y
youssef_andrews

Youssef A

@youssef_andrews

Cybersecurity Engineer

Verenigde Staten
Engels, Arabisch
Sommige informatie wordt in het Engels weergegeven.
Over mij
I am a Security+ certified cybersecurity engineer completing an M.S. in Systems Engineering. I have hands-on experience securing cloud infrastructure, strengthening identity and access management, and running pre-launch security programs. I am comfortable working alongside software engineers and briefing leadership to integrate security throughout the development lifecycle.... Lees meer

Skills

y
youssef_andrews
Youssef A
offline • 
Gemiddelde reactietijd: 1 uur

Bekijk mijn diensten

Cloudnetwerk en -beveiliging
I will audit your cloud security configuration and access controls

Werkervaring

Cybersecurity Engineer Intern

Unlisted • Parttime

May 2026 - Aug 2026 • 3 mos

• Ran a 62 task CIS Controls v8 (IG1) security program as the company’s first security hire, closing all 48 in scope tasks across mobile, web, and backend before public launch and reviewing each teammate’s remediation evidence before sign off. • Directed the access control and audit logging workstreams, covering GCP Cloud Audit Logs, Security Command Center alerting to Slack, and MFA enforcement on GCP and Firebase, and audited IAM across Cloud Run, Cloud Functions, and Secret Manager for least privilege. • Tracked vulnerability findings to closure across company repositories: scanned full commit history with TruffleHog and rotated exposed credentials, decompiled the Android build with jadx for hardcoded secrets, pushed Dependabot and Snyk alerts through remediation, and piloted the Garak LLM scanner against AI facing endpoints. • Found a broken authorization flaw exposing roughly 324 user records of PII by reading backend authorization logic and database access controls, documented the root cause for engineering leadership, and verified the fix before it reached production. • Closed a privilege escalation path across 40 Postgres SECURITY DEFINER functions missing search_path hardening, rewrote Supabase Row Level Security policies to remove publicly readable tables, and wrote Python and Bash automation in GitHub so configuration checks ran the same way every time.