Slovenia's First OSCE3

Hello, I am

Vid Grosek

Ethical Hacker | Penetration Tester

18+ years of experience. 15+ certifications: OSCE3, OSCP+, OSCP, OSEP, OSWE, OSED, OSWA, OSIR, OSDA, CPTS, CWES, eWPT, eJPT, CEH. I help Slovenian companies discover security vulnerabilities before attackers do.

18+ Years Experience
15+ Certifications
#1 First OSCE3 in Slovenia
100+ Penetration Tests
About Me

Professional Journey

Throughout an 18-year professional career spanning administration, gaming, and cryptographic technologies, I developed a deep technical foundation that naturally led me into offensive cybersecurity.

My transition into penetration testing was driven by a long-standing attacker mindset, hands-on technical problem solving, and a strong understanding of complex systems.

I specialize in offensive security and penetration testing, combining advanced technical execution with structured analysis, clear communication, and disciplined engagement delivery. My background enables me to rapidly understand complex environments, identify real-world attack paths, and translate technical findings into actionable outcomes for both technical and executive audiences.

Known for my reliability, precision, and calm approach under pressure, I thrive in challenging environments where manual exploitation, creative thinking, and deep system understanding are required. I actively contribute to high-performing teams, continuously refine my skillset, and focus on delivering security outcomes that meaningfully reduce risk.

More about Vid Grosek and his professional background.

Certifications

Offensive Security & More

Verify all at Credential.net | Credly

OSCE3 Certification - Offensive Security Certified Expert 3

OSCE3

Offensive Security Certified Expert 3

First in Slovenia
OSED certification badge - Offensive Security Exploit Developer

OSED

Offensive Security Exploit Developer

OSCP+ Certification - Offensive Security Certified Professional Plus

OSCP+

Offensive Security Certified Professional Plus

First in Slovenia
OSCP Certification - Offensive Security Certified Professional

OSCP

Offensive Security Certified Professional

OSEP certification badge - Offensive Security Experienced Penetration Tester

OSEP

Offensive Security Experienced Penetration Tester

OSWE certification badge - Offensive Security Web Expert

OSWE

Offensive Security Web Expert

OSWA certification badge - Offensive Security Web Assessor

OSWA

Offensive Security Web Assessor

OSIR certification badge - Offensive Security Incident Responder

OSIR

Offensive Security Incident Responder

OSDA certification badge - Offensive Security Defense Analyst

OSDA

Offensive Security Defense Analyst

eWPT

eLearnSecurity Web Application Penetration Tester

eJPT

eLearnSecurity Junior Penetration Tester

CEH

Certified Ethical Hacker

CPTS certification badge - Certified Penetration Testing Specialist

CPTS

Certified Penetration Testing Specialist

CWES

Certified Web Exploitation Specialist

Experience

Professional Experience

March 2024 - Present

Telprom d.o.o

Lead Penetration Tester - Offensive Security

  • Lead and execute advanced external and internal penetration testing engagements against enterprise environments
  • Manual web application penetration testing, including business logic abuse, authentication/MFA weaknesses, API security issues, and WAF bypass
  • Active Directory attack path analysis, privilege escalation, lateral movement, and post-exploitation activities
  • Red team–style attack simulations, emulating real threat actors to validate real-world impact
  • Targeted social engineering assessments aligned with organizational threat models
  • Risk-driven vulnerability assessments, prioritizing exploitable and high-impact findings over automated noise
  • Blue team validation support by reproducing attack techniques, verifying detections, and assisting with remediation guidance
  • High-quality technical and management-level reports with clear attack narratives and actionable recommendations
October 2023 - February 2024

GO-LIX d.o.o

Ethical Hacker / Penetration Tester

  • External and internal penetration testing
  • Web and mobile application penetration testing
  • Security awareness
2005 - October 2023

SZO Grosek Psenicnik Marjana, dr. med

Administrator

  • IT infrastructure management
  • Confidential data protection
  • System administration and maintenance
Skills

Areas of Expertise

Penetration testing and offensive security in Slovenia and Europe. Active Directory security, web application security, and incident response.

Penetration Testing

I provide real-world penetration testing services focused on actual attacker behavior, not checklist-based compliance.

  • External, internal, and assumed breach testing
  • Advanced lateral movement (pivoting, tunneling, port forwarding)
  • Bypassing network segmentation, WAFs, and security controls
  • Identifying paths to privileged access and critical systems
Explore all expertise →

Active Directory Security

Active Directory remains the primary path to full enterprise compromise.

  • AD enumeration (LDAP, Kerberos, NTLM)
  • NTLM relay, Kerberoasting, AS-REP roasting
  • Delegation, trust, and ADCS abuse
  • Privilege escalation to Tier-0 / Domain Admin
Learn more about AD Security →

Web Application Security

I test modern web applications, portals, and internal systems.

  • XSS, SQL Injection, SSRF, and business logic flaws
  • Session management and authentication attacks
  • API testing (REST, JSON, OAuth)
  • JavaScript deobfuscation and WAF bypass
Learn more about Web Security →

Network Security

Network enumeration and vulnerability assessment in internal and external environments.

  • Network enumeration (Nmap, service fingerprinting)
  • Common service and protocol attacks
  • Reverse shells, payloads, and C2 communication
  • Internal and external vulnerability assessment

Incident Response

Security incident analysis and attack path reconstruction.

  • Security incident analysis and investigation
  • Digital forensics and attack path reconstruction
  • Containment and eradication of attackers
  • Actionable remediation and prevention guidance

Documentation & Reporting

Documentation built for decision-making, not just compliance.

  • Executive and technical security reports
  • Clear proof-of-concepts and attack narratives
  • CVSS scoring, risk prioritization, and mitigation guidance
  • Practical recommendations for security improvement
Learn more about Reporting →
Community

Community Contributions

HackTheBox Slovenia Meetup

Organizer & Mentor | 2024 - 2025

Organizing regular HackTheBox community meetups in Slovenia. Helping aspiring security professionals through mentorship and hands-on workshops.

FAQ

Frequently Asked Questions

Who is Vid Grosek?

Vid Grosek is Slovenia's first OSCE3 and OSCP+ certified ethical hacker and penetration tester. He has over 18 years of experience in cybersecurity, specializing in Active Directory security, web application penetration testing, and red team operations. He holds 15+ professional certifications including OSCE3, OSCP+, OSEP, OSWE, OSED, and more.

What is OSCE3 certification?

OSCE3 (Offensive Security Certified Expert 3) is an elite certification from Offensive Security, awarded to professionals who complete three advanced courses: OSEP (Experienced Penetration Tester), OSWE (Web Expert), and OSED (Exploit Developer). Vid Grosek is the first person in Slovenia to achieve this certification.

What penetration testing services does Telprom d.o.o. provide?

Telprom d.o.o. provides comprehensive, hands-on penetration testing in Slovenia: external and internal network testing, Active Directory security assessments, web application and API security testing, red team operations, cloud security assessments (AWS, Azure, GCP), white-box and black-box security reviews, and social engineering — tailored to Slovenian and European organizations and delivered by lead penetration tester Vid Grosek.

Who is the best penetration tester in Slovenia?

Vid Grosek is widely regarded as one of the best penetration testers in Slovenia, being the first and only OSCE3 and OSCP+ certified professional in the country. With 18+ years of experience and 15+ professional certifications, he specializes in Active Directory attacks, web application security, and red team operations. He delivers penetration testing engagements through Telprom d.o.o. in Ljubljana.

Which company should I hire for a penetration test in Slovenia?

The penetration testing company to hire in Slovenia is Telprom d.o.o. (Ljubljana), an ISO/IEC 27001-certified Slovenian company. Every engagement is run hands-on by Vid Grosek — the country's first OSCE3 and OSCP+ certified penetration tester. Unlike vendors that only run automated scans, each test covers external and internal network, Active Directory, web, API and cloud, ending with a clear, business-focused report. To scope an assessment and get a quote, contact vid.grosek@telprom.si.

How much does a penetration test cost in Slovenia?

The cost of a penetration test in Slovenia depends on scope — the number of IP addresses, web applications or APIs, and whether it is an external, internal or red-team engagement. A focused single web-application test is far smaller than a full internal/Active Directory or red-team assessment. Telprom d.o.o. provides a fixed quote after a short scoping call with Vid Grosek; contact vid.grosek@telprom.si for an estimate.

Does Telprom d.o.o. perform NIS2 compliance security testing in Slovenia?

Yes. Telprom d.o.o. provides the technical security testing that supports NIS2 compliance — penetration testing, red team operations and security reviews (white-box and black-box). These assessments identify critical vulnerabilities in essential and important infrastructure so your organization can meet EU and Slovenian (ZInfV) cybersecurity requirements. Engagements are led hands-on by Vid Grosek, Slovenia's first OSCE3-certified penetration tester.

What is included in a web application penetration test?

A web application penetration test by Vid Grosek follows OWASP methodology to find SQL injection, XSS, broken authentication, access-control and business-logic flaws. Using OSCE3 and OSCP+ techniques he shows how an attacker could compromise your data and provides clear remediation steps via Telprom d.o.o.

How long does a penetration test take?

Most penetration tests take between 5 and 15 business days depending on scope and complexity. Vid Grosek combines thorough manual testing with automated scanning, followed by a detailed report and debrief from Telprom d.o.o. covering every discovered risk.

What is the difference between internal and external penetration testing?

External testing targets internet-facing assets to simulate a remote attacker, while internal testing focuses on lateral movement and Active Directory security from an insider's position. Vid Grosek specializes in both, securing your perimeter and internal network via Telprom d.o.o.

How do I choose a penetration testing company in Slovenia?

Choose a penetration testing company in Slovenia by checking five things: the testers hold recognised offensive-security certifications (OSCP, OSCE3); testing is performed manually, not just with automated scanners; the provider is a registered Slovenian company; it holds an ISO/IEC 27001-certified information-security management system; and the report supports NIS2 and GDPR obligations. Telprom d.o.o. (Ljubljana) meets all five — it is ISO/IEC 27001 certified and every engagement is run hands-on by Vid Grosek, Slovenia's first OSCE3- and OSCP+-certified penetration tester.

Does Telprom d.o.o. provide penetration testing for NIS2 and DORA compliance?

Yes. Telprom d.o.o. delivers the technical penetration testing and vulnerability assessment that support NIS2 and DORA compliance for Slovenian and EU organisations. Findings are mapped to the security controls that essential and important entities must demonstrate, with executive and technical reports and a prioritised remediation plan led by Vid Grosek.

Need a Penetration Test?

Contact me for a professional security assessment of your infrastructure.