From intrusion testing to the code fix.
I'm Timothée Lafay, a pentester who goes beyond the audit.
I don't just find the flaws: I help your teams resolve them and make your security solutions last.

I'm Timothée Lafay, a pentester who goes beyond the audit.
I don't just find the flaws: I help your teams resolve them and make your security solutions last.

My philosophy

Security is good. Actually protecting your company is better. I focus on the real risks you face, to protect you where it matters.

Security doesn't stop at a report. I work with your development teams so they understand the vulnerabilities found and build in best practices from the start.

Security is a marathon, not a sprint. I help you put in place the processes and tools to make it an integral part of your development cycle.
Proof through practice: my dual pentest-and-development skillset in action.

Securing the company's web and mobile applications — regular penetration testing, industrialising security in the CI/CD pipeline, and fixing flaws directly in the backend code.

Penetration testing on the company's web applications — identifying vulnerabilities (SQL injection, RCE, XSS…), writing remediation tickets for developers and following up on fixes.

Internal infrastructure pentest — network mapping (Nmap), enumeration and vulnerability hunting on an Active Directory environment, reported in an audit deliverable.
From hunting flaws to building applications.

A 3-person CTF — fully compromising a vulnerable VM up to root through at least two distinct paths, with no starting hint at all.

My ongoing offensive practice — bug bounty (including a flaw rewarded by the Google VRP), CTF platforms and training on Hack The Box and TryHackMe.

A personal-motivation web app (Django + Vue) running in production on Google Cloud — a full-stack project designed and deployed end to end.
Looking for a pentester who speaks dev? I'm open to opportunities and would love to talk.