You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Jean-Baptiste AstarieJA

Jean-Baptiste Astarie

AppSec .NET | Pentest & Audit | OSCP

€650/day
21 projects
La Rochelle, FR
3-7 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Jean-Baptiste

Your developers are good at delivering the features that provide **value to your products**. But who is in charge of the security of your application and your clients? You need efficient and secure applications: a one-time audit or long-term support? I intervene according to your needs.

With15 years of .NET development**, including a validated **contributionto the officialMicrosoftdotnet/runtime repository, I have taken these shortcuts myself. I know where they lead and how to fix them. Security doesn't stop at the code: a misconfigured server is enough to expose a robust application.

CertifiedOSCPand **HTB CWES**, I regularly practice bug bounty on YesWeHack to stay in touch with real-world vulnerabilities.

Here's what it looks like in practice:
  • Creation of a shared security department (5 people) at a software vendor: internal audits, developer training, CVE monitoring. The system persisted after my departure.
  • Coordination of post-pentest remediation on a critical energy sector project (47,000 users): SonarQube/Checkmarx monitoring, runbooks, team empowerment.

Insupport missions**, the objective is concrete: to propose **solutions adapted to the project**, such as raising developer awareness of the **OWASP Top 10**, implementing **automatic detectionof trivial vulnerabilities (SonarQube, Semgrep, ...), or **integrating cyber risk into team practices**.

Services:
  • Web and API audit (blackbox/greybox)
  • Source code audit
  • Remediation support
  • Training and awareness for developers and system administrators
Typical clients:SaaS vendors, tech SMEs, large corporations with a .NET stack.
  • English

    Conversational

  • French

    Native or bilingual

Remote only
Primarily works remotely

Experience

  • Editeur de logiciel (Confidentiel)
    Malt logoOn Malt
    Web & Mobile Android Application Security Audit
    SOFTWARE PUBLISHING
    July 2025 - July 2025
    Security audit mission for a composite application (Web portal + Android mobile application) in a multi-tenant SaaS environment.

    Methodological Approach:

    • Blackbox: Mapping of the attack surface and intrusion tests without privileges
    • Mobile analysis: Static and dynamic analysis of the Android application
    • Greybox: In-depth audit with provided accounts (privilege escalation, access controls, isolation)
    • Reporting: Writing the audit report, classifying vulnerabilities, and client presentation

    Deliverables:

    • Detailed audit report with vulnerability classification
    • Prioritized remediation recommendations
    Tools: Burp Suite Pro, Frida, MobSF, Python scripting
    Intrusion Testing Mobile Pentest Burp Suite Web Pentest
  • Editeur de logiciel (Confidentiel)
    Malt logoOn Malt
    Web Application Security Audit
    May 2024 - June 2024
    Intrusion test on a complex Web application. Mission carried out in mixed mode (blackbox + greybox) with application security objectives.
    Web Pentest Security Audit Intrusion Testing SonarQube
  • Ordanche Solutions
    Pentester - Cybersecurity Auditor
    DIGITAL AND IT
    August 2022 - Today (3 years and 9 months)
    Independent application security consultant activities:
    • Web, API, and mobile (Android) penetration testing
    • Source code auditing and DevSecOps support
    • Active bug bounty hunter on YesWeHack (20 vulnerabilities validated, including 6 critical/high)
    • Remediation support and skills transfer
    Security Audit Vulnerability Management Cybersecurity Intrusion Testing

Reviews

4.8

Out of 16 ratings

B

Benoit

mc²i Groupe

Reviewed on 9/10/2018

Very good developer and very responsive.
B

Benoit

mc²i Groupe

Reviewed on 7/11/2018

Very good work!

Recommendations

TM
Sebastien LubranoSL
Thierry Mercier and 1 other person have recommended Jean-Baptiste

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Professional Bachelor's Degree in Biotechnology, specializing in Information Systems and Modeling Applied to Bioinformatics
    Université Clermont-Ferrand I
    2006

Certifications

Skill set

Categories