively with financial institutions and other organizations operating in regulated environments.

Eric holds a Bachelor of Business Administration in Accounting from Florida Atlantic University and is a member of InfraGard, the Information Systems Security Association (ISSA), and ISACA. He has earned multiple professional certifications across information security, IT audit, business continuity, and ethical hacking.

  • 25+ yearsInformation security, audit, risk, and compliance
  • Cross-disciplinarySecurity testing, audit, risk, and resilience
  • BBA, AccountingFlorida Atlantic University
  • Professional membershipsInfraGard, ISSA, and ISACA

Capabilities

A multidisciplinary view of security and risk.

TruSec’s work combines hands-on technical assessment with the governance and business context needed to support defensible decisions.

OFF

Offensive Security

Network, application, API, cloud, wireless, social engineering, and approved physical security testing.

RISK

Risk & Compliance

Security program assessments, IT audits, regulatory alignment, privacy, and third-party risk support.

IR

Response & Resilience

Incident preparedness, tabletop exercises, business resiliency, investigation support, and remediation planning.

Professional Standards

Methodical testing grounded in recognized practices.

TruSec applies structured assessment methods, disciplined rules of engagement, and practical judgment throughout every engagement. Testing approaches are informed by recognized security and risk practices, including PTES, OWASP, NIST, PCI DSS, and other requirements relevant to the client’s environment.

Frameworks provide consistency, but the work is never treated as a checklist. Each assessment is tailored to the organization’s actual systems, threat exposure, operational constraints, and business priorities.

  • Risk-Based Testing
  • Manual Validation
  • Controlled Exploitation
  • Clear Rules of Engagement
  • Executive-Level Reporting
  • Actionable Remediation
  • PTES
  • OWASP
  • NIST
  • PCI DSS
  • HIPAA
  • SOC 2
  • ISO 27001

Engagement Commitments

Clear expectations. Ethical testing. Direct communication.

AuthorizedTesting is performed within approved scope and rules of engagement.
ControlledTechniques are selected to validate risk while minimizing operational disruption.
ActionableMaterial findings include context, evidence, impact, and remediation guidance.

Looking for an assessment partner?

Start with a short scoping conversation about your environment, concerns, and requirements.

Talk with TruSec