Takaharu Ogasa, founder of Security Initiative and a leader in the OWASP Sendai community, describes an unconventional move from software development into penetration testing and security consulting. His journey began with a serious mistake, continued through self-funded training and community building, and ultimately became a lesson in pricing expertise with confidence.
Connect with Takaharu on X and LinkedIn.
Takaharu worked as a web developer for about 15 years. Around 2014, a small script he wrote caused the loss of a customer’s data. The incident shook his confidence and made him consider changing careers. While attending conferences and community talks, he encountered security work that matched what he already enjoyed: analysis, debugging, and understanding how systems fail.
He studied the security market outside Japan and noticed that penetration testing was less established locally than security assessment. To gain hands-on training, he borrowed one million yen from an acquaintance, travelled to the United States for a course, and returned to establish a one-person business in 2015. An instructor who led an OWASP chapter encouraged him to create a local chapter as a way to exchange knowledge and build a community.
The data-loss incident was painful, but it also exposed the scale of harm a tiny technical error could create. Instead of leaving technology entirely, Takaharu examined the parts of his work that held his interest. Security offered a way to apply his debugging instincts to adversarial questions and to help prevent failures. The career change therefore built on existing strengths rather than discarding his earlier experience.
Launching the company required both financial risk and practical learning. Formal training supplied skills, while OWASP created opportunities to speak, meet practitioners, and develop trust. Takaharu initially managed the chapter work and presentations himself, which increased his visibility and connected the business to a wider professional network. Community contribution was not presented as a sales tactic, but it became an important part of building his place in the field.
Takaharu normally begins early with coffee and one or two hours of reading. Continuous learning is part of the job rather than an occasional extra. He then runs or cycles before opening his computer around 10 a.m. Email and chat come first, followed by focused blocks for penetration-testing projects.
Because he does not consider himself effective at rapid multitasking, he assigns different periods of the day to individual customers. Work may resume after dinner, but he describes security as closely integrated with his life and personal interests. Exercise and reading give that long day structure.
His strongest business warning is aimed at new founders who lack funds and confidence. Lowering prices can seem like the easiest way to win early customers, but Takaharu resisted that approach. Growth took more than three years, yet he believes preserving the value of the service was the better long-term choice. He also encourages people to experiment with work that genuinely interests them instead of simply reproducing what others already offer.