You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Chris W.CW

Chris W.

Pentester | Cybersecurity Expert | OSCP | PASSI

€450/day
3 projects
Paris, FR
15+ years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Chris

Hello and welcome,

I have been working for several years with clients of all sizes, from SMEs to CAC40 groups, as well as with public sector organizations, to assess and strengthen the security of their information systems.

I am OSCP and PASSI certified, which allows me to undertake penetration testing, architecture audits, source code audits, configuration audits, as well as acting as an audit manager.

My assignments focus mainly on two areas:

1. Technical audits and penetration testing:

- Needs analysis to define the scope of the audit (e.g., security assessment of a web application, web API, or Active Directory network infrastructure).

- Performing penetration tests.

- Identification of vulnerabilities, qualification of business risks, and formulation of concrete recommendations.

- Writing detailed reports summarizing the overall assessment and the tests performed.

- Clear and structured restitution, both technical and managerial.

2. Specialized audits:

- Configuration audit: analysis and optimization of system and application parameters.

- Architecture audit: evaluation of the design of on-premise or cloud systems and infrastructures to ensure their robustness.

- Source code audit: secure code review to detect vulnerabilities and propose appropriate corrections.

If my skills match your needs or if you would like to know more, please do not hesitate to contact me to discuss.
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 50km)

Experience

  • INSEE
    Technical Audit
    PUBLIC SECTOR
    November 2024 - November 2024
    Paris, France
    Web application penetration testing

    Performing comprehensive penetration tests on web applications to assess their resistance to common attacks (injections, XSS, CSRF, authentication bypass, etc.).

    Using specialized tools (Burp Suite, OWASP ZAP, Nmap, Nikto, Metasploit) and manual methods to identify vulnerabilities not detected automatically.

    Applying security standards such as OWASP Top 10, CWE/SANS, and best practices for application hardening.

    Developing technical and executive reports detailing vulnerabilities, their criticality level, and tailored remediation recommendations.

    Contributing to the validation of fixes and raising awareness among development teams on application security.
    Penetration Testing Cybersecurity Risk and Vulnerability Assessment
  • EDF
    Technical Audit
    ENERGY AND UTILITIES
    October 2024 - December 2024 (2 months)
    Nanterre, France
    Performing manual and automated penetration tests on internal web applications to identify security vulnerabilities (injections, XSS, CSRF, poor session management, etc.).

    Using tools such as Burp Suite, OWASP ZAP, Nmap, Nikto, and Metasploit for vulnerability detection and exploitation.

    Writing detailed reports presenting discovered vulnerabilities, their criticality, and remediation recommendations according to OWASP Top 10 and CWE/SANS standards.

    🔹 Infrastructure Component Configuration Audit

    Analyzing and evaluating the security of systems and equipment: servers (Linux, Windows), firewalls, routers, and databases.

    Identifying misconfigurations (open ports, excessive privilege accounts, outdated protocols, lack of encryption).

    Developing audit reports and assisting technical teams in implementing corrective actions.
    Penetration Testing Kali Linux Cybersecurity Risk and Vulnerability Assessment
  • Ministère de la Transition Ecologique
    Technical Audit
    PUBLIC SECTOR
    September 2024 - October 2024 (1 month)
    Paris, France
    Conducting penetration tests on web applications: attack surface analysis, component mapping, exploitation of potential vulnerabilities (SQL injections, XSS, CSRF, deserialization, poor session management).

    Writing technical reports and remediation recommendations for development teams.
    Penetration Testing PASSI Risk Analysis

Reviews

5.0

Out of 1 rating

F

Fabien

ContactMedia

Reviewed on 6/10/2022

Hello, Chris is very professional, provides great advice, I recommend Chris for your cybersecurity missions. We will work with Chris again soon.

Recommendations

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Master Networks and Cybersecurity
    Pierre et Marie Curie Paris 6
    2008
    Informatique, programmation, cyber sécurité, bases de données, scripting.

Certifications

  • OSCP Offensive Security Certified Professional
    Offensive Security
    2021
    https://www.credly.com/badges/049aeda0-db41-4ee7-a3b4-deed0d8cd5bb
    Networking Application Attacks Penetration Test Ethical Hacking Active Directory Vulnerability Scanning
  • PASSI (Information System Security Audit Provider)
    LSTI
    2025
    Configuration Audit Audit Manager Penetration Test Source Code Audit Architecture Audit

Skill set (32)

Categories