About Anas
Cybersecurity Consultant - Pentest, Red Team & Vulnerability Management
- Expert in information system protection and realistic attack simulation.
- Solid experience in Pentest, Red Team, vulnerability management (VOC), and offensive R&D, certified OSWE & OSCP+
- Supporting companies in detecting, analyzing, and remediating vulnerabilities, while optimizing processes and KPIs.
- Development of custom tools and dashboards to make security operational and understandable.
- Proactive approach: strategic monitoring, offensive testing, and automation to reduce real risks.
French
Native or bilingual
Arabic
Native or bilingual
English
Native or bilingual
Experience
- ConfidentielVulnerability Management AnalystSOFTWARE PUBLISHINGJuly 2025 - Today (1 year and 1 month)Paris, France
- Piloting vulnerability management activities: monitoring, scans (Qualys, Cyberwatch, Rapid7), exploitability analysis, and risk prioritization.
- Facilitating operational vulnerability committees and monitoring remediation plans.
- Designing and tracking KPIs to measure the health of the IS and security posture.
- "Purple team" contribution: combining defensive and offensive approaches to test and validate the effectiveness of security measures.
- Continuous reduction of remediation times and overall improvement of IS resilience.
- ConfidentielConfirmed VOC Analyst - Threat & Vulnerability ManagementPHARMACEUTICALS INDUSTRYJuly 2022 - May 2025 (2 years and 10 months)Paris, France
- Establishment of a Vulnerability Operations Center (VOC): design of infrastructure, workflows, and processes.
- Management of 4000+ assets via Tenable, Qualys, HTTPCS, and Bitsight; centralization of results in Hackuity.
- Automation of 70% of manual tasks and prioritization of vulnerabilities using CVSS v3/v4 and EPSS.
- Reduction of critical vulnerability remediation time by 40% and securing 5000+ systems during CVE crises.
- Improvement of the Bitsight score through proactive vulnerability management.
- OSINT investigations (credential leaks, exposed databases) and implementation of countermeasures.
- Orange CyberdefenseConfirmed Pentester AuditorTECHSeptember 2021 - June 2025 (3 years and 9 months)Casablanca, Morocco
- Conducted 50+ pentests (web applications, mobile, internal infrastructures: LAN, Active Directory) for banking/insurance clients.
- Led 10+ Red Team operations including phishing, OSINT, physical and logical intrusions.
- Developed Python tools that reduced reporting time by 30%.
- Supervised and trained 5 junior auditors on application and infrastructure testing methodologies.
- Modeled attack surfaces from OSINT and Threat Intelligence.
- Wrote detailed technical reports and presented strategic summaries.
- Pre-sales support: commercial proposals, tender responses, client demonstrations (Pentest, VOC, Red Team).
Recommendations
Be the first to recommend Anas
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- STATE ENGINEERING DIPLOMA IN COMPUTER SCIENCENational Higher School of Computer Science and Systems Analysis (ENSIAS)2021DIPLÔME D'INGÉNIEUR D'ÉTAT EN INFORMATIQUE
Certifications
- OffSec Web Expert (OSWE)Offsec2025