Yassine Belkhadem

Curriculum vitae / 2026

Yassine Belkhadem

Software Engineering Graduate focused on product security, offensive tooling, and cloud systems.

Email
yassine.belkhadem@insat.ucar.tn
LinkedIn
Profile
GitHub
yassinebk
04

Experience

to

Product Security Engineer

Mercari

Tokyo, Japan, Hybrid

  • Current Product Security Engineer at Mercari.
  • Product Security
  • Web Application Security
  • Security Engineering
to

Rust Backend Engineer

Stockly

Paris, France, Onsite

  • Developed backend integrations with suppliers.
  • Maintained, optimized, and improved the existing Rust codebase.
  • Rust
  • Backend Engineering
  • API Integrations
to

Product Security Intern

Mercari

Tokyo, Japan, Hybrid

  • Enhanced DAST process By developing an extension for Burp Suite Enterprise and Nuclei using Burp Montoya API in Java.
  • Engineered Golang control server for Nuclei in a microservices architecture with NextJS frontend.
  • Automated security checks for 5,200+ repositories using Golang, GitHub API, GCP Scheduled Jobs, and BigQuery.
  • Burp Suite
  • OWASP Top 10
  • Web Application Security
  • Threat Modeling
  • Java
  • Golang
  • NextJS
to

Software Engineer

CTF.ae

Dubai, UAE, Remote

  • Contributed to CTF platform development using .NET ASP.NET and React.
  • Implemented E2E and integration tests and optimized CI/CD pipelines.
  • Organized CTF competitions for Black Hat MEA in 2024 and 2025.
  • Organized the DEF CON Bug Bounty Village CTF in 2025.
  • Organized the Dubai Police CTF in 2026.
  • C#
  • .NET
  • React
  • E2E Testing
  • Integration Testing
  • Capture the Flag
  • Web Application Security
to

Cybersecurity Engineer Intern

PCP Consulting

Toulouse, France, Remote

  • Developed in-house auditing tool in Golang using Hexagonal Architecture.
  • Created unified dashboard using NextJS for multi-cloud infrastructure management.
  • Implemented real-time notification system for cloud configuration changes.
  • Golang
  • NextJS
  • GCP
  • AWS
  • Azure
  • Terraform
  • Cloud Formation
to

CTO & Co-Founder

K-Noon

Tunis, Tunisia, Hybrid

  • Developed proof of concept in React to secure investor interest.
  • Established and documented technical direction and strategy.
  • Led recruitment, mentorship, and technical team upskilling.
  • Technical Leadership
  • Mentorship
  • Gitlab CI/CD
  • API Development
  • Clean Architecture
  • Typescript
  • React
to

Red Team Intern

Ernst and Young

Tunis, Tunisia, Hybrid

  • Developed real-time dynamic Red Teaming lab with over 130 scenarios.
  • Created 15 vulnerable web applications and binaries for training.
  • Vulnerability Research
  • Web Application Security
  • Penetration Testing
  • Red Teaming
  • Ansible
  • Docker
  • Azure
05

Projects

01

Request Minimizer Modernized

A modern Burp Suite request minimizer built with Java 21 and the Montoya API.

Open
02

Caido Next.js Actions Analyzer

A Caido plugin for detecting Next.js Server Actions.

Open
03

Distributed Database Synchronizer

A distributed database synchronizer using Golang, Fyne, and RabbitMQ to ensure data consistency between geographically dispersed database parts and a central database, even in case of server failures.

Open
04

Lein Digital Assistant

A Python Discord assistant for managing schedules, tasks, and daily workflow noise.

Open
05

Codex Profile Switcher

A TypeScript CLI for managing Codex skill profiles.

Open
06

GraphQL Mapper

A Caido community plugin for mapping and visualizing GraphQL endpoints.

Open
07

C2 Chopper

A flexible and extensible C2 framework built with Golang and React for managing red team operations during penetration testing missions.

Open
08

LDAP Kerberos DNS Lab

A lab environment for experimenting with LDAP, Kerberos, and DNS, utilizing Docker for ease of use and rapid development.

Open
09

Hadoop and Kafka and Grafana for Job Posting Data Analysis

A project that collects job posting data from various sources like LinkedIn and Twitter, providing real-time and historical insights using Hadoop and Kafka.

Open
10

Job/Internship Application Tracker

A simple website to track job applications, providing a structured approach to managing and improving the application process.

Open
11

Ein Framework

Ein revolutionizes penetration testing with its template-based declarative attack system, Go-powered engine, AI-assisted template generation, and a sleek Svelte frontend.

Open
12

NCSC Booking and Event Sites

A website to allow tickets buying and hotel reservations for participants in the National Congress of Cybersecurity

Open
13

Distributed Text Editor

A distributed GUI text editor allowing multiple users to edit the same document simultaneously and remotely. Built using RabbitMQ and Golang.

Open
14

Vulnerable Smart Contracts

A collection of smart contracts designed to educate developers about common blockchain vulnerabilities.

Open
15

Online Library (.NET)

An online library management system built using .NET, providing features for managing books, members, and borrowing activities.

Open
16

Robolympix

A platform for a robotics event, featuring user profiles, conference booking, and a personalized space with Japanese-themed animations.

Open
17

Damn Vulnerable DeFi Solvers

Solvers for Damn Vulnerable DeFi challenges, utilizing Hardhat.js for testing and exploiting vulnerabilities in decentralized finance applications.

Open
18

Devini Workshop

Website to hold course material for workshops on full stack development for students, Held in the summer of 2022.

Open

Get in touch

Let’s discuss the work.

For product security, backend engineering, CTF collaboration, or speaking opportunities.