Leviathan Security Group
Leviathan Security Group is a Tukwila, Washington-based cybersecurity consultancy founded in 2006 that delivers penetration testing, risk advisory, IoT security, and vCISO services to enterprise technology clients including Microsoft, Intel, and Google, and was acquired by K2 Integrity in March 2026.
- Company typePrivate
- Founded2006
- HeadquartersSeattle, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Leviathan Security Group does
Leviathan Security Group is a boutique cybersecurity consulting firm founded in 2006 and headquartered in Tukwila, Washington, that delivers expert-led security testing and risk advisory services to enterprise technology companies and federal contractors. Its service catalog spans application and network penetration testing, secure code review, smart device and IoT security assessments, vendor security management, virtual CISO (vCISO) engagements, and tabletop incident-response exercises, with additional specialized assessment programs tied to the Google App Defense Alliance (CASA, MASA, ADA Mobile) and a Shopify Certified Technology Partner track. The firm has produced notable original security research, including the TunnelVision VPN vulnerability disclosure (CVE-2024-3661) and CVE-2024-31735 in LibEvent, which serves as both technical contribution and demand-generation.
The business operates as a professional services firm with a direct, sales-led B2B go-to-market: engagements are custom-quoted based on scope and complexity, often structured as multi-year contracts with enterprise buyers such as Microsoft, Intel, Google, and Geckoboard. Revenue is generated per engagement rather than via subscription or product licensing. Marketing is content-led, relying on blog content and CVE-driven research publications for top-of-funnel visibility, while partner-program credentials (Google, Shopify) act as ecosystem-level distribution. In March 2026, Leviathan was acquired by K2 Integrity as part of the acquirer's technology-focused, AI-enabled strategic direction, with CEO Frank Heidt and the team joining the acquirer; the firm had 11-50 employees at acquisition.
Leviathan Security Group firmographics
Firmographics- Name
- Leviathan Security Group
- Legal name
- Leviathan Security Group
- Website
- https://leviathansecurity.com
- Company type
- Private
- Founded year
- 2006
- Operating status
- Acquired
- Headcount range
- 11–50 employees
- Short description
- Leviathan Security Group is a Tukwila, Washington-based cybersecurity consultancy founded in 2006 that delivers penetration testing, risk advisory, IoT security, and vCISO services to enterprise technology clients including Microsoft, Intel, and Google, and was acquired by K2 Integrity in March 2026.
- Ownership category
- akta.pro rank
Leviathan Security Group industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Investigation and Security Services (5616), Computer Systems Design and Related Services (54151), Investigation and Personal Background Check Services (561611)
- SIC
- Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Security Consulting, Risk Assessment & Security Program Design (BPABAMAE)
- akta.pro secondary industries
- Enterprise Security Strategy & Program Advisory (BPAKADAA), Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG), Executive/Board Security Advisory & Risk Briefings (BPAKADAK), Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF)
Keywords
Where Leviathan Security Group is headquartered
LocationHeadquarters
- HQ city
- Seattle
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Leviathan Security Group business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Professional Cybersecurity Services: Revenue generated from providing cybersecurity consulting services including penetration testing, risk advisory, virtual CISO services, secure code reviews, network penetration testing, hardware security assessments, vendor security management, and tabletop exercises. Services are typically engagement-based with quotes provided to enterprise clients.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom engagement-based pricing |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels2 records
Leviathan Security Group product offering
Product offeringCore offering
Leviathan Security Group provides cybersecurity consulting services, including web application and network penetration testing, secure code reviews, smart device/IoT and premarket medical device security assessments, vendor security management, and risk advisory engagements such as virtual CISO and tabletop exercises. The firm delivers these services directly to enterprise clients through custom engagements led by expert security engineers, and participates in Google App Defense Alliance CASA/MASA programs and Shopify partner security assessments.
Product overview
Leviathan Security Group offers a comprehensive suite of cybersecurity consulting services organized into three main categories: Application and Network Penetration Testing (including Web Application Penetration Testing, Secure Code Review, Network Penetration Testing, and Smart Device/IoT Security Assessment); Risk Advisory Services (including Virtual CISO, Tabletop Exercises, and Vendor Security Management); and specialized assessment programs through partnerships with Google (Nest SDM API Assessment, CASA, MASA), Shopify, and the App Defense Alliance. The company also conducts original security research, notably discovering the TunnelVision (CVE-2024-3661) VPN vulnerability. Founded in 2006 and based in Tukwila, Washington, the firm was acquired by K2 Integrity in March 2026.
Differentiator
Problem solved
Functional benefit
Products and services
- Web Application Penetration Testing In-depth security testing of web applications including DevSecOps advisement and rigorous penetration testing to identify vulnerabilities, delivered to enterprise clients.
- Secure Code Review Meticulous review of source code to identify security vulnerabilities and weaknesses in application development, provided to enterprise engineering teams.
- Network Penetration Testing Security assessment services for enterprise network infrastructure to identify and address network security vulnerabilities.
- Smart Device and IoT Security Assessment Expert security testing for IoT devices, smart devices, and premarket medical technology including wearables, appliances, and virtual devices, delivered to device manufacturers and enterprises.
- Vendor Security Management Assessment, testing, and validation of vendor security controls to help organizations evaluate and select trustworthy third-party vendors.
- Virtual Chief Information Security Officer (vCISO) Executive-level security leadership and advisory services including audit preparation, policy gap analysis, and strategic security guidance delivered on a fractional basis.
- Tabletop Exercises Security incident response exercises designed to test people and processes so client teams can practice handling security incidents before they occur.
- Nest SDM API Security Assessment Security assessment program for Google Nest Device Access with SDM API integration, conducted by Leviathan as a Google-authorized assessor.
- Cloud Application Security Assessment (CASA) Google-backed security assessment program for cloud applications under the App Defense Alliance, conducted by Leviathan for cloud application developers.
- Mobile Application Security Assessment (MASA) Google-certified security assessment program for mobile applications under the App Defense Alliance, enabling Android app developers to complete MASA assessments for Google Play Store certification.
- ADA Mobile Application Security Assessment App Defense Alliance program for mobile application security assessments and certification, conducted by Leviathan.
- Shopify Technology Partner Security Assessment Security assessment service for Shopify merchants and technology partners requiring validation of partner technology solutions, delivered under the Shopify Certified Technology Partner Program.
Quantifiable outcome
- Identified security gaps not uncovered by previous cybersecurity firms
Companies that use Leviathan Security Group
Customer profileNamed customers4 records
Segments3 records
Ideal customer profiles3 records
Leviathan Security Group technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Leviathan Security Group partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and flagship.
- K2 IntegritycoreK2 Integrity acquired Leviathan Security Group in March 2026 to enhance its technology and cybersecurity capabilities as part of the company's technology-focused, AI-enabled strategic direction. Leviathan Security Group, led by Frank Heidt, was integrated into K2 Integrity following completion of the transaction. No deal terms were disclosed.
- Google (App Defense Alliance)flagshipLeviathan is a member of Google's App Defense Alliance, participating in the Cloud Application Security Assessment (CASA) program and Mobile Application Security Assessment (MASA) program. Also conducts Nest SDM API Security Assessments for Google.
- ShopifycoreLeviathan is a Shopify Certified Technology Partner in the Technology Track, providing security assessments and validation for Shopify technology partners.
Scale indicators2 records
Recent moves6 records
Expansion highlights4 records
Leviathan Security Group competitors and assessment
Company assessmentDirect peers
- Bishop Fox: Boutique cybersecurity consulting firm specializing in penetration testing, red teaming, and security assessments for enterprise clients. Closely comparable to Leviathan in service mix, target customers, and boutique engagement model.
- Trail of Bits: Research-driven boutique security firm offering application security assessments, secure code review, and cryptographic consulting. Comparable to Leviathan's research-led approach and enterprise tech client base.
- NetSPI: Enterprise penetration testing and attack surface management firm with a similar service portfolio (pentesting, vulnerability management, advisory). Direct competitor in the application and network security testing space.
- Praetorian: Cybersecurity services firm offering penetration testing, red teaming, and security advisory to enterprise technology clients. Highly comparable in GTM and service offerings to Leviathan.
- TrustedSec: Boutique cybersecurity consulting firm specializing in penetration testing, incident response, and advisory for enterprise clients. Comparable boutique positioning and service focus to Leviathan.
- Cure53: Boutique penetration testing and application security firm with a research-heavy reputation and enterprise tech client base. Closely comparable in size, culture, and assessment depth to Leviathan.
Broad incumbents
- NCC Group: Global cybersecurity services provider with broad capabilities spanning application security, penetration testing, software escrow, and GRC advisory. A larger incumbent overlapping with much of Leviathan's service catalog.
- Coalfire: Cybersecurity advisory firm specializing in GRC, penetration testing, and compliance services for cloud and enterprise environments. Comparable to Leviathan's risk advisory and assessment practice, though at much larger scale.
- Optiv: Large cybersecurity solutions integrator and advisory firm covering assessments, GRC, and managed security services. Overlaps with Leviathan's enterprise risk advisory and assessment offerings but at significantly greater scale.
Emerging players
- Schellman & Co: Specialized compliance and risk advisory firm (SOC 2, ISO, HITRUST, FedRAMP). Comparable to Leviathan's risk advisory, vCISO, and audit preparation practices for enterprise and federal-adjacent clients.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
Leviathan Security Group social profiles
Digital presenceLeviathan Security Group financial estimates
Financial estimateRevenue estimate
Valuation estimate
Leviathan Security Group leadership team
Management profileNumber of profiles
Profiles2 records
Leviathan Security Group funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Leviathan Security Group M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Leviathan Security Group
What does Leviathan Security Group do?
Leviathan Security Group provides cybersecurity consulting services, including web application and network penetration testing, secure code reviews, smart device/IoT and premarket medical device security assessments, vendor security management, and risk advisory engagements such as virtual CISO and tabletop exercises. The firm delivers these services directly to enterprise clients through custom engagements led by expert security engineers, and participates in Google App Defense Alliance CASA/MASA programs and Shopify partner security assessments.
Is Leviathan Security Group a public or private company?
Leviathan Security Group is a private company. It is classified as corporate owned and is currently acquired.
When was Leviathan Security Group founded?
Leviathan Security Group was founded in 2006. It employs 11 to 50 people.
Where is Leviathan Security Group based?
Leviathan Security Group is headquartered in Seattle, United States, in the North America region.
How does Leviathan Security Group make money?
One revenue line is on record: professional Cybersecurity Services.
Who are Leviathan Security Group's main competitors?
Direct peers on record are Bishop Fox, Trail of Bits, NetSPI, Praetorian, TrustedSec and Cure53. Broad incumbents are NCC Group, Coalfire and Optiv. Schellman & Co is listed as an emerging player.
Does Leviathan Security Group have an API?
No public API is recorded for Leviathan Security Group.
What industry is Leviathan Security Group in?
Leviathan Security Group's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPABAMAE, Security Consulting, Risk Assessment & Security Program Design, with a secondary code of BPAKADAA, Enterprise Security Strategy & Program Advisory. Its NAICS code is 5616 and its SIC code is 7381.