The team

Meet the people who will actually do the work.

Every specialist on your engagement is named in the proposal, with public work you can read before you sign.

Discuss your scope
200+ audits between them
2 Heads of Security on the advisory team
1 principal on every engagement

OSCP · OSWE · CREST CRT · CISM · AWS Security · CVE disclosures · U.S. patents

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

  • Rust
  • NEAR & Substrate
  • Custody

Timur founded Guvenkaya after seeing teams reduce security to code review while their real risk spans architecture, infrastructure, operations, custody, and launch decisions. Before Guvenkaya, he established and led a security engineering practice for complex blockchain systems, specializing in Rust-based and non-EVM ecosystems including Substrate and NEAR. Earlier at Invicti, he helped build enterprise vulnerability-scanning and security detection engines used by Fortune 50 companies and public-sector organizations.

Müjde Nur Asgarli Güvenkaya portrait

Müjde Nur Asgarli Güvenkaya

Growth & Marketing Partner

  • MBA
  • Performance marketing
  • Growth strategy

Müjde leads growth and marketing, bringing hands-on agency experience in performance marketing, data-led strategy, and audience-specific campaign planning. On the agency side she has worked with major brands across healthcare, e-commerce, and other sectors, translating business goals into focused growth strategies for different markets and audiences. She holds a Bachelor's degree in International Affairs and a Master's in Business Administration.

Piotr Cielas portrait

Piotr Cielas

Principal Advisor

  • OSCP
  • OSWE
  • U.S. patents

Piotr is Head of Security at Agora, where he oversees information security, cybersecurity, data protection, and corporate IT risk management. He brings both industry and consulting experience, having led information security advisory engagements and security program development for global financial institutions and large organizations. Earlier in his career, Piotr was a Senior Cybersecurity Consultant at Ernst & Young (EY), leading security assessments across financial services, healthcare, and government. He holds CEH, OSCP, and OSWE certifications, has contributed to the CVE program, and is the inventor of multiple U.S. patents related to information security and blockchain technology.

Currently

Head of Security, Agora

$45B+ in volume

Paul Vijender portrait

Paul Vijender

Specialist Advisor

  • CISM
  • Cloud & IAM
  • DevSecOps

Paul is Head of Security at Gauntlet, a hands-on security leader experienced in building and operating teams that secure assets in some of the most adversarial environments on the planet. He is a security generalist with specialist depth spanning product security, IAM, cloud security, network and data security (DLP), DevSecOps, blockchain security, and infosec and compliance, and has advised and delivered engagements for Fortune 500 firms, big-tech companies, and frontier-technology startups across crypto and AI. Earlier he was Head of Security at Tensor and a Senior Cybersecurity Manager at EY, and held security roles at Broadcom and ADP. He holds the CISM certification.

Currently

Head of Security, Gauntlet

$1.6B+ TVL

Michal Bajor portrait

Michal Bajor

Specialist Advisor

  • Exchange & custody
  • 60+ reviews
  • 3 research papers

Michal is a security expert with a Master's in ICT, three published research papers, and active academic research in blockchain technology. He has reviewed 60+ Web3 projects across DeFi, L1 systems, bridges, oracles, and other critical ecosystem components. At Kraken, he was responsible for security across crypto and fiat funding services, custody, B2B APIs, on-chain monitoring, smart-contract risk, and architectural and compliance reviews. Earlier at EY, he conducted web application penetration tests, participated in red-team activities, and worked across defensive security responsibilities; at Cisco, he supported Security Advisory penetration-testing work and internal cybersecurity training.

Łukasz Mikuła portrait

Łukasz Mikuła

Specialist Advisor

  • 100+ audits
  • 8+ ecosystems
  • CVE disclosures

Łukasz is a security researcher with 10+ years in offensive security and a public portfolio of 100+ audits across 8+ ecosystems. His smart-contract work spans EVM/Solidity, Move, Rust-based ecosystems, CosmWasm, Solana, Substrate, and TON, including assessments for Coinbase, MegaETH, Kyber, Jupiter, Zilliqa, IOTA, and Initia Move. At ING, he worked across web application and infrastructure penetration testing, red-team work, exploit development, reverse engineering, mobile security, adversary simulation, and smart-device testing. At Binance, he worked on security concerns for high-scale digital asset systems. He has CVE disclosures affecting IBM, Oracle, F5, Dell, and Red Hat.

José C. Ramírez portrait

José C. Ramírez

Specialist Advisor

  • OSCP
  • CREST CRT
  • AWS Security

José is a security engineer and technical trainer specializing in smart contract and blockchain security, with around 10 years of experience across offensive security, application security, and security review. At ZKsync, he reviewed code, architecture, and design across Solidity/EVM, account abstraction, protocol-level security, and Rust-based components, later building AI-assisted workflows for vulnerability discovery and protocol security analysis. He has participated in smart contract audits across CosmWasm, EVM, and NEAR and holds OSCP, CREST CRT, AWS Certified Security, and AWS Certified Solutions Architect certifications. José has also delivered university courses, guest lectures, and workshops on blockchain and smart contract security, including at the University of Málaga and with the University of Porto.

Staffing

How your engagement gets staffed.

Three example scopes and the team each assigns: a custody review, a smart contract review and a penetration test each draw a different set of specialists, and each carries exactly one principal

Same firm, three different teams. The specialists follow the system.

01

The system decides the team

Not availability. A custody review and a runtime review need different people, so we read the scope first.

02

One principal, plus the specialists it needs

The principal scopes, QAs the report, and owns communication. On a narrow scope they may run the review alone.

03

Specialists review, write, and retest

They run the review and write the report, work remediation with the principal, then retest once you have shipped fixes.

04

You know the team before you sign

Whoever the principal assigns is named in the proposal, with the reports they wrote. Kickoff is not the first time you hear their names.

The firm

Founded

2022

Origin

Guvenkaya began from one observation: the hardest security problems rarely live in code alone. Serious teams need someone who can look across architecture, infrastructure, operations, and engineering practice, then say what actually matters. Timur Güvenkaya founded the firm in 2022 after establishing and leading a security engineering practice for complex blockchain systems, and earlier building enterprise security detection engines at Invicti used by Fortune 50 companies and public-sector organizations.

Scope it with a principal, not a salesperson.

Tell us what needs securing. We will reply with the next questions, a likely scope, and the engineers who would be named on it.

Discuss your scope