Professional Summary

Offensive Security Engineer and exploit developer, specialized in vulnerability research, reverse engineering, and production-grade exploit development.

Currently open to senior offensive security roles, including international and relocation opportunities.

Professional Experience

Paris, France

LeakIX, Security Researcher

  • Writing plugins for vulnerability detection on the platform
  • Setting up R&D labs to reproduce n-day vulnerabilities
  • Vulnerability monitoring and research
Paris, France

Onepoint, Offensive Security Intern (Pentesting focus)

  • Conducted penetration tests and security assessments, with a focus on web application testing
  • Performed security evaluations for APIs and mobile applications targeting clients in critical sectors: finance, banking, insurance, and the public sector
  • Identified vulnerabilities with potential impact on sensitive infrastructures
Antony, France

UPFRONT TECHNOLOGIES, Offensive Security Intern (Pentesting focus)

  • Participation in penetration tests and security assessments, contributing to various technical engagements
  • Performed audits and vulnerability assessments
  • Developed offensive security skills while training for the eJPT and OSWP certifications

Education

Paris, France

Master's Degree - Cybersecurity and Computer Science (Technical Expert track)

Oteria Cyber School
Strasbourg, France

Bachelor's Degree in Computer Science, specialization in Web Development

University of Strasbourg
Haguenau, France

High School Diploma (French Scientific Baccalaureate - Engineering Sciences option)

Heinrich Nessel High School

Open Source Contributions

The Metasploit Project, Contributor

  • Top contributor in 2024/2025
  • Development of exploit modules for Metasploit
  • Creation and enhancement of payloads and auxiliary modules
  • Contribution to the community by adding new offensive features

LeakIX, Hunter & Moderator

  • Monitoring of CVEs and 0-day vulnerabilities
  • Moderation of submitted vulnerability reports
  • Reporting security flaws to CERTs or affected entities
  • Writing PoCs to support plugin development

Projects

pgread - Read PostgreSQL data files without credentials - forensics, data recovery, and security research tool
WPProbe - A fast WordPress plugin enumeration tool
LFIHunt - LFI Exploitation Tool in Python
LeakPy - LeakIX API Interaction Tool in Python

Awards

SVGTranslate RCE - Wikimedia
Recognition by WPScan for LFI-to-RCE escalation in Extensive VC Addons for WPBakery Page Builder - WPScan
Recognition by Amazon for discovering a critical vulnerability in their bug bounty program - Amazon

Certifications

Learn Intermediate Go Course - Codecademy
Learn Go Course - Codecademy
API Penetration Testing - APIsec University
eJPT (eLearnSecurity Junior Penetration Tester) - INE
Certified Network Security Practitioner - The SecOps Group
Certified AppSec Practitioner - The SecOps Group
CompTIA Pentest+ - CompTIA