You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Julien MartinJM

Julien Martin

Pentester OSCP | Web & API Penetration Testing

€685/day
Strasbourg, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Julien

I find the vulnerabilities in your Web and API applications before an attacker does.

Certifiedethical hackingconsultantOSCP**, I have over **10 years of experiencein systems, networks, and cybersecurity, acquired in demanding environments such asOrange,theDGFiP,andGeneral Electric**. I have also conducted over **50 security audit missions**, covering **varioustechnical and organizational contexts.

🎯Specialty: Web & API Penetration Testing

I adopt the posture of a real attacker, not a mechanical checklist.
The objective: identify what is truly exploitable and measure its impact on your business.

- Web penetration testing (OWASP Top 10): injections, broken authentication, XSS, IDOR, privilege escalation, business logic...
- REST API security testing (OWASP API Security Top 10): access control, sensitive data exposure, undocumented endpoints...
- Re-tests and patch validation

☁️Also available for

Cloud security audits (AWS, Azure, GCP) and hybrid On-premise / Cloud architectures.

📄Deliverables included in each mission

A dual-level report:

Executive Summary: Business impact, overall risk level, remediation priorities
Technical Report: Detailed vulnerabilities, proof of exploitation, actionable recommendations

+ A formalized certificate of completion at the end of the mission.

Have a project in mind? Write to me!
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Strasbourg (up to 50km), Sélestat (up to 50km), Colmar (up to 50km), Mulhouse (up to 50km)

Experience

  • BonjourCyber
    Pentester | Auditor | Red Team
    CONSULTING AND AUDITS
    April 2024 - Today (2 years and 4 months)
    Strasbourg, France
    • Conducting in-depth penetration tests on web applications, network infrastructures, and internal systems to identify exploitable vulnerabilities.
    • Designing, executing, and managing targeted phishing campaigns to assess and improve employee security awareness.
    • Leading technical audit debriefing sessions, providing detailed analysis and strategic recommendations to technical and non-technical teams.
    • Providing technical support during commercial qualifications, including penetration testing demonstrations and risk assessments for clients.
    • Actively contributing to the evolution of internal tools.
    Cybersecurity Ethical Hacking Project Management PenTest Training Delivery
  • GeneralElectric
    Application Security Engineer
    ENERGY AND UTILITIES
    April 2023 - March 2024 (11 months)
    Territoire de Belfort, France
    - Conducting penetration testing (pentest) campaigns using blackbox, greybox, and whitebox approaches to identify vulnerabilities.
    - Developing detailed reports and in-depth assessments of detected vulnerabilities, providing clear recommendations for risk mitigation.
    - Exhaustively documenting all stages of testing campaigns, including methodology, tools used, and results obtained.
    - In-depth analysis of test results, including vulnerability exploitation to assess their potential impact on overall system security.
    - Managing the follow-up and implementation of corrective actions to address discovered vulnerabilities, ensuring they are resolved effectively and securely.
    - Close collaboration with development and operations teams to ensure a clear understanding of risks and security requirements.
    - In-depth source code analysis to identify potential vulnerabilities in applications.
    PenTest Cybersecurity Project Management Data Analysis Ethical Hacking
  • Direction générale des Finances publiques
    Project Manager
    PUBLIC SECTOR
    December 2022 - April 2023 (4 months)
    Strasbourg, France
    - Leading the deployment of infrastructure and technical integration architectures, as well as interfaces with other SI components.
    - Monitoring and coordinating qualification campaigns: installation, performance, monitoring, and backup/restore tests.
    - Installation and deployment of applications, and technical tests: functionality tests, production plan, exploitability.
    - Detection, reporting, support, and follow-up of anomalies during integration platform deployments.
    - Analysis and diagnosis of results: Incident tracking and workaround proposals. Production support (support during production deployments and within the incident management process). and skills transfer to ESI qualification center teams.
    - Qualification of documentation intended for production centers (installation guides, operating procedures, intervention sheets).
    Project Management Qualification Data Analysis Technical Documentation Software Deployment

Recommendations

Mickael V.MV
NK
Thomas R.TR
+1
Mickael V. and 3 other people have recommended Julien

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Architect in Systems and Network Engineering, Information Systems Security / Safety
    EPITECH - European Institute of Technology
    2021
    Architecte en ingénierie système et réseau, Sécurité / sûreté de l''information des systèmes informatiques
  • Bachelor's degree in Information Systems Administration and Security
    University of Haute-Alsace
    2019
    Licence en administration et sécurité de l'information des systèmes

Certifications

Skill set

Categories