Ethical Hacker
CurrentWeb Application Penetration Testing:- Pentesting internet facing web applications, SaaS applications, web APIs and e-banking solutions in Black Box and Grey Box perspective, applying the OWASP methodology.Infrastructure penetration testing:- External network vulnerability assessment with automatic and manual tools, applying both OSINT and offensive security methods. Social engineering:- Carrying out phishing campaigns by setting up the infrastructure, developing the malicous websites and scenarios and processing the data according to ISO27001. Managing and developing phishing tools.- Physical intrusion engagementMobile application testing:- Testing Android and iOS mobile applications through automated and manual tools; reverse engineering and API testing.Tools development:- Developing internal pentest tools with Python and bash scripting with their concise technical documentation.Other activities:- Leading Kick-Off meetings with customers to organise the assessments- Writing detailed security assessment reports in English and French, presenting the results to technical and managerial audiences.- Managing Linux and Windows machines on local infrastructure through different virtualisation products, contributing to keeping the infrastructure up-to-date, secure and carrying out troubleshooting.