You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Mehdi C.MC

Mehdi C.

DevSecOps Engineer | AppSec Automation

€350/day
Lille, FR
0-2 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Mehdi

Looking to secure your CI/CD pipelines or structure your DevSecOps approach? I help you identify risks, implement the right tools, and deliver concrete results quickly.
As a cybersecurity engineer (JUNIA ISEN Lille), I focus on securing build and deployment pipelines, detecting secrets and vulnerabilities, analyzing open-source dependencies, and writing technical documentation. I applied these practices in real production environments during my work-study program.
What sets me apart: a pragmatic, deliverable-oriented approach, a genuine security culture (top 0.05% globally on TryHackMe), and the ability to adapt to both technical teams and less specialized profiles.
Available for short, targeted missions.
  • English

    Fluent

  • Spanish

    Conversational

  • French

    Native or bilingual

Remote only
Primarily works remotely

Experience

  • ISAGRI
    DevSecOps Engineer
    SOFTWARE PUBLISHING
    September 2023 - Today (2 years and 11 months)
    60000 Beauvais, France
    • Software Supply Chain Security (SSCS): Industrial deployment of SBOM across 10+ product lines, full traceability of open-source components used in production.
    • CI/CD Hardening: Integration of quality gates (JFrog Xray, Gitleaks) into over 50 Azure DevOps pipelines, with the implementation of a two-tier Gitleaks config architecture (shared base + per-project override).
    • Artifactory Governance: Administration of a JFrog Artifactory Hub & Spoke architecture, repository compliance audits, Xray Watches/Policies configuration, and incident response (axios/UNC1069 compromise).
    • AI Filtering of False Positives: Proof of concept and industrialization of an LLM pipeline (Azure AI Foundry, gpt-4.1-mini) to filter Gitleaks alerts, data processed exclusively in France (francecentral).
    • Acculturation & Support: Daily training and support for 8 Business Units on Secure Coding practices and vulnerability remediation.
    • Dependency Management: Securing npm, NuGet, and Docker registries against Dependency Confusion attacks.
    CI/CD Security Azure DevOps Cybersecurity Vulnerability Analysis DevSecOps
  • Junia ISEN
    Cybersecurity Engineer in Training
    TECH
    September 2020 - Today (5 years and 11 months)
    Lille, France
    Cybersecurity and DevSecOps engineering degree at JUNIA ISEN Lille. Specialization covering network security, applied cryptography, pentesting (web, system), secure development, and IT risk management. Practical projects on Docker environments, CI/CD pipelines, and CTF platforms. Ranked top 0.05% globally on TryHackMe. Additional skills in vulnerability analysis, system hardening, and applied DevSecOps in a real-world context through work-study.
    Network Security Cryptography PenTest Secure Development IT Risk Management

Recommendations

Be the first to recommend Mehdi

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Engineering Degree
    JUNIA ISEN
    2026
    Diplôme d'ingénieur
  • CompTIA Pentest+ (Learning Path)
    TryHackMe
    2023

Certifications

Skill set

Categories