> Hello, World.

RAMI HENIA

[Offensive Security Engineer]
$▌

~/whoami

~/about.sh
$ cat about.txt

Offensive Security Engineer with 5+ years of experience in penetration testing, red teaming, and adversary simulation.

Currently securing an enterprise infrastructure as a key member of the internal offensive security team.

Passionate about finding vulnerabilities before the bad guys do. From web applications to Active Directory environments, cloud platforms to mobile apps — if it can be broken, I'll find the way.

Former Lead Pentester at Niji, Cybersecurity Consultant at Wavestone, and Security Developer at SAP R&D.

Trilingual (French, Arabic, English) engineer graduated from IMT Atlantique and EURECOM, with a deep curiosity for all things related to offensive security.
>
⏱5+ Years
🎯100+ Pentests
🌍3 Languages
🐛100+ Bug Reports

~/career.log

Nov 2025 — Present

[+] Offensive Security Engineer

@

Key member of the internal offensive security team, securing enterprise infrastructure and applications.

  • ▸Security SPOC for 100+ internal and external projects
  • ▸Targeted penetration tests on web apps, APIs, and critical infrastructure
  • ▸Configuration reviews & vulnerability assessments across AWS and Azure
  • ▸Guiding development teams in implementing security recommendations
  • ▸Integrating security best practices into the SDLC
Feb 2023 — Nov 2025

[+] Lead Pentester

@ Niji

Key member of the offensive security team, conducting advanced penetration tests and Red Team exercises.

  • ▸50+ penetration tests on web, mobile (iOS & Android), network, and cloud (AWS, Azure, GCP)
  • ▸PASSI-qualified configuration audits for banking and industrial clients
  • ▸Red Team exercises on hybrid AD/Entra ID environments, AWS, Kubernetes
  • ▸Integrated SAST, DAST, and IaC security tools into CI/CD pipelines
Feb 2021 — Feb 2023

[+] Cybersecurity Consultant

@ Wavestone

Offensive security and cybersecurity consultant, working on penetration tests, security audits, and advisory.

  • ▸Web, mobile, and network penetration tests
  • ▸Phishing campaigns for 1,000+ employees
  • ▸Created a Python-based dynamic malware analysis tool
  • ▸Automated pentesting tasks using Python and Bash scripts
  • ▸Forensic analysis on compromised Windows systems
Sep 2020 — Jan 2021

[+] Security Testing Developer

@ SAP

R&D security role focused on enhancing SAP's automated security testing capabilities.

  • ▸Improved SAP's internal DAST solutions
  • ▸Identified SQL Injection, XSS, and auth bypasses in SAP web apps
  • ▸Designed CTF challenges for SAP training programs

~/arsenal.sh

🛡️
Core
Expertise
Web Application Pentesting
Mobile Pentesting (iOS/Android)
Active Directory Attacks
Red Teaming & Adversary Simulation
Network Infrastructure
Cloud Security (Azure, AWS)
AI security

~/articles/

~/connect.sh

Interested in working together or just want to talk security? Let's connect.

contact.sh
$./ping_socials.sh

$