I provide advice and consultancy to clients on the following services:
•Threat modeling and assessment to measure the security effort
• Development of security policies
• Audit of IS and implementation of urbanization plan
• Support for security operations within digitalization projects
• Vulnerability hunting & Penetration testing (web, mobile, API, Smart contract)
• Training, awareness of internal teams in cybersecurity
• Development and optimization of information security processes
• Assessment and protection of digital identity
• Implementation of identity and access management plan (IAM/IAM)
• Consulting in decentralized identity management
• Implementation of information security governance plan in on-promise and cloud environment
• Implementation of a risk management and compliance policy
• Vulnerability assessment and security testing on web applications (2.0/3.0), API, mobile at the system level on environments of testing.
• Perform continuous integration of security tests via SCA, SAST, DAST type tools on the different environments of a chain of delivery software to automatically detect security vulnerabilities along the CI/CD cycle on all phases of the SDLC by soliciting static and dynamic analysis techniques
• Advice on DevSecOps best practices (continuous integration of security testing) and cloud security