Skip to content

About me ​

Timothée Lafay

Who am I? ​

I'm Timothée Lafay, a work-study pentester, passionate about offensive security, web development and automation.

What defines me is a dual skillset: I come from development, and I do pentest. So I don't just find flaws and write a report — I understand the code they live in, I know how to talk to development teams, and I can fix the vulnerabilities myself when it makes sense. That ability to bridge attack and defence is what makes my profile valuable.

Skills ​

Offensive security ​

  • Web penetration testing (OWASP Top 10: SQL injection, XSS, CSRF, RCE, path traversal…)
  • Internal infrastructure and Active Directory pentesting
  • Binary exploitation, reverse engineering, privilege escalation
  • Bug bounty (a flaw rewarded by the Google VRP)

DevSecOps ​

  • Integrating security into CI/CD (Jenkins)
  • Automated vulnerability scanning and penetration testing
  • Container and Kubernetes security

Development ​

  • Python (Django), Vue / TypeScript, Java (Spring Boot)
  • Designing, building and deploying full-stack applications

Tools ​

nmap · gdb · Burp Suite · Linux · Git · Docker · Kubernetes

Soft skills ​

Rigorous and methodical — two essential qualities when you're looking for what others missed. Patient and persistent in the face of hard problems, naturally curious, and autonomous in the way I work.

Education ​

I study at School 42 (Lyon), a free, selective, project-based computer science school built on peer learning. There I built solid foundations in C, Unix systems, networking and teamwork on software projects.

Let's work together ​

I'm open to opportunities in pentest and offensive security. Get in touch or find me on LinkedIn.

Last updated: