About me

Who am I?
I'm Timothée Lafay, a work-study pentester, passionate about offensive security, web development and automation.
What defines me is a dual skillset: I come from development, and I do pentest. So I don't just find flaws and write a report — I understand the code they live in, I know how to talk to development teams, and I can fix the vulnerabilities myself when it makes sense. That ability to bridge attack and defence is what makes my profile valuable.
Skills
Offensive security
- Web penetration testing (OWASP Top 10: SQL injection, XSS, CSRF, RCE, path traversal…)
- Internal infrastructure and Active Directory pentesting
- Binary exploitation, reverse engineering, privilege escalation
- Bug bounty (a flaw rewarded by the Google VRP)
DevSecOps
- Integrating security into CI/CD (Jenkins)
- Automated vulnerability scanning and penetration testing
- Container and Kubernetes security
Development
- Python (Django), Vue / TypeScript, Java (Spring Boot)
- Designing, building and deploying full-stack applications
Tools
nmap · gdb · Burp Suite · Linux · Git · Docker · Kubernetes
Soft skills
Rigorous and methodical — two essential qualities when you're looking for what others missed. Patient and persistent in the face of hard problems, naturally curious, and autonomous in the way I work.
Education
I study at School 42 (Lyon), a free, selective, project-based computer science school built on peer learning. There I built solid foundations in C, Unix systems, networking and teamwork on software projects.
Let's work together
I'm open to opportunities in pentest and offensive security. Get in touch or find me on LinkedIn.