// cybersecurity services — las vegas, nv

Find the vulnerabilities
before they do.

Professional security assessments, penetration testing, and code audits for businesses that take their security seriously.

Get a Free Consultation View Packages
// services

What I do.

Targeted security services for web applications, APIs, and infrastructure. Every engagement ends with a clear, actionable report.

[01]

Vulnerability Assessment

Comprehensive scanning and manual testing of your web applications and infrastructure. Prioritized findings with severity ratings and step-by-step remediation guidance your team can act on immediately.

[02]

Penetration Testing

Simulated real-world attacks against your systems. I think like an attacker — testing authentication flows, business logic, and API endpoints — so you can defend like a professional.

[03]

Secure Code Review

Line-by-line security analysis of your source code. Injection points, hardcoded secrets, dependency vulnerabilities, and authentication flaws — found before they reach production.

[04]

API Security Testing

Deep testing of REST and GraphQL APIs for authorization bypasses, IDOR vulnerabilities, injection attacks, rate limiting gaps, and data exposure in responses.

[05]

Security Consulting

One-on-one guidance for startups and small businesses. Build your security posture from scratch with plain-English recommendations and a prioritized action plan.

[06]

AI/LLM Security Audit

Security review of AI-integrated applications, MCP servers, and LLM pipelines. Prompt injection testing, data leakage analysis, and agent governance assessment.

[07]

Prompt Injection Testing

Direct and indirect injection attacks, system prompt extraction, tool-call abuse, and jailbreak attempts. Practical mitigations — not just theoretical risk ratings.

[08]

Multi-Agent System Audits

Agent-to-agent trust boundaries, privilege escalation paths, MCP server hardening, and orchestration layer security. Built for teams deploying autonomous AI pipelines.

[09]

Bug Bounty Consulting

Active researcher on HackerOne, Bugcrowd, and Intigriti. Help your team scope a program, set up triage workflows, and think like an attacker before you go public.

// packages

Transparent pricing.

Choose the package that fits your needs. Every tier includes a professional report with actionable findings.

Recon
$125 flat
Quick security health check
  • Automated vulnerability scan
  • Top 10 critical findings report
  • Risk severity ratings (Critical/High/Medium/Low)
  • Basic remediation guidance
  • 1 target (website or API)
  • Delivered in 24-48 hours
Get Started
Sweep
$250 flat
Targeted manual assessment
  • Everything in Recon
  • Manual testing of top 5 vulnerability classes
  • Authentication and session security review
  • Basic API endpoint review
  • Up to 2 targets
  • Remediation priority list
  • Delivered in 48-72 hours
Get Started
Siege
Custom
Scoped engagements for complex needs
  • Everything in Strike, scaled to your scope
  • Multi-system security assessments
  • Comprehensive source code security review
  • AI/LLM application security audits
  • Custom timelines for larger codebases
  • Extended remediation support
  • Direct access throughout engagement
  • Scoped and priced after consultation
Contact for Scoping
// resources

Security resources.

Self-service tools and guides for teams that want to improve their security posture on their own schedule.

Browse All Resources on Gumroad →
// about

Who I am.

I'm Jesus Sandoval, founder of DeathAngel Security, based in Las Vegas, Nevada. I specialize in finding security vulnerabilities in web applications, APIs, and AI-integrated systems before malicious actors do.

I'm an active bug bounty hunter on HackerOne and maintain a security-first approach to everything I build and test. My focus is on delivering clear, actionable findings — not checkbox compliance reports that collect dust.

Every client gets direct access to me throughout the engagement. No account managers, no ticket queues, no runaround. You talk to the person doing the work.

Toolkit

Burp Suite
Semgrep
Nuclei
GitLeaks
TruffleHog
Trivy
OWASP ZAP
Nmap
Grype
Hadolint
Checkov
pip-audit
deathangel_sec — active on HackerOne, Bugcrowd, Intigriti
// process

How it works.

Simple, fast, and transparent. Most engagements complete within a week.

01

Scope

Free 15-minute call. We define what's in scope, agree on timeline and price. No surprises.

02

Test

Automated scanning plus manual testing. I look for what scanners miss — logic flaws, auth bypasses, business-layer vulnerabilities.

03

Report

Professional findings document with severity ratings, proof-of-concept, and specific remediation steps your dev team can act on.

04

Support

Questions after delivery? I'm here. Fixes verified at no extra charge within 30 days.

// sample

What you get.

Every engagement delivers a professional security assessment report. Here's what one looks like.

SAMPLE REPORT PREVIEW

Security Assessment Report — [Client Name]

15-20 pages covering executive summary, methodology, detailed findings with severity ratings, proof-of-concept screenshots, and step-by-step remediation guidance.

3
Critical Findings
7
High/Medium Findings
FINDING DA-2026-001 — Critical
SQL Injection in /api/v2/users endpoint
Impact: Full database access, user credential exposure
Remediation: Parameterized queries, input validation...
Request a Sample Report
// contact

Let's talk.

Ready to find out what's vulnerable? Reach out for a free initial consultation.

Location
Las Vegas, NV — Available Worldwide (Remote)