Senior Cybersecurity Engineer - Leyton
(2024-08)
International consulting group — corporate security team
- Lead vulnerability assessments across 50+ business applications using SonarQube and GitHub Advanced Security, triaging findings so engineering teams remediate the highest risks first.
- Run dynamic application security testing with Burp Suite Pro and OWASP ZAP to confirm which weaknesses are genuinely exploitable, eliminating false positives before they reach developers.
- Deployed and administer the company's Wazuh + ELK SIEM platform, including custom detection rules and dashboards that give security and IT operations shared incident visibility.
- Handle security incidents end to end — detection, investigation, containment and reporting — and deliver phishing simulation and awareness programs reaching 200+ employees.
Cybersecurity / DevSecOps Engineer - OHM Énergie
(2023-09 - 2024-05)
- Audited production cloud environments across Docker, Kubernetes, AWS and GCP, identifying 30+ critical CVEs and driving them to remediation with platform teams.
- Embedded automated SAST and DAST gates into GitLab CI and Jenkins pipelines, contributing to a 70% reduction in vulnerabilities reaching production.
- Centralized security monitoring on Prometheus, Grafana and Elasticsearch, giving the team unified alerting across previously siloed services.
- Secured a microservices architecture including Knative and Kafka workloads, and eliminated hard-coded credentials by migrating secrets to HashiCorp Vault.
Security Engineer - RIBATIS
(2023-02 - 2023-09)
- Designed and implemented a secure CI/CD architecture with automated security testing built into every build, and containerized legacy applications following Docker security best practices.
- Conducted web application penetration tests using OWASP methodology and delivered prioritized remediation reports.
R&D Cybersecurity Engineer - Secure-IC
(2022-02 - 2023-01)
Embedded systems security — hardware and industrial devices
- Researched vulnerabilities in embedded Linux systems and industrial device firmware, feeding findings into internal security improvement work.
- Built Python and Bash tooling for network traffic analysis and automated security testing, and ran internal penetration tests to support remediation planning.