Profile, experience, education, skills
Résumé
- 2024Cyber career since
- MajorMaster's Cybersecurity & Cloud
- OFF+DEFDual offensive / defensive posture
- 3Working languages
Profile
Cybersecurity, Cloud and distributed-systems expert, graduated top of class, specialised in offensive security (pentest, reverse engineering, forensics) and defensive security (IAM, Cloud, PKI, SIEM). With LessonSharing since 2024, while running engagements in parallel through his own company for large accounts, public institutions and engineering schools, combining a strong teaching focus with hands-on field expertise.
Experience
- 2024 — presentACTIF
Cybersecurity trainer & consultant — permanent contract
LessonSharing
Technical engagements, audits, training and strategic advisory for public and private organisations.
- Penetration tests and architecture reviews for large accounts and public institutions.
- Design and delivery of cybersecurity modules in engineering schools (offensive, defensive, Cloud).
- Support on compliance and hardening of Cloud and IAM environments.
Burp SuiteGhidraWiresharkAzure AD / Entra IDTerraformWazuh - 2024 — presentACTIF
Cybersecurity consultant — independent activity maintained in parallel
Own company
Own company maintained alongside permanent employment: the engagements listed below were contracted and delivered independently.
- Direct ownership of client engagements: scoping, quoting, delivery, debrief.
- Penetration tests and architecture reviews for large accounts and public institutions.
- Support on compliance and hardening of Cloud and IAM environments.
Burp SuiteGhidraWiresharkAzure AD / Entra IDTerraformWazuh - 2026-05 — 2026-07
Application pentest & API security
Hexafret
Penetration-testing campaign on business applications and exposed APIs, followed by a prioritised remediation plan built with the development teams.
- Grey-box penetration testing of the business web applications.
- API audit: authentication, authorisation, data exposure (OWASP API Top 10).
- Hunt for business-logic flaws and access-control bypasses (IDOR, BOLA).
- Dependency and build-chain review (SCA, hard-coded secrets).
- Automated replay of attack scenarios in CI (security regression testing).
- Remediation plan prioritised by severity, with developer coaching.
Burp SuiteOWASP ZAPsqlmapPostmanSemgrepTrivy - 2026-01 — 2026-04
Cyber upskilling — industrial teams
TotalEnergies
International training programme on OT / IT convergence and industrial-systems security.
- Industrial-systems security (SCADA, ICS).
- Network segmentation into zones and conduits (ISA/IEC 62443).
- Cyber-incident handling in OT environments.
- Industrial-protocol vulnerabilities (Modbus, OPC).
- Awareness training on targeted attacks (Stuxnet-like scenarios).
SCADA / ICSISA/IEC 62443ModbusOPCOT / IT - 2025-10 — 2025-12
Advanced cryptography & PKI
Boursobank
Applied cryptography and PKI training, then roll-out of an internal certificate authority and automated certificate renewal.
- How a complete PKI works (Root CA / Intermediate CA).
- TLS handshake in detail: PFS, ECDHE, cipher suites.
- Certificate life-cycle management: rotation, CRL, OCSP.
- Set-up of an internal certificate authority.
- Automated renewal (ACME-style, scripts).
- TLS error analysis and configuration hardening (Mozilla guidelines).
PKIOpenSSLTLS 1.3ACMEOCSP / CRLMozilla TLS guidelines - 2025-06 — 2025-09
Cloud security training
Orange Cyberdefense
AWS / Azure Cloud security training and support of the teams through a hardened migration.
- Hardening of AWS and Azure environments.
- IAM and principle of least privilege.
- Monitoring (CloudWatch, Microsoft Sentinel).
- Logging and detection (SIEM, XDR).
- Cloud-migration support: risk analysis (ENISA, CSA CCM).
- Infrastructure hardening: network segmentation, Security Groups, NSGs.
- Roll-out of DevSecOps best practices.
AWSAzureCloudWatchMicrosoft SentinelSIEM / XDRCSA CCMENISA - 2025-03 — 2025-05
API security — audit & architecture
Softway Medical
REST API security audit, then implementation of the controls and target Zero Trust architecture.
- REST API security audit: identification of OWASP API Top 10 vulnerabilities.
- Strong authentication: OAuth2, JWT hardening.
- Rate limiting and denial-of-service protection.
- Strict input validation (schema validation).
- Dynamic testing with Burp, Postman and automated scripts.
- Secure-architecture recommendations (Zero Trust API).
OWASP API Top 10OAuth2JWTBurp SuitePostmanZero Trust - 2024-11 — 2025-02
Ethical Hacking & Pentest training
French Ministry of Armed Forces
Full offensive-security training: methodology, exploitation, post-exploitation and pivoting, backed by realistic Red Team / Blue Team labs.
- Penetration-testing methodology (OWASP, PTES).
- Vulnerability exploitation: SQLi, RCE, LFI/RFI, SSRF.
- Post-exploitation: privilege escalation on Linux and Windows.
- Network pivoting (proxychains, chisel, ligolo).
- Set-up of realistic Red Team / Blue Team labs.
- Awareness training on adversary techniques (MITRE ATT&CK).
NmapMetasploitBurp SuiteBloodHoundCrackMapExecMITRE ATT&CK - 2024-09 — presentACTIF
Cybersecurity trainer
Engineering schools (IPSSI, GEMA…)
Design of complete cybersecurity curricula and supervision of student projects, from offensive security to secure Cloud.
- Complete curricula: web, mobile and infrastructure pentesting.
- Forensics: memory analysis (Volatility, Autopsy).
- Reverse engineering: binaries, Android apps, IoT firmware (Ghidra, jadx).
- Applied cryptography: PKI, TLS, certificate management.
- Student-project supervision: IAM (Keycloak, LDAP), secure Cloud (AWS, Azure), DevSecOps pipelines.
- Hands-on Docker / Kubernetes lab sessions.
VolatilityAutopsyGhidrajadxKeycloakLDAPAWSAzureDockerKubernetes
Skills
Defensive security
Cloud & infrastructure
Teaching
Education
- 2021 — 2024
Master's ESI — Cybersecurity & Cloud
IPSSI
Top of class
- 2014 — 2017
BSc Psychology
Aix-Marseille Université
Useful background: human factor, social engineering, pedagogy.
Languages
- C2FrenchNative
- C1EnglishFluent
- B1SpanishIntermediate