IT Security engineer
Paris Area, France
IT Security engineer
Paris Area, France
IT Security expert
More information on http://securitech.homeunix.org
- IT security expert at Apple since Nov. 06
- Founder (and head for 2 years) of the largest French IT Security challenge Challenge-SecuriTech
- Public presentations held at SSTIC, EuroSec, OSSIR, SecuriTech, ESIEA and numerous articles written for the french IT security magazine MISC
- Strong skills in software security (reverse-engineering, advanced debugging, kernel mechanisms, etc,), security assessments (black/grey/white boxes) ...
- Network and software vulnerability research (DNS, Bluetooth, WIfi, software vulnerabilities...)
Main public security researches:
- Bluetooth Stack Smasher (BSS), fuzzer and articles available on http://securitech.homeunix.org/blue
- DNSA (DNS Auditing tool) project, available on http://www.packetfactory.net/projects/dnsa/
- Reverse-engineering on x86/PPC/ARM on MacOS/Win/Linux. Strong knowledge of IDA, OllyDBG, PyDBG framework...
Fields of expertise: vulnerability research, network, penetration testing, reverse engineering, software security, apple products
(Public Company; 10,001 or more employees; AAPL; Computer Hardware industry)
November 2006 — Present (2 years 1 month)
Offensive IT-security (penetration testing, software oriented attacks, reverse engineering...).
Designing new security schemes for protections on various Apple products.
Security validation for implemented enforcements.
Working in a team split between Paris and San Francisco.
(Privately Held; 10,001 or more employees; Telecommunications industry)
January 2006 — November 2006 (11 months)
Aircraft information system security on the A380 European project : penetration testing, risk analysis, security research. Worked as a trainee.
(Privately Held; 1-10 employees; Computer & Network Security industry)
April 2005 — November 2006 (1 year 8 months)
Tutorials, white papers, and articles redaction, Bluetooth security fuzzing ( http://www.secuobs.com/news/05022006-bluetooth1.shtml ) ...
(Privately Held; 11-50 employees; Information Technology and Services industry)
September 2003 — January 2006 (2 years 5 months)
Performed several "confirmed level" trainings (IT Security, MySQL, VoIP) in freelance.
(Privately Held; 10,001 or more employees; EAD; Defense & Space industry)
December 2004 — July 2005 (8 months)
Researcher in Computer Security for the french EADS Common Research Center (EADS / CCR).
(Privately Held; 10,001 or more employees; EAD; Defense & Space industry)
December 2003 — August 2004 (9 months)
Designed and developed an IT-security assessment platform.
VoIP mobile solutions security and penetration testing (VoWLAN).
(Privately Held; 11-50 employees; Computer & Network Security industry)
2002 — 2004 (2 years)
Creator and head of the Challenge-SecuriTech, french national IT-security Challenge. The project brought together 7 people for 2 years (more than 2200 participants per year).
When quitting this project after 2 years, I led the transition for several months to help the new head of the project to handle his new position.
Challenge-Securitech has been the most widely known french security challenge and has ended in 2006.
See http://www.google.com/search?q=challenge-securitech for more information.
2001 — 2006
Tennis (competition), ex-rugby player, guitar/music, karting