You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Maxime J.MJ

Maxime J.

Offensive Cybersecurity Expert (OSWE) | Web Pentest

€600/day
Nice, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Maxime

OSWE certified offensive security expert, I assist companies in identifying and correcting their critical vulnerabilities before they are exploited.

My profile stands out with dual expertise: in-depth source code auditing (Whitebox approach) and mastery of new risks related to Artificial Intelligence.

Administrator of Root-Me, the reference platform for cybersecurity learning, I cultivate a rigorous pedagogical approach. I ensure that my audit reports are not only technical but also understandable and actionable for your decision-making and development teams.

MY AREAS OF EXPERTISE


1. Web Audit & Penetration Testing (Pentest)
  • Researching advanced vulnerabilities (OWASP Top 10 and business logic).
  • Source code auditing (Whitebox).
  • Securing APIs and complex application architectures.
2. Generative AI Security
  • Security auditing of solutions integrating LLMs (Large Language Models).
  • Identifying specific risks (Prompt Injection, data poisoning).
  • Advising on secure architecture for AI projects

WHY WORK WITH ME?

Certified Expertise: The OSWE (Offensive Security Web Expert) certification guarantees an advanced methodology, going beyond automated scans to analyze code in depth.

Communication & Pedagogy: Drawing on my community and association experience, I prioritize relationships and clear reporting.

Constant Technical Monitoring: My daily involvement in the Root-Me community and my role as Lead AI require me to stay at the forefront of the state-of-the-art.

Let's discuss your security needs to define the most suitable audit scope for your context.
  • French

    Native or bilingual

  • English

    Fluent

Remote only
Primarily works remotely

Experience

  • ORANGE
    Lead Cybersecurity / AI Engineer
    DIGITAL AND IT
    October 2022 - Today (3 years and 10 months)
    Mougins, France
    [2022-Today]

    Pentests - Blackbox & Whitebox

    Multiple Pentests on Web and Desktop applications with and without source code access
    Advanced vulnerability testing (CORS Regex Bypass, CSP Bypass, Cookie Bombing, Blind XXE, SSTI, Cache Poisoning, etc.)
    Expert vulnerability testing (HRS/H2C, HPP, SSPP, CpDoS, Secondary Context Attacks, Dangling Markup Injection, HTTP Hop-by-Hop Header Injection, etc.)

    [2025-Today]

    Product Owner / Lead - AI-Native SAST

    Development of an internal AI-Native SAST solution
    • Use of agent frameworks (LangChain/LangGraph)
    • Use of Context Engineering methods (AST Slicing, Inter-component graphs, Business constraints)
    • Use of LLM Engineering methods (Chain of Thoughts, Prompt Paraphrasing, HITL, Less is More, etc.)
    Management of a full-time developer
    Communication and adoption of the tool among internal auditors

    [2022-Today]

    Product Owner / Lead - EASM

    Development of a in-house EASM solution
    • Blue-Green deployment on GCP following best practices (TP, CAB)
    • Building the solution for security issue detection (nuclei, xsstrike, sqlmap, wfuzz)
    • Automation of ticket creation and closure
    Management of 2 interns on tool improvement (adding vulnerabilities, adding detection for Web-Skimming risk)

    [2023-2024]

    Ontologies

    Development (in collaboration) of an MVP on DNS security issue detection using Semantic Web (OWL, RDF, TTL)

    [2022-2024]

    Lead Compliance via ETL

    Continuation of the apprenticeship subject to take the lead and continue adding features and ensure the maintenance/run of the solution.
    Web Pentest AI Agent Code Audit penetration-testing
  • ORANGE
    Apprentice - Cybersecurity Engineer
    DIGITAL AND IT
    September 2020 - September 2022 (2 years)
    Mougins, France

    Pentest - Web Blackbox

    Use of professional tools (BurpSuite Professional, nmap, wfuzz, dalfox)
    Application of a strict Pentest methodology
    Report writing
    Correction support

    Pentest - IoT BLE

    Use of reconnaissance and attack tools (ubertooth, GATTacker)
    Pentest on connected keyboards, mice, and headsets

    AppSec / DevSecOps

    State of the Art & Market analysis of DAST/IAST
    Planning work on integrating a DAST tool
    • Benchmark of DAST solutions (SaaS and OnPrem)
    • Review with CISO and purchase of a solution
    Improvement work on compliance tools (GRC), specifically developing on an in-house ETL solution in Python to:
    • Administer an ELK instance (DataLake) (Automatic management of user rights, tenants, and index patterns)
    • Improve the core of the ETL (performance, scalability)
    • Add essential data for compliance processing (SAST, DWH, DNS, EASM, etc.)

    SI Security Correspondent

    Support and follow-up on SAST and BugBounty submissions
    Support and follow-up on the proper GDPR compliance of applications
    Monitoring of risks reported via AR
    Security supervision (via ELK) against scraping, web attack attempts (XSS, Open Redirect, SSRF, ...) and DDoS

    IT Watch

    State of the Art on attack methods and defense mechanisms of APT/AVT/FIN groups
    Study on EBIOS-RM 2018

Recommendations

Be the first to recommend Maxime

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Certifications

Skill set

Categories