> Hello, World.
RAMI HENIA
[Offensive Security Engineer]
$▌
~/whoami
~/about.sh
$ cat about.txt
Offensive Security Engineer with 5+ years of experience in penetration testing, red teaming, and adversary simulation.
Currently securing an enterprise infrastructure as a key member of the internal offensive security team.
Passionate about finding vulnerabilities before the bad guys do. From web applications to Active Directory environments, cloud platforms to mobile apps — if it can be broken, I'll find the way.
Former Lead Pentester at Niji, Cybersecurity Consultant at Wavestone, and Security Developer at SAP R&D.
Trilingual (French, Arabic, English) engineer graduated from IMT Atlantique and EURECOM, with a deep curiosity for all things related to offensive security.
>
⏱5+ Years
🎯100+ Pentests
🌍3 Languages
🐛100+ Bug Reports
~/career.log
Nov 2025 — Present
[+] Offensive Security Engineer
@
Key member of the internal offensive security team, securing enterprise infrastructure and applications.
- ▸Security SPOC for 100+ internal and external projects
- ▸Targeted penetration tests on web apps, APIs, and critical infrastructure
- ▸Configuration reviews & vulnerability assessments across AWS and Azure
- ▸Guiding development teams in implementing security recommendations
- ▸Integrating security best practices into the SDLC
Feb 2023 — Nov 2025
[+] Lead Pentester
@ Niji
Key member of the offensive security team, conducting advanced penetration tests and Red Team exercises.
- ▸50+ penetration tests on web, mobile (iOS & Android), network, and cloud (AWS, Azure, GCP)
- ▸PASSI-qualified configuration audits for banking and industrial clients
- ▸Red Team exercises on hybrid AD/Entra ID environments, AWS, Kubernetes
- ▸Integrated SAST, DAST, and IaC security tools into CI/CD pipelines
Feb 2021 — Feb 2023
[+] Cybersecurity Consultant
@ Wavestone
Offensive security and cybersecurity consultant, working on penetration tests, security audits, and advisory.
- ▸Web, mobile, and network penetration tests
- ▸Phishing campaigns for 1,000+ employees
- ▸Created a Python-based dynamic malware analysis tool
- ▸Automated pentesting tasks using Python and Bash scripts
- ▸Forensic analysis on compromised Windows systems
Sep 2020 — Jan 2021
[+] Security Testing Developer
@ SAP
R&D security role focused on enhancing SAP's automated security testing capabilities.
- ▸Improved SAP's internal DAST solutions
- ▸Identified SQL Injection, XSS, and auth bypasses in SAP web apps
- ▸Designed CTF challenges for SAP training programs
~/arsenal.sh
🛡️
Core
Expertise
Expertise
Web Application Pentesting
Mobile Pentesting (iOS/Android)
Active Directory Attacks
Red Teaming & Adversary Simulation
Network Infrastructure
Cloud Security (Azure, AWS)
AI security
~/articles/
~/connect.sh
contact.sh