PROFILE / INDEX© Clément Depernet / 2026

Profile, experience, education, skills

Résumé

  • 2024Cyber career since
  • MajorMaster's Cybersecurity & Cloud
  • OFF+DEFDual offensive / defensive posture
  • 3Working languages
01

Profile

Cybersecurity, Cloud and distributed-systems expert, graduated top of class, specialised in offensive security (pentest, reverse engineering, forensics) and defensive security (IAM, Cloud, PKI, SIEM). With LessonSharing since 2024, while running engagements in parallel through his own company for large accounts, public institutions and engineering schools, combining a strong teaching focus with hands-on field expertise.

02

Experience

  1. 2024 — presentACTIF

    Cybersecurity trainer & consultant — permanent contract

    LessonSharing

    Technical engagements, audits, training and strategic advisory for public and private organisations.

    • Penetration tests and architecture reviews for large accounts and public institutions.
    • Design and delivery of cybersecurity modules in engineering schools (offensive, defensive, Cloud).
    • Support on compliance and hardening of Cloud and IAM environments.
    Burp SuiteGhidraWiresharkAzure AD / Entra IDTerraformWazuh
  2. 2024 — presentACTIF

    Cybersecurity consultant — independent activity maintained in parallel

    Own company

    Own company maintained alongside permanent employment: the engagements listed below were contracted and delivered independently.

    • Direct ownership of client engagements: scoping, quoting, delivery, debrief.
    • Penetration tests and architecture reviews for large accounts and public institutions.
    • Support on compliance and hardening of Cloud and IAM environments.
    Burp SuiteGhidraWiresharkAzure AD / Entra IDTerraformWazuh
  3. 2026-05 — 2026-07

    Application pentest & API security

    Hexafret

    Penetration-testing campaign on business applications and exposed APIs, followed by a prioritised remediation plan built with the development teams.

    • Grey-box penetration testing of the business web applications.
    • API audit: authentication, authorisation, data exposure (OWASP API Top 10).
    • Hunt for business-logic flaws and access-control bypasses (IDOR, BOLA).
    • Dependency and build-chain review (SCA, hard-coded secrets).
    • Automated replay of attack scenarios in CI (security regression testing).
    • Remediation plan prioritised by severity, with developer coaching.
    Burp SuiteOWASP ZAPsqlmapPostmanSemgrepTrivy
  4. 2026-01 — 2026-04

    Cyber upskilling — industrial teams

    TotalEnergies

    International training programme on OT / IT convergence and industrial-systems security.

    • Industrial-systems security (SCADA, ICS).
    • Network segmentation into zones and conduits (ISA/IEC 62443).
    • Cyber-incident handling in OT environments.
    • Industrial-protocol vulnerabilities (Modbus, OPC).
    • Awareness training on targeted attacks (Stuxnet-like scenarios).
    SCADA / ICSISA/IEC 62443ModbusOPCOT / IT
  5. 2025-10 — 2025-12

    Advanced cryptography & PKI

    Boursobank

    Applied cryptography and PKI training, then roll-out of an internal certificate authority and automated certificate renewal.

    • How a complete PKI works (Root CA / Intermediate CA).
    • TLS handshake in detail: PFS, ECDHE, cipher suites.
    • Certificate life-cycle management: rotation, CRL, OCSP.
    • Set-up of an internal certificate authority.
    • Automated renewal (ACME-style, scripts).
    • TLS error analysis and configuration hardening (Mozilla guidelines).
    PKIOpenSSLTLS 1.3ACMEOCSP / CRLMozilla TLS guidelines
  6. 2025-06 — 2025-09

    Cloud security training

    Orange Cyberdefense

    AWS / Azure Cloud security training and support of the teams through a hardened migration.

    • Hardening of AWS and Azure environments.
    • IAM and principle of least privilege.
    • Monitoring (CloudWatch, Microsoft Sentinel).
    • Logging and detection (SIEM, XDR).
    • Cloud-migration support: risk analysis (ENISA, CSA CCM).
    • Infrastructure hardening: network segmentation, Security Groups, NSGs.
    • Roll-out of DevSecOps best practices.
    AWSAzureCloudWatchMicrosoft SentinelSIEM / XDRCSA CCMENISA
  7. 2025-03 — 2025-05

    API security — audit & architecture

    Softway Medical

    REST API security audit, then implementation of the controls and target Zero Trust architecture.

    • REST API security audit: identification of OWASP API Top 10 vulnerabilities.
    • Strong authentication: OAuth2, JWT hardening.
    • Rate limiting and denial-of-service protection.
    • Strict input validation (schema validation).
    • Dynamic testing with Burp, Postman and automated scripts.
    • Secure-architecture recommendations (Zero Trust API).
    OWASP API Top 10OAuth2JWTBurp SuitePostmanZero Trust
  8. 2024-11 — 2025-02

    Ethical Hacking & Pentest training

    French Ministry of Armed Forces

    Full offensive-security training: methodology, exploitation, post-exploitation and pivoting, backed by realistic Red Team / Blue Team labs.

    • Penetration-testing methodology (OWASP, PTES).
    • Vulnerability exploitation: SQLi, RCE, LFI/RFI, SSRF.
    • Post-exploitation: privilege escalation on Linux and Windows.
    • Network pivoting (proxychains, chisel, ligolo).
    • Set-up of realistic Red Team / Blue Team labs.
    • Awareness training on adversary techniques (MITRE ATT&CK).
    NmapMetasploitBurp SuiteBloodHoundCrackMapExecMITRE ATT&CK
  9. 2024-09 — presentACTIF

    Cybersecurity trainer

    Engineering schools (IPSSI, GEMA…)

    Design of complete cybersecurity curricula and supervision of student projects, from offensive security to secure Cloud.

    • Complete curricula: web, mobile and infrastructure pentesting.
    • Forensics: memory analysis (Volatility, Autopsy).
    • Reverse engineering: binaries, Android apps, IoT firmware (Ghidra, jadx).
    • Applied cryptography: PKI, TLS, certificate management.
    • Student-project supervision: IAM (Keycloak, LDAP), secure Cloud (AWS, Azure), DevSecOps pipelines.
    • Hands-on Docker / Kubernetes lab sessions.
    VolatilityAutopsyGhidrajadxKeycloakLDAPAWSAzureDockerKubernetes
03

Skills

OFF

Offensive security

Pentest web / API
Pentest interne / AD
Reverse engineering
Forensic / DFIR
OSINT / recon
Exploit dev
DEF

Defensive security

IAM / Zero Trust
PKI / gestion de certificats
SIEM / détection
Durcissement système
Réponse à incident
Threat modeling
CLD

Cloud & infrastructure

AWS / Azure / OCI
Docker / conteneurs
Kubernetes
Terraform / IaC
CI/CD & supply chain
Linux / réseau
EDU

Teaching

Ingénierie pédagogique
Conception de labs / CTF
Animation & prise de parole
Sensibilisation utilisateurs
Rédaction technique
Vulgarisation direction
04

Education

  1. 2021 — 2024

    Master's ESI — Cybersecurity & Cloud

    IPSSI

    Top of class

  2. 2014 — 2017

    BSc Psychology

    Aix-Marseille Université

    Useful background: human factor, social engineering, pedagogy.

05

Languages

  • C2FrenchNative
  • C1EnglishFluent
  • B1SpanishIntermediate
SEC / OPS / CD-01

Astro + Tailwind, containerised, served behind Caddy · Inspiration · Startup theme: Severance (Theodore Shapiro) · Cute favicon, isn't it?

READY / CD-01