
Youssef A
Cybersecurity Engineer
Competenze

Consulta i miei servizi

Esperienza lavorativa
Cybersecurity Engineer Intern
Unlisted • Part time
May 2026 - Aug 2026 • 3 mos
• Ran a 62 task CIS Controls v8 (IG1) security program as the company’s first security hire, closing all 48 in scope tasks across mobile, web, and backend before public launch and reviewing each teammate’s remediation evidence before sign off. • Directed the access control and audit logging workstreams, covering GCP Cloud Audit Logs, Security Command Center alerting to Slack, and MFA enforcement on GCP and Firebase, and audited IAM across Cloud Run, Cloud Functions, and Secret Manager for least privilege. • Tracked vulnerability findings to closure across company repositories: scanned full commit history with TruffleHog and rotated exposed credentials, decompiled the Android build with jadx for hardcoded secrets, pushed Dependabot and Snyk alerts through remediation, and piloted the Garak LLM scanner against AI facing endpoints. • Found a broken authorization flaw exposing roughly 324 user records of PII by reading backend authorization logic and database access controls, documented the root cause for engineering leadership, and verified the fix before it reached production. • Closed a privilege escalation path across 40 Postgres SECURITY DEFINER functions missing search_path hardening, rewrote Supabase Row Level Security policies to remove publicly readable tables, and wrote Python and Bash automation in GitHub so configuration checks ran the same way every time.