Souhail Mssassi

AI Researcher

Marrakesh-Safi, Morocco7 yrs 3 mos experience

Key Highlights

  • Over a decade of experience in cybersecurity.
  • Specializes in application security and cryptography.
  • Delivered lectures at universities and conferences.
Stackforce AI infers this person is a Cybersecurity Expert with a focus on Blockchain and Decentralized Applications.

Contact

Skills

Core Skills

Blockchain SecurityAuditingSmart ContractsPenetration TestingDevsecopsMobile SecurityVulnerability AnalysisSecurity TestingInformation Gathering

Other Skills

Action Plan ImplementationAssembly Code AnalysisBlockchainBlockchain ArchitectureCC++Code ReviewCompliance SupportCryptographyCybersecurityData AnalysisDeFiDecentralized FinanceEVMEthereum

About

With over a decade of experience in cybersecurity, I specialize as a Senior Security Researcher in application security, cryptography, and the security of decentralized applications. Throughout my career, I have assisted numerous organizations in enhancing their cybersecurity strategies. As an instructor and speaker, I have delivered security lectures at universities and conferences, sharing my expertise with the academic and professional communities. My current research focuses on formal verification within the cybersecurity field, aiming to advance the reliability and security of systems. Feel free to reach out to me if you want to talk about security.

Experience

Quantstamp, inc.

Senior Security Researcher

Jul 2021Jan 2024 · 2 yrs 6 mos

  • Led team of auditors in several project audits, including Big Solana programs and Solidity Contracts. Researched new DeFi developments and security updates to continually improve protocol blockchain security. Analyzed fraudulent transactions and reverse-engineered attacks/exploits executed on the blockchain. Analyzed assembly code.
  • Created a tool to help auditors scope security audits, estimate time to audit, and reduce overall workload.
SolidityBlockchain SecurityDeFiAuditingFraud AnalysisAssembly Code Analysis

Halborn

Offensive Security Engineer

May 2020Jun 2021 · 1 yr 1 mo

  • Conducted audits and risk analyses on vulnerabilities in Smart Contracts - Ethereum under Solidity. Performed audits and penetration tests (pentests) of Solana programs and dAPP applications (DEX - DEFI). Pentested blockchain SKD and blockchain network infrastructure. Assessed both static and dynamic aspects of smart contracts.
Smart ContractsPenetration TestingRisk AnalysisEthereumSolana

Société générale

Senior Security Consultant

Jun 2018Apr 2020 · 1 yr 10 mos · Préfecture de Casablanca, Morocco

  • Enabled integration of DevSecOps into development cycle with analysis of tools and solutions. Audited mobile banking system applications inclusive of risk analysis, infrastructure audits, recommendation implementations, and compliance support for EU and Moroccan regulations. Wrote reports and set up action plan to correct vulnerabilities found in security testing of JAVA web applications.
  • Implemented several hardening rules and instructions for DevOps development cycle - Ngnix, Zuul, Keycloack, Jenkins.
  • Established reference for pentesting methodology and authored generic report specific to Société Générale Morocco.
  • Secured infrastructure and implemented DevSecOps process that reduced 90% of vulnerabilities.
DevSecOpsMobile SecurityRisk AnalysisInfrastructure AuditsCompliance Support

It6 group

Cyber Security Consultant

Jun 2017May 2018 · 11 mos · Rabat Prefecture, Morocco

  • Tested security of finance, government, and nonprofit platforms. Ensured conformity with DNSSI and master plans.
  • Conducted vulnerability analysis of EURAFRIC banking platform, exploited vulnerabilities, drafted report, and implemented action plan.
  • Performed code review of Ministry of Agriculture platform.
  • Tested security of Ministry of Health platform and rolled out action plan to correct vulnerabilities.
Vulnerability AnalysisSecurity TestingCode ReviewAction Plan Implementation

Absec cybersécurité

Cyber Security Consultant

Sep 2014Jun 2017 · 2 yrs 9 mos

  • Performed information gathering and system discovery of multiple platforms and web sites. Issued remediation and support recommendations and generated safety assessment reports, with technical notes. Installed, supported, and administered laboratory infrastructure security testing.
  • Tested security of trading platform with vulnerability analysis of website and heavy client.
  • Tested security of insurance agency mobile app; conducted website vulnerability analysis and application reverse engineering.
Information GatheringSystem DiscoveryVulnerability AnalysisTechnical Reporting

Stackforce found 100+ more professionals with Blockchain Security & Auditing

Explore similar profiles based on matching skills and experience