About Mehdi
Cybersecurity Expert | IT Architecture
French
Native or bilingual
English
Fluent
Experience
- M42 CONSULTINGCybersecurity Expert & IT ArchitectureCONSULTING AND AUDITSNovember 2019 - Today (6 years and 9 months)Lyon, France→ Objective:Protect critical information systems by auditing their security and designing resilient architectures capable of withstanding current threats.→ Challenges:- Exposed applications with undetected flaws- Architectures designed without security considerations- IT Directors facing strategic technical choices without visibility into real risks- Need for immediate security without interrupting business operations→ Expertise MobilizedCode Audit · Penetration Testing · WAF · Reverse Proxy · Strong Authentication · Zero Trust Architecture ·IT System Urbanization· Open Source · Linux→ My Missions- **Comprehensive Application Security Audit**: source code, infrastructure, architecture- Penetration testing and vulnerability assessment- Design and deployment of protection architectures (WAF, filtering proxy, security dome, segmentation)-Post-incident forensic analysis and remediation plan- Design of resilient and secure-by-design IT architectures- Urbanization and rationalization of information systems- Development of security strategies and budgeted roadmaps- Support forIT Directorsin their architecture and security decisions→ Results: dozens of audited and secured systems, **50% to 95% savings on remediation**, **zero incidents post-intervention**, architectures designed to last.
- M42 CONSULTINGCybersecurity TrainerCONSULTING AND AUDITSNovember 2019 - Today (6 years and 9 months)Lyon, France→ Objective: Transform teams into the first line of defense against cyber threats, from the executive committee to developers.→ Challenges:- Unaware employees representing the primary attack surface- Traditional training that is too theoretical and quickly forgotten- Need for sustainable and measurable behavioral changes→ ApproachQuick Awareness Sessions · Attack Simulations · Practical Workshops · Secure Coding Training ·OWASP→ My Missions- Design and delivery of cybersecurity training for all levels- Quick awareness sessions tailored to the daily work of teams-Real attack simulations to instill good reflexes- Training in secure development (**OWASP**, best practices)-Impact measurement and post-training support→ Results: **dozens of teams trained**, unanimously positive feedback, measurable reduction in risky behaviors.
- HB EMTECSenior Developer / Code Security ReferentSOFTWARE PUBLISHINGJune 2008 - November 2019 (11 years and 5 months)Lyon, France→ Objective:Reduce the attack surface from the source codeand build a culture of application security within development teams.→ Challenges:- Functional codebases that are exploitable- Vulnerabilities reaching production undetected- No security culture among developers→ Technical StackPHP · Java · Python · JavaScript · SQL · REST API · Linux→ My Missions- Risk-oriented code audits and reviews (hundreds of codebases: web, **API**, scripts)- Identification and correction of critical flaws in developments compliant with standards-Definition of secure coding standards for the company- Implementation of sustainable application security practices- Skill development for development teams in security→ Results: **hundreds of codebases audited and secured over 11 years**, **significant reduction in production vulnerabilities**, lasting security culture established.
Recommendations
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Software Engineering and DevelopmentINSA de Lyon2011Ingénieur d'études et développement informatique