Ali Yazdani

is working from home. 🏡

Angestellt, Senior DevSecOps Engineer, scoutbee GmbH

Berlin, Deutschland

Über mich

I am a Security Engineer with over a decade of experience working in various industries such as Telco, FinTech, Retail, and SasS. My expertise includes implementing security-focused software development practices, conducting threat modeling exercises, performing penetration testing, and managing vulnerability programs to enhance the security posture of applications and infrastructure. I assist companies in adopting DevSecOps to shape their development culture and enable automation to produce more secure final products with less effort and cost. My work style allows me to collaborate with various teams and translate security concerns into different languages that make sense to both technical and non-technical departments. As an active contributor to the global security community, I currently lead the OWASP DevSecOps Guideline project to help companies gain a better technical perspective and form their future security strategies.

Fähigkeiten und Kenntnisse

Web application pentest
Mobile application Pentest
information security
Windows
PHP
ISO 27001
Python
Penetration Testing
Linux
IT Security
Continuous Testing
Vulnerability Assessment
Vulnerability Analysis
DevOps
Agile Development
SIEM
Threat analysis
Data Protection
Security Policies and Procedures
Software Development
Microsoft Azure
Cloud security
IT Security & Infrastructure
terraform
Kubernetes
istio
InsightVM
Nessus
Acunitix
nmap
Informationstechnologie
Azure
Terraform
K8s
Microservices
DevSecOps
Application Security
Product Security

Werdegang

Berufserfahrung von Ali Yazdani

  • Bis heute 1 Jahr und 10 Monate, seit Aug. 2022

    Senior DevSecOps Engineer

    scoutbee GmbH

  • Bis heute 7 Jahre und 6 Monate, seit Dez. 2016

    Project Lead

    OWASP

    The OWASP DevSecOps Guideline explains how we can implement a secure pipeline and use best practices and introduce tools that we can use in this matter—also, the project is trying to help us for promoting the shift-left security culture in our development process.

  • 6 Monate, Feb. 2022 - Juli 2022

    Senior Security Engineer

    NewStore, Inc.
  • 5 Monate, Sep. 2021 - Jan. 2022

    Lead Engineering DevSecOps

    Henkel AG & Co. KGaA

    Perform vulnerability assessments and penetration tests. Perform security testing and code review as part of the SDLC pipeline to improve software security. (promoting the shift-left strategy and DevSecOps culture).

  • 2 Jahre und 3 Monate, Juni 2019 - Aug. 2021

    Cyber Security Engineer

    Deposit Solutions GmbH

    Perform periodic and on-demand vulnerability assessments and penetration tests. Design and evaluation of cloud/hybrid infrastructure development leveraging Azure IaaS and PaaS. Implement an SIEM solution to monitor security-related activities. Threat modeling and analyze software designs, implementations, and the infrastructure to identify security issues and design countermeasures. Perform security testing and code review as part of the SDLC pipeline to improve software security.

  • 11 Monate, Juni 2018 - Apr. 2019

    IT Security Team Leader

    MTN

    Implement regular Vulnerability and Penetration Tests on IT Infrastructures. To identify potential areas where existing OS/DB security policies and procedures. Implement and integrate IT services with SIEM. Develop security tools to automate IT security process. Collaborate with ISO auditors to implement ISO27001.

  • 2 Jahre und 10 Monate, März 2016 - Dez. 2018

    Penetration Tester (Part-time)

    Atieh Dadeh Pardaz

    ADP Digital is a solution provider for Major banks and major enterprises in Iran by providing Internet Mobile Banking, Short- text-message, and internet notification service, and Datacenter collocation services. My role was the responsibility to perform penetration test on their Web application and Mobile application to ensure the security of the app.

  • 2 Jahre und 7 Monate, Nov. 2015 - Mai 2018

    ITS Security Engineer

    MTN

    Perform penetration test and vulnerability assessment on ITS systems. Check SRS documents and apply security policies and requirements in it. Technical forensic investigation on important security incidents and performing root cause analysis. Implement and develop health check toolkit to automate OS and DB security tools.

  • 3 Jahre und 5 Monate, Nov. 2014 - März 2018

    Security Instructor (Part-time)

    City IT Academy

    City Academy is a modern IT training center in Isfahan that focuses on IT courses. I had a chance to work with this center to share my knowledge with Enthusiasts. courses which I instructed: Penetration Test (Web, Mobile application and Network) Forensics Investigation (Windows, Linux, Mobile)

  • 3 Jahre und 10 Monate, Juni 2014 - März 2018

    Security Instructor (Part-time)

    Metacomplex

    Metaco is one of the biggest IT training centres in Isfahan, having a variety department. I had a chance to start my teaching career in an IT department with a course focused on penetration test. courses which I instructed: -Penetration Test (web, mobile application, and Network) -Forensics Investigation (Windows, Linux, Mobile) -Programming (python)

  • 2 Jahre und 7 Monate, Apr. 2013 - Okt. 2015

    Security Specialist and Penetration tester

    Ertebat Gostar

    - Perform penetration test and provide related report based on customer request. - Perform vulnerability assessment program on customer network and follow up to fix founding. - Consultancy to our customers to improve systems and network hardening. - Develop and implement security dashboard for our customers. - Establish detection and prevention solution to improve customer security.

  • 5 Jahre und 1 Monat, März 2008 - März 2013

    Security Engineer

    IDSco

    Implement penetration test and provide related report based on customer request. Drive vulnerability assessment program on the customer network. Develop and implement security dashboard for our customers. Establish detection and prevention solution to improve customer security.

Ausbildung von Ali Yazdani

  • 3 Jahre und 11 Monate, Feb. 2010 - Dez. 2013

    Computer software engineering

    Jahaad Software Academic Institute – Esfahan

  • 3 Jahre und 6 Monate, Juli 2006 - Dez. 2009

    Computer Software Engineering

    Jahaad Software Academic Institute – Esfahan

Sprachen

  • Englisch

    Fließend

  • Deutsch

    Grundlagen

  • Persian

    -

Interessen

Squash
Music
Photography
Movies
Hacking

21 Mio. XING Mitglieder, von A bis Z