About Derrouiche
French
Native or bilingual
English
Fluent
Spanish
Fluent
Experience
- ACCORPentesterHOSPITALITYJuly 2022 - Today (3 years and 11 months)- Web / API Application Penetration Testing- Red Team type testing targeting the hotel IS- Internal Penetration Testing (Networks, Active Directory)- Code Auditing (Java EE, PHP, .Net)- Conducting training / Security awareness sessions- Audit report with detailed remediation plan- Remediation follow-up using the DefectDojo tool
- BNP PARIBASRed Team / PentesterBANKING AND INSURANCESeptember 2018 - August 2022 (3 years and 11 months)Paris, FranceConducting Red Team type missions:Logical Intrusion:- Open Source Intelligence (OSINT) phase, gathering and analyzing information on the targeted organization: Web applications, information system (public addressing plan), employee names, list of partners / service providers- External information system surface discovery phase: exposed services (port scanning), technologies used, security equipment- Offensive testing phase on external servicesSocial Engineering:This approach aims to exfiltrate authentication information or gain access to the organization's internal network by exploiting techniques such as phishing.- Profiling phase, to identify a list of people to target for the phishing campaign (OSINT)- Definition of scenarios for the phishing campaign (Downloading malicious files containing a backdoor, for example)- Campaign execution, exploitation of the backdoor after the malicious file is executed. Collection of indicators (statistics on email reception/reading/malicious link opening)Physical Intrusion:- Active reconnaissance phase: perimeter discovery of the premises / employees, identification of surrounding wireless networks- Physical intrusion and deployment of an implant on the internal network to gain remote access (WiFi or 4G antenna)- Offensive testing on the internal network.
- DevoteamSecurity Consultant: PentesterDIGITAL AND ITMay 2016 - September 2018 (2 years and 4 months)92300 Levallois-Perret, FranceConducting technical audits:- Web Application Penetration Testing- Network Penetration Testing- Mobile Penetration Testing (iOS, Android)- Code Auditing (Java EE, PHP, .Net)- Audit report with recommendations for code and architecture improvementsConducting physical/architecture audits:- Assessment of the security of physical sites (access control) and the information system architecture
Recommendations
Be the first to recommend Derrouiche
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Master's degree in Computer Science, Systems and NetworksUniversité de Technologie de Compiègne2016Diplome d'ingénieur en Informatique, Système et réseaux
- Computer Engineering, Computer Systems Networking and TelecommunicationsTampere University of Technology2015Ingénieur en Informatique, Mise en réseau de systèmes informatiques et télécommunications