A

Anatolii S.

Security Engineer

Amersfoort, Utrecht, Netherlands7 yrs 6 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Over 8 years of hands-on security experience.
  • Expert in web and mobile application security.
  • Proficient in threat modeling and vulnerability assessments.
Stackforce AI infers this person is a Cybersecurity expert with a focus on application security and vulnerability management.

Contact

Skills

Core Skills

Security EngineeringPenetration TestingActive DirectorySecurity Consulting

Other Skills

Mobile ApplicationsMicrosoft Entra IDSecurity ResearchVulnerability AssessmentKerberosOWASPLarge Language Models (LLM)Threat ModelingSecure Code ReviewPythonInformation SecurityProgrammingGPENRisk AssessmentShell Scripting

About

With over 8 years of hands-on security experience, Anatolii helps organizations break before attackers do. His work focuses on web and mobile applications, code review, cloud environments, LLMs, Active Directory, and network security. He keeps up with how attacks actually evolve and uses that knowledge to give practical, no-nonsense guidance teams can act on.

Experience

7 yrs 6 mos
Total Experience
1 yr 10 mos
Average Tenure
3 yrs 1 mo
Current Experience

Anvil secure

Security Engineer

Apr 2023Present · 3 yrs 1 mo · Amsterdam, North Holland, Netherlands

  • As a Security Engineer, Anatolii was responsible for API and web application security testing, mobile application security assessments, and in-depth reviews of cloud infrastructure. Led security source code reviews and developed internal security tools to enhance testing efficiency and coverage. Worked with testing LLMs and evaluating their guardrails to identify security weaknesses, misuse scenarios, and potential abuse paths. Applied STRIDE-based threat modeling to identify architectural risks early, providing actionable guidance to engineering teams to strengthen overall security posture across applications and platforms.
Security EngineeringPenetration Testing

Secura

Cyber Security Specialist

Mar 2022Mar 2023 · 1 yr · Amsterdam, North Holland, Netherlands

  • Anatolii had a strong focus on offensive security, conducting network and Active Directory penetration tests to identify privilege escalation paths, lateral movement opportunities, and critical misconfigurations. Performed web and mobile application penetration testing and developed mobile security testing guidance to standardize assessment approaches and improve testing quality. Delivered clear, actionable remediation recommendations to strengthen client security posture across environments.
Active DirectoryMicrosoft Entra ID

Dataart

Cyber Security Consultant

Oct 2019Feb 2022 · 2 yrs 4 mos · Wrocław, Dolnośląskie, Poland

  • Performed penetration tests of mobile applications related to finances, education, logistics, client services, and others. Basically, tests included four phases: threat modeling, security testing (ST/DT), recommendations report writing, and fixes reassessment. During Dynamic Testing, besides the mobile-related issues, Anatolii also evaluated the security of the back-end components, APIs, and implementation of transport security mechanisms. During Static Testing, he investigated the source code, looked for extraneous functionality presence and sensitive data hardcoding, and estimated the overall code quality.
  • Anatolii also conducted vulnerability assessments of web applications and related server-side components. Among the solutions were banking, trading, healthcare, resources management, client services, streaming, traveling, and others. The tests included black-box testing, as well as white-box ones. All of them were based on compliance regulations such as GDPR, PCI DSS, and the OWASP project.
  • Being engaged in penetration testing of connected devices (IoT), Anatolii evaluated the security mechanisms implemented by the devices. I rarely found that the devices mutually authorized services while protecting the confidentiality, integrity, and privacy of the data they collected and shared between the endpoints.
  • During the testing, I faced an increasing number of cloud-based solutions. As organizations continue to develop new applications or migrate existing applications to cloud-based services, new potential vulnerabilities appear. Lately, I've been identifying different authorization and authentication issues within the implementations of the Amazon solutions (e.g., AWS Cognito, AWS S3), Okta, Azure, and other popular cloud providers.
Security ConsultingSecurity Research

Deloitte

2 roles

Cyber Security Consultant

Sep 2018Oct 2019 · 1 yr 1 mo · Kiev Region, Ukraine

  • Performed technical evaluations of the client's solutions to identify risks and to assess the design and effectiveness of controls established to ensure confidentiality, integrity, and availability of the systems and data.
  • Conducted black box as well as grey box network penetration testings using Metasploit Framework, Nessus, Netsparker, and other automated scanners to uncover vulnerabilities or loopholes in the infrastructures of international companies. Advised developers on impacts from assessments and potential solutions for fixing the issues identified.
  • Conducted Web/Mobile Applications Vulnerability Assessments for banking and healthcare applications using Burp Suite, OpenVAS, Nikto, OWASP ZAP, SQLmap, and other open-source tools. During penetration tests of mobile applications and related infrastructure, I used the following software: networking (Proxyman, Wireshark, Nessus, Nmap), Swiss knife (Passionfruit, Cydia tweaks, Frida with modules, Metasploit Framework), static and dynamic analysis (Drozer Framework, MobSF, Cycript, Sonarqube), reverse engineering (apktool, d2j-dex2jar, Hopper), transport security (testssl), development and source code analysis (Android Studio, Xcode). Additionally, for some projects, I built custom tools for security audits of the solutions.
  • After each testing was completed, I prepared reports containing detailed information about the identified vulnerabilities, efforts required for the remediation, and assisted customers in filling the security gaps that were identified.

Intern

Jun 2018Aug 2018 · 2 mos · Kiev Region, Ukraine

Education

National Technical University of Ukraine 'Kyiv Polytechnic Institute'​

Bachelor's degree — Cybersecurity

Jan 2017Jan 2021

Stackforce found 100+ more professionals with Security Engineering & Penetration Testing

Explore similar profiles based on matching skills and experience