Unlock this candidate profile
Sign up free as a recruiter to view the full CV, contact info and reach out to this candidate.
Skills
Experience
Bug Bounty Hunter — Web & API Security
HackerOne, Bugcrowd, YesWeHack, Intigriti
2024-01 -
Conducted authorized testing on in‑scope bug bounty programs and training environments, focusing on access‑control, authentication, input validation and misconfigurations. Produced structured vulnerability reports with reproducible steps, technical impact analysis and remediation recommendations. Utilized tools such as Burp Suite, OWASP ZAP, Nmap and Nuclei to discover and validate findings. Engaged with platform communities to ensure responsible disclosure and improve security posture of target applications.
Academic Project — Secure CI/CD DevSecOps Pipeline
ENSAO
2025-01 - 2025-12
Implemented a security‑focused CI/CD workflow for a Django application collecting sensor data from ESP8266 devices. Integrated code review, container hardening and automated security scans using Docker, Nuclei and OWASP ZAP. Applied DevSecOps best practices to enforce security gates before deployment, reducing vulnerability exposure in the pipeline.
Final‑Year Project — Intelligent Pentest Automation
ENSAO / Novelis, Oujda
2026-01 - 2026-12
Designed an AI‑assisted pentesting solution that automates reconnaissance, scanning, analysis and reporting across a virtualized enterprise infrastructure. Built an automation pipeline using Linux, Docker and scheduled tasks to orchestrate Nmap, Nuclei, OWASP ZAP and Subfinder. Performed manual penetration tests on internal solutions to benchmark automated results, and evaluated candidate tools on coverage, accuracy and reporting quality.
Education
Engineering Degree in Information Technologies & Communication Networks, ENSA Oujda
Languages
Arabic
native
French
intermediate
English
intermediate
Last updated: 2 months ago