About Maxime
MY AREAS OF EXPERTISE
- Researching advanced vulnerabilities (OWASP Top 10 and business logic).
- Source code auditing (Whitebox).
- Securing APIs and complex application architectures.
- Security auditing of solutions integrating LLMs (Large Language Models).
- Identifying specific risks (Prompt Injection, data poisoning).
- Advising on secure architecture for AI projects
WHY WORK WITH ME?
French
Native or bilingual
English
Fluent
Experience
- ORANGELead Cybersecurity / AI EngineerDIGITAL AND ITOctober 2022 - Today (3 years and 10 months)Mougins, France[2022-Today]
Pentests - Blackbox & Whitebox
Multiple Pentests on Web and Desktop applications with and without source code accessAdvanced vulnerability testing (CORS Regex Bypass, CSP Bypass, Cookie Bombing, Blind XXE, SSTI, Cache Poisoning, etc.)Expert vulnerability testing (HRS/H2C, HPP, SSPP, CpDoS, Secondary Context Attacks, Dangling Markup Injection, HTTP Hop-by-Hop Header Injection, etc.)[2025-Today]Product Owner / Lead - AI-Native SAST
Development of an internal AI-Native SAST solution- Use of agent frameworks (LangChain/LangGraph)
- Use of Context Engineering methods (AST Slicing, Inter-component graphs, Business constraints)
- Use of LLM Engineering methods (Chain of Thoughts, Prompt Paraphrasing, HITL, Less is More, etc.)
Management of a full-time developerCommunication and adoption of the tool among internal auditors[2022-Today]Product Owner / Lead - EASM
Development of a in-house EASM solution- Blue-Green deployment on GCP following best practices (TP, CAB)
- Building the solution for security issue detection (nuclei, xsstrike, sqlmap, wfuzz)
- Automation of ticket creation and closure
Management of 2 interns on tool improvement (adding vulnerabilities, adding detection for Web-Skimming risk)[2023-2024]Ontologies
Development (in collaboration) of an MVP on DNS security issue detection using Semantic Web (OWL, RDF, TTL)[2022-2024]Lead Compliance via ETL
Continuation of the apprenticeship subject to take the lead and continue adding features and ensure the maintenance/run of the solution. - ORANGEApprentice - Cybersecurity EngineerDIGITAL AND ITSeptember 2020 - September 2022 (2 years)Mougins, France
Pentest - Web Blackbox
Use of professional tools (BurpSuite Professional, nmap, wfuzz, dalfox)Application of a strict Pentest methodologyReport writingCorrection supportPentest - IoT BLE
Use of reconnaissance and attack tools (ubertooth, GATTacker)Pentest on connected keyboards, mice, and headsetsAppSec / DevSecOps
State of the Art & Market analysis of DAST/IASTPlanning work on integrating a DAST tool- Benchmark of DAST solutions (SaaS and OnPrem)
- Review with CISO and purchase of a solution
Improvement work on compliance tools (GRC), specifically developing on an in-house ETL solution in Python to:- Administer an ELK instance (DataLake) (Automatic management of user rights, tenants, and index patterns)
- Improve the core of the ETL (performance, scalability)
- Add essential data for compliance processing (SAST, DWH, DNS, EASM, etc.)
SI Security Correspondent
Support and follow-up on SAST and BugBounty submissionsSupport and follow-up on the proper GDPR compliance of applicationsMonitoring of risks reported via ARSecurity supervision (via ELK) against scraping, web attack attempts (XSS, Open Redirect, SSRF, ...) and DDoSIT Watch
State of the Art on attack methods and defense mechanisms of APT/AVT/FIN groupsStudy on EBIOS-RM 2018
Recommendations
Be the first to recommend Maxime
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Certifications
- OSWEOffensive Security2025