You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Hamza DarghouthHD

Hamza Darghouth

Cybersecurity Consultant Appsec / DevSecOps

€450/day
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Hamza

Looking for an Appsec / DevSecOps consultant to join your team?
Do you want to improve your application security?

I am an application security / DevSecOps consultant with over 12 years of experience.
I have worked in various sectors such as banking, insurance, and transportation.
I have had the opportunity to work with companies such as BNP Paribas, AXA, and SNCF.

My services:
- Application vulnerability remediation
- Developer coaching (OWASP Top 10)
- Implementation of a Security Champion program (Shift-Left/Security By Design)
- Implementation of SSDLC/DevSecOps (SAST / SCA / DAST / IAST)

Would you like to discuss your project further? Contact me!
  • French

    Native or bilingual

  • Arabic

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 50km), Lyon (up to 10km), Toulouse (up to 50km), Marseille (up to 50km)

Experience

  • BNP Paribas
    Appsec/DevSecOps Consultant
    BANKING AND INSURANCE
    June 2021 - Today (5 years)
    Paris, France
    BNP Paribas Corporate and Institutional Banking (CIB) is the global investment banking arm of BNP Paribas, the world's largest banking group. BNP Paribas has been ranked by Bloomberg and Forbes as the largest bank and largest company in the world by assets, with over US$3.1 trillion.

    I joined BNPP CIB in July 2021 as an Appsec/DevSecops expert in the Appsec team.

    I performed the following tasks:
    - Application source code and dependency audit
    - Configuration of Fortify/Nexus detection rules
    - Coaching developers/Security Champions on OWASP TOP 10
    - Definition and monitoring of the application vulnerability remediation strategy
    - Assistance with application vulnerability remediation
    - Definition and integration of security requirements into the DevOps approach in terms of organization, processes, and controls.
    - Design and implementation of a DevSecOps platform anomaly automated control framework (Vulnerability processing, SAST/SCA scans, Application onboarding/offboarding)
    - Participation in GO/NO GO production committees (Security in projects/ISP)
    - Team lead (3 consultants)
    Fortify Jenkins Bitbucket Git DevSecOps OWASP Nexus Code Review Python Coaching Appsec Security Champion Cybersecurity
  • Axa
    Appsec/DevSecOps Consultant
    BANKING AND INSURANCE
    December 2019 - May 2021 (1 year and 5 months)
    Paris, France
    AXA is an international group specializing in insurance and asset management services. Founded in 1985, AXA is one of the world leaders in insurance and asset management, operating in over 50 countries worldwide. Its headquarters are located in Paris, France.
    I joined the AXA GO SAST team in January 2020 as a SAST Tech Lead on the Checkmarx source code scanning platform.

    I performed the following tasks:
    - Integration of automated security tests (Jenkins, Checkmarx, GitHub, Azure DevOps, etc.)
    - Administration and troubleshooting of the Checkmarx CxSast SAST platform
    - Assistance to developers for vulnerability remediation
    - Writing secure development guides
    - Analysis of false positives
    - Writing / optimizing Checkmarx CxQueries
    - Development of a tool for generating KPIs from the Checkmarx API (REST, OData)
    - Project management and coordination with different teams
    Checkmarx CxSAST Azure Vulnerability Management Vulnerability Analysis CxQuery REST Python Qualys Cybersecurity
  • SNCF
    Pentester/Redteam
    TRANSPORTATION
    September 2018 - December 2019 (1 year and 3 months)
    Paris, France
    SNCF is a rail transport giant in France. With over 120 years of history, it manages an extensive network of nearly 30,000 kilometers of railway lines. Every day, it transports approximately 4 million passengers and 300,000 tons of goods, making it one of Europe's largest rail operators. Furthermore, it employs over 250,000 people, contributing significantly to the French economy.

    I joined the SNCF Red Team in 2018 as a Senior Pentester.
    I performed the following tasks:
    - Analysis of Android mobile application source code
    - Study, formalization, and extraction of Indicators of Compromise (IoCs) in Windows environments to create custom SIEM rules
    - Presentation of audit results to project committees
    - Follow-up and post-patch verification of vulnerabilities
    PenTest Web Pentest Red Team Vulnerability Management Kali Linux Offensive Security

Recommendations

Issam C.IC
Aymen GabsiAG
Nicolas Tran BinhNT
Issam C. and 2 other people have recommended Hamza

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Computer Engineering Degree
    INSAT
    2012
    Réseau/Télécom

Certifications

  • OSCP
    Offensive Security
    2016
    PenTest
  • AWS Certified Solution Architect Associate
    AWS
    2023
    Amazon Web Services AWS

Skill set

Categories