Ali Yazdani

Co-Founder

Berlin, Berlin, Germany16 yrs 3 mos experience

Key Highlights

  • Over 10 years of experience in the security industry.
  • Expert in implementing DevSecOps culture and security guardrails.
  • Proven track record in penetration testing and vulnerability management.
Stackforce AI infers this person is a seasoned security engineer specializing in DevSecOps and application security within the tech industry.

Contact

Skills

Core Skills

DevsecopsApplication SecurityThreat & Vulnerability ManagementPenetration TestingWeb Application Security Assessment

Other Skills

KubernetesTeam LeadershipInformation SecurityWeb Application SecuritySecurity AuditsSecurityPythonLinuxDockerAmazon Web Services (AWS)Microsoft AzureTerraformIstioMobile SecurityEnterprise Security Architecture

About

With over 10 years of experience in the security industry, I have honed my skills in various sectors and companies. Beginning my journey as a penetration tester, I gained valuable insights into the offensive side of application security. As I progressed in my career, I focused on helping organizations implement security guardrails and solutions to address their security concerns. Throughout this journey, I was exposed to numerous technologies and strategies that piqued my interest. Today, my passion lies in assisting companies in cultivating a strong DevSecOps culture to ensure their security posture is robust and effective.

Experience

16 yrs 3 mos
Total Experience
3 yrs 3 mos
Average Tenure
--
Current Experience

Scandog

Founder

Jan 2025Present · 1 yr 3 mos · Berlin, Germany · Remote

Scoutbee

Principal DevSecOps Engineer

Aug 2022Dec 2024 · 2 yrs 4 mos · Berlin, Germany · Remote

  • Implementing SAST, SCA, IaC, PaC, and DAST as part of the CI/CD pipelines.
  • Threat modeling and analyzing software designs, implementations, and infrastructure to identify security issues and design countermeasures.
  • Managing penetration test programs on applications and services.
  • Define a vulnerability disclosure program (VDP) to identify vulnerabilities in internet-facing services.
  • Promoting the shift-left strategy and DevSecOps culture by starting the threat modeling section.
KubernetesDevSecOpsApplication Security

Henkel

Engineering Lead DevSecOps

Sep 2021Jul 2022 · 10 mos · Berlin, Germany · Hybrid

  • Implement SAST, SCA, IaC, PaC, and DAST as part of the CI/CD pipelines.
  • Threat modeling and analyzing software designs, implementations, and infrastructure to identify security issues and design countermeasures.
  • Manage penetration test programs on applications and services.
  • Promote the shift-left strategy and DevSecOps culture by starting the threat modeling section.
DevSecOpsApplication Security

Raisin

Senior Security Engineer

Jul 2019Aug 2021 · 2 yrs 1 mo · Hamburg Area, Germany · Hybrid

  • Perform periodic and on-demand vulnerability assessments and penetration tests.
  • Design and evaluate cloud/hybrid infrastructure development leveraging Azure IaaS and PaaS.
  • Threat modeling and analyzing software designs, implementations, and infrastructure to identify security issues and design countermeasures.
  • Perform security testing and code review as part of the SDLC pipeline to improve software security. (promoting the shift-left strategy and DevSecOps culture).
  • Implement SAST, SCA, and DAST as part of the CI/CD pipelines.
KubernetesDevSecOpsApplication Security

Atieh dadeh pardaz - آتیه داده پرداز

Penetration Tester (Part-time)

Mar 2016Dec 2018 · 2 yrs 9 mos · Iran

  • ADP Digital is a solution provider for Major banks and major enterprises in Iran by providing Internet Mobile Banking, Short-text-message, and internet notification service, and Datacenter collocation services.
  • My role was the responsibility to perform penetration test on their Web application and Mobile application to ensure the security of the app.
Penetration TestingApplication Security

Mtn

Red Team Tech Lead

Nov 2015Apr 2019 · 3 yrs 5 mos · Iran · On-site

  • Implement regular Vulnerability assessments and Penetration tests on IT services.
  • Review service architecture and perform threat modeling documents for significant services.
  • To define and enforce IT infrastructure security checklists for new and existing systems considering the MTN Irancell standards and requirements.
  • Develop security tools to automate the IT security process.
  • Collaborate with the Bule team to implement and manage SIEM and integrate this solution with IT services.
  • Collaborate with ISO auditors to implement ISO27001.
  • Collaborate with the DevOps team to find security issues and automate some test cases.
Threat & Vulnerability ManagementTeam LeadershipApplication Security

Freelancer

Penetration Tester

Mar 2008Oct 2015 · 7 yrs 7 mos · Iran

  • Implement penetration test and provide a related report based on customer request.
  • Drive vulnerability assessment program on the customer network.
  • Develop and implement a security dashboard for our customers.
  • Establish detection and prevention solutions to improve customer security.
Penetration TestingWeb Application Security Assessment

Education

Jahaad Software Academic Institute – Esfahan

Bachelor's degree — Computer Software Engineering

Jan 2010Jan 2013

Jahaad Software Academic Institute – Esfahan

Associate's degree — Computer Software Engineering

Jan 2006Jan 2009

Stackforce found 100+ more professionals with Devsecops & Application Security

Explore similar profiles based on matching skills and experience