Inside the Mind of a Red Teamer: A Conversation with Orgito, Co-Founder & Security Researcher at RTA

Red Team Albania (RTA) is a new offensive security company built in Tirana, bringing red teaming, penetration testing, threat intelligence, and hands-on security training to the Western Balkans. Ahead of the company’s official launch, we sat down with co-founder and security researcher Orgito Leka to talk about the origins of RTA, the philosophy behind the work, and what it takes to build a security company from the ground up in a region that’s still building its cybersecurity culture.
Q: Let’s start with the basics, what is RTA, and why did you start it?
RTA stands for Red Team Albania. At its core, we’re an offensive security company, we simulate real attacks against organizations so they can find and fix their weaknesses before an actual attacker does. We started it because we saw a gap: the Western Balkans has a growing pool of technical talent, but very few companies here are doing serious, standards-driven offensive security work. We wanted to build something that could hold its own against international firms while staying rooted in this region.
Q: You’re based in Tirana. What’s it like building a cybersecurity company there right now?
It’s early days for the ecosystem, honestly. There’s real talent, a lot of it coming out of programs like 42 Tirana, but the market itself is still maturing. That’s part of why we’re doing this. We’re not just trying to run engagements; we want to help grow the culture around security here, which is why training and community are baked into what we do, not an afterthought.
Q: Tell us about the team. RTA isn’t a huge company, how did it come together?
We’re a small team, three of us, and we all came up through 42 Tirana. That shared background matters. We didn’t just meet each other; we went through the same intense, project-based, no-instructors way of learning, which shapes how you approach problems. When you’re used to figuring things out without someone handing you the answer, that translates directly into how you approach a red team engagement, you’re constantly probing, testing assumptions, and adapting.
Q: What services does RTA actually offer?
We work across five lines: Red Teaming, Penetration Testing, Threat Intelligence, Research, and something we call RTA Academy, which covers training, CTFs, and internships. On the engagement side, our core packages are penetration testing, full red team operations, AI and LLM security assessments, and security audits paired with threat intelligence work.
The AI and LLM security piece is something we’re particularly focused on. As more companies bolt AI features onto their products, the attack surface changes in ways a lot of traditional security testing doesn’t cover. We wanted to make sure we weren’t just offering yesterday’s services.
Q: Walk us through how an engagement actually runs.
We follow a six-phase methodology: Scoping, Reconnaissance, Exploitation, Post-Exploitation, Reporting, and Retest. It sounds straightforward on paper, but the discipline is in not skipping steps under time pressure. Scoping is where a lot of engagements actually succeed or fail, if you don’t nail down exactly what’s in bounds and what the client actually needs answered, everything downstream suffers.
The retest phase is one people sometimes treat as optional, and we don’t. Finding vulnerabilities is only half the job. Confirming that what was fixed is actually fixed is what makes the whole engagement worth something to the client.
Q: What standards or frameworks does RTA build its work around?
We align with MITRE ATT&CK, OWASP’s WSTG and ASVS, PTES, NIST SP 800–115, and CVSS v3.1 for scoring. And we follow coordinated disclosure practices, that’s non-negotiable for us. Working against recognized frameworks isn’t just about credibility with clients; it keeps our own methodology honest and repeatable instead of ad hoc.
Q: You mentioned RTA Academy. Why put training and internships into a red team company’s business model?
Because the talent pipeline doesn’t build itself. If we want a real offensive security scene in this region, we have to help create the next generation of people who can do this work, not just hire from an already-thin pool. RTA Academy is our way of doing that, training, CTF events, and internships that give people a real, hands-on way in, rather than just theory.
Q: Can you talk about the launch event?
We’re launching September 1st at 42 Tirana, a one-hour presentation followed by a one-hour CTF, open to 42 students. We wanted the launch itself to reflect what RTA is about: not just an announcement, but something people actually get to participate in and test their skills against.
Q: Any final thoughts for people watching RTA get off the ground?
Just that we’re building this deliberately and for the long term. Offensive security is a trust business, clients are letting us try to break into their systems, which means everything we do has to be rigorous, methodical, and disclosed responsibly. That’s the standard we’re holding ourselves to from day one.
RTA (Red Team Albania) is an offensive security company based in Tirana, offering red teaming, penetration testing, threat intelligence, research, and security training across the Western Balkans.