
Mohamed Kamel Bouzekria
Verified Expert in Engineering
Kali Linux Developer
Paris, France
Toptal member since August 21, 2026
Across technology, finance, and automotive, Mohamed has spent over 10 years building offensive and application security programs. His toolkit centers on AWS, Azure, and Kubernetes. While at SII Group, Mohamed led penetration-test engagements for enterprise clients and produced executive-ready reports that translated technical risk into business impact.
Portfolio
Experience
- Application Security - 10 years
- Kali Linux - 10 years
- Burp Suite - 10 years
- Offensive Security - 10 years
- Penetration Testing - 8 years
- SCA - 7 years
- Static Application Security Testing (SAST) - 7 years
- Dynamic Application Security Testing (DAST) - 7 years
Preferred Environment
Azure, Docker, GitHub Actions, Kali Linux, Metasploit, Burp Suite, Application Security, ASVS, Phishing Simulation & Analysis
The most amazing...
...security program I've built embedded secure SDLC controls and automated vulnerability management across a full product attack surface.
Work Experience
Senior Security Consultant
Self-employed
- Led offensive-security and application-security engagements for international clients end to end.
- Ran fixed-scope penetration tests covering authentication bypass, IDOR, broken access control, injection, file-upload abuse, and business-logic flaws, mapped to OWASP Top 10 and API Top 10.
- Advised engineering leaders on secure-by-design decisions and remediation strategy. Ran post-remediation retests and verified fixes rather than only reporting risk.
- Extended coverage to AI/LLM application features (prompt injection, guardrail bypass, and system-prompt disclosure) as products increasingly shipped LLM-backed functionality.
Senior Penetration Tester
Swile
- Owned the offensive-testing function for a fast-moving product organization: penetration tests on web and mobile applications and their APIs, coordinated across engineering teams in France and Brazil.
- Triaged and validated vulnerability reports from researchers and automated sources (AWS Inspector, GuardDuty, Microsoft Defender, Security Hub). Drove remediation ownership and cut noise by qualifying findings against real exploitability.
- Hardened authentication and access-control paths and reviewed application, Kubernetes, and network architectures across AWS and Azure.
- Embedded Semgrep, Aikido, and Dependabot into GitHub CI/CD for continuous secure code review.
- Authored SOC playbooks improving detection and incident response.
Lead Penetration Tester
Groupe SII
- Led penetration-test engagements for enterprise clients across web, API, network, and cloud (AWS, Azure). Acted as the senior technical point of contact from kickoff to findings walkthrough.
- Produced high-quality reports and executive summaries, translating technical risk into business impact for management and steering committees, and defending findings against client challenge.
- Performed black-box, grey-box, and white-box testing on applications and infrastructure, including containerized environments (Docker, Kubernetes). Guided engineering teams on secure remediation.
- Mentored junior consultants on methodology, reporting quality, and client communication, raising the delivery standard across the team.
Lead Penetration Tester
Realistic Security
- Designed and delivered recurring, holistic security testing for a critical group of production services (design review, threat modeling, penetration testing, and red teaming) partnering with service teams through to risk closure.
- Scoped and executed penetration testing and vulnerability research on complex proprietary software. Ran application, infrastructure, physical, and social-engineering assessments for clients.
- Prepared and presented detailed technical findings to both engineering and executive audiences. Documented exploitation chains, proof-of-concept code, and remediation plans.
- Established repeatable testing methodology and reporting templates that improved consistency and turnaround across engagements.
Cloud Security Engineer
RedFabriQ
- Delivered hands-on secure architecture reviews, code reviews, business-logic testing, and cloud security assessments (AWS).
- Defined security requirements and architecture for a connected-vehicle cloud platform (AWS). Built automated testing methodologies from cloud to embedded device.
- Led security code reviews and design reviews with engineering teams and produced risk assessments for technical and executive audiences.
Head of Product Security
G22 REI
- Owned end-to-end product security strategy, embedding secure-by-design principles and SDLC controls from ideation to deployment across the full product attack surface.
- Partnered with engineering, product, and design to automate security tooling (SAST, DAST, SCA) in CI/CD and stand up vulnerability-management workflows with KPI reporting.
- Directed the vulnerability disclosure program as technical authority for triage and remediation prioritization. Ensured compliance with GDPR and DORA.
- Explore Azure resources used to add redundancy, fail-over, and load balancing, using the Azure Content Delivery Network.
Cyber Security Engineer
Brandt
- Identified software security design and architectural risks and developed mitigation plans. Implemented technical controls to improve the organization’s security posture.
- Perform security assessments on native, managed, and interpreted software using static and dynamic analysis techniques, white-box, and black-box testing methods.
- Mentor software engineers on how to abate security vulnerabilities and threats in applications.
Software Engineer
Sirius NET
- Performed SAST/DAST assessments on native, managed, and interpreted software.
- Mentored engineers on remediating vulnerabilities.
- Designed and validated the technical architecture of critical applications and systems.
Malware Researcher Intern
USTHB
- Buil tand integrated software solutions following established development standards. Unit-tested components against business requirements.
- Analyzed suspicious files with static and dynamic techniques.
- Contributed to malware-classification automation and tooling.
Experience
Automated Framework for Malware Detection and Classification Using Machine Learning Algorithms
Education
Master's Degree in Cybersecurity
University of Science and Technology Houari Boumediene - Algiers, Algeria
Bachelor's Degree in Software Engineering
University of Science and Technology Houari Boumediene - Algiers, Algeria
Certifications
OSWP, Offensive Security Wireless Professional
Offensive Security
OSEP, Offensive Security Experienced Penetration Tester
Offensive Security
OSCP, Offensive Security Certified Professional
Offensive Security
CRTE, Certified Red Team Expert
Pentester Academy
CRTP, Certified Red Team Professional
Pentester Academy
PSM I, Professional Scrum Master
Scrum.org
OSWE, Offensive Security Web Expert
Offensive Security
Skills
Libraries/APIs
Java Security
Tools
NMap, Jenkins, Postman, Sqlmap, AWS CloudFormation, Ghost Inspector, WPScan, Hashcat, Checkmarx, SonarQube, AWS IAM, Metasploit, Interactive Disassembler (IDA) Pro, Weka, GCP Security, SAP Security, VPN
Languages
Python, JavaScript, Java, C#, PHP, Bash
Frameworks
Redux, Windows PowerShell, .NET
Paradigms
Penetration Testing, DevSecOps, Security Orchestration, Automation, and Response (SOAR), Automation, Scrum, Agile
Platforms
Kali Linux, Burp Suite, Kubernetes, Azure, Microsoft, Docker, Amazon Web Services (AWS), Google Cloud Platform (GCP), SAP HANA, Vanta
Industry Expertise
Cybersecurity
Storage
Azure Active Directory, SQL Injection Protection, Database Security
Other
OWASP Top 10, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), SCA, Offensive Security, Application Security, ASVS, Threat Modeling, MITRE ATT&CK, NIST, Vulnerability Management, IT Security, Security, AI Security, SIEM, Ethical Hacking, Certified Ethical Hacker (CEH), OSCP, Security Assessment, Compliance, GRC, IT Audits, IT Contracts, IT Operations Management (ITOM), External Audits, Security Architecture, Documentation, Consulting, Prompt Engineering, Network Security, Semgrep, GitHub Actions, Social Engineering, Secure Software Development Lifecycle (SSDLC), CVSS, BloodHound, PowerShell, Security Engineering, SOC 2, AI Agents, Endpoint Protection, IDS/IPS, Security Monitoring, System Administration, PCI DSS, SecOps, Artificial Intelligence (AI), Large Language Models (LLMs), Identity & Access Management (IAM), SaaS, Microsoft Azure, Microsoft 365, Phishing Simulation & Analysis, Cloud, Amazon GuardDuty, Security Hub, Dependabot, CI/CD Pipelines, GDPR, DevOps Research and Assessment (DORA), nikto, Snyk, Active Directory (AD), Malware Analysis, Vulnerability Scanning, Vulnerability Assessment, Vulnerability Identification, Burp Proxy, Red Teaming, Vulnerability Remediation, IT Project Management, Source Code Review, Zero-day Vulnerabilities, IoT Security, Web Security, OT Security, Data Security, SaaS Security, Web App Security, Security Audits, AWS Cloud Security, Mobile App Security, CCNP Security, Server Security, Azure Cloud Security, Security Analysis, Blockchain Security, Computer Security, Cloud Security, Security Compliance, Security Design, Product Security, Payment Security, Security Principles, Endpoint Security, Email Security, Operational Security (OPSEC), Security Operations Centers (SOC), Security Information and Event Management (SIEM), Firewalls, Proxies, ISO 27701, Security Automation, SAP Business Technology Platform (BTP), SAP, Startups, Wiz Cloud Security Platform, CSPM
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring