You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Malt welcome

Willkommen auf dem Freelancer-Profil von Ali !

Malt bringt Sie mit den besten Freelancern für Ihre Projekte zusammen. Sie können Ali kostenlos kontaktieren und sich im Chat austauschen, oder andere Freelancer anschreiben und unverbindliche Angebote einholen.

Ali Yazdani AppSec | Cloud Security | Pentest | DevSecOpsAY

Ali Yazdani

AppSec | Cloud Security | Pentest | DevSecOps
  • Unverbindlicher Tarif
    800 € /Tag
  • Berufserfahrung8-15 Jahre
  • Antwortrate100 %
  • Antwortzeit1h
Das Projekt startet erst, wenn Sie das Angebot von Ali annehmen
Standort und Mobilität
Standort
Berlin, Deutschland
Nur remote
Führt Projekte hauptsächlich remote aus
Checkliste

Malt Freelancer Charta unterzeichnet

Die Charta lesen
Geprüfte E-Mail-Adresse
Reputation
63Follower
15Repositories
0Gists
Sprachen
Kategorien
Diese Profile passen auch zu Ihrer Suchanfrage

Agatha Frydrych

Backend Java Software Engineer

Baptiste Duhen

Fullstack developer

Amed Hamou

Senior Lead Developer

Audrey Champion

Web developer

Fähigkeiten
Branchenkenntnisse
Ali in wenigen Worten
Hello, I’m Ali, a Security Engineer with over 10 years of experience in the security industry. I am a Security Engineer with an Application Security background. Beginning as a Penetration Tester, I gained insights into the offensive side of application security.
I progressed to help organizations implement security solutions and cultivate a strong DevSecOps culture. Today, my passion lies in assisting businesses to ensure their product’s security posture is robust and effective.

As an OWASP Foundation Researcher, I contribute to the OWASP MSTG (Mobile Security Testing Guide) project as a project contributor and lead the OWASP DevSecOps guideline project. I am passionate about sharing my knowledge and experience with the security community to promote best practices and enhance security awareness.

For more info please check my blog:
Projekt- und Berufserfahrung
  • Scoutbee GmbH
    Principal DevSecOps Engineer
    DIGITALAGENTUREN & IT-CONSULTING
    Oktober 2023 - Heute (1 Jahr und 9 Monate)
    Berlin, Deutschland
    • Defining Scoutbee’s security strategies to make sure our product and services are secure and in compliance with the standards and regulations we are following.
    • Collaboration with development teams to implement best practices based on Secure Coding principles and define secure CI/CD guardrails to keep the development pipelines in the rail.
    • Collaborated with the infra/SRE team to identify security vulnerabilities and misconfigurations. Established IaC scanning, CNAPP, and Policy as Code for deployment on cloud providers to improve understanding and visibility.
    • Performing threat modeling and secure coding workshops to identify the threats and plan to fix them in the design and developing phase (Shift-left mindset) and promote a clutter of DevSecOps.
    SAST DAST Kubernetes AWS DevSecOps
  • Scoutbee GmbH
    Senior DevSecOps Engineer
    DIGITALAGENTUREN & IT-CONSULTING
    August 2022 - September 2023 (1 Jahr und 2 Monate)
    Berlin, Deutschland
    Implementing SAST, SCA, IaC, PaC, and DAST as part of the CI/CD pipelines.
    Threat modeling and analyzing software designs, implementations, and infrastructure to identify security issues and
    design countermeasures.
    Managing penetration test programs on applications and services.
    Define a vulnerability disclosure program (VDP) to identify vulnerabilities in internet-facing services.
    Promoting the shift-left strategy and DevSecOps culture by starting the threat modeling section.
    DevSecOps Kubernetes AWS DAST SAST Terraform
  • HENKEL
    Lead Engineering DevSecOps
    CHEMIE
    September 2021 - Februar 2022 (5 Monate)
    Berlin, Germany
    Perform vulnerability assessments and penetration tests. Perform security testing and code review as part of the SDLC pipeline to improve software security. (promoting the shift-left strategy and DevSecOps culture).
Externe Empfehlungen
Ausbildung und Abschlüsse
  • Associate s Degree in Computer Software Engineering
    Jahaad Software Academic Institute – Esfahan
    2013
    Bachelor's degree, Computer Software Engineering
  • Associate s Degree in Computer Software Engineering
    Jahaad Software Academic Institute – Esfahan
    2009
    Associate's degree, Computer Software Engineering
Zertifizierungen