g
gabrielnbjj

Gabriel N.

@gabrielnbjj

Principal Security Engineer

Roumanie
Anglais, Roumain
Certaines informations sont présentées en anglais.
À propos de moi
Hi, I'm Gabriel, a Principal Security Engineer, specializing in cloud security, web apoplications and security monitoring. With 10 years of experience, I provide top-notch solutions to protect your assets from cyber threats. Services include network security design, penetration testing, threat analysis, incident response, and security audits across the entire Microsoft Security Toolset. ... Plus d’infos

Compétences

g
gabrielnbjj
Gabriel N.
hors ligne • 

Voir mes services

Réseau Cloud et sécurité
I will provide azure security consultancy
Réseau Cloud et sécurité
I will provide azure sentinel consultancy

Expérience professionnelle

defendermate

Security Research Lead

defendermate

Sep 2025 - Present1 yr

- Built an enterprise security knowledge graph, ingesting data from identity systems, cloud providers and security tools to compute effective permissions as well as effective network paths. - Designed a novel attack path representation system on top of an enterprise security knowledge graph, built from scratch, showcasing chaining of attacker tactics, techniques and procedures. - Built a service that collected, aggregated, curated and deduplicated OSINT data for a given CVE. - Designed an agentic exploitability verification system for CVEs. - Built a harness producing exploitable and non-exploitable docker images for evaluation. - Built an in-house vulnerability management system using cloud agents for compliance purposes.

UiPath

Principal Security Engineer

UiPath • Temps plein

Jun 2024 - Sep 20251 yr 3 mos

- Implemented Detection as Code pipeline for the SOC team, bringing Azure Sentinel, XDR and custom data lake alerting into a single, unified engine. - Implemented threat informed risk based alerting methodology to help reduce volume and bring context to threats in Sentinel - Developed a log secret scanner service to address secret leakage into logs. Over 30 terabytes per day processed from multiple log sources continuously. - Developed an LLM-enhanced SaaS Secret Scanner to discover and validate secrets leaked into Confluence, Jira, etc. - Developed a secret permission enricher to prioritize leaked secrets with context over the permissions they have - Led major incident responses across both the product space and corporate space. - Designed the multi-cloud logging and threat detection architecture (GCP, AWS, Azure) to ensure coverage,scalable and affordable handling of over 10 TB per day worth of data - Contributor to the in-house AI SOC solution. - Active mentoring of team members - Web Application Security Testing

Spotnana

Staff Security Engineer

Spotnana

Jul 2022 - Jun 20241 yr 11 mos

- Solely responsible for security monitoring, incident response and digital forensics across on-prem, cloud (AWS) and application environments. - Designed, deployed and configured the entire Spotnana Security Monitoring stack across the board, including tools such as SentinelOne (Crowdstrike later), AquaSec (across containers, integrated in CICD), Snowflake, Hunters XDR (as code). - Detection engineering work to cover critical business use-cases - Created and deployed an automated third party vulnerability and secrets management program that automatically identified, prioritized and assigned work to relevant owners with state management of the findings and tickets automated completely. - Codified the Crowdstrike Configuration to ensure we can manage it as code from Github - Integrated security controls within the application CICD pipeline. - Performed constant security reviews across all the environments (on-prem and cloud), leading to several critical attack paths identified and remediated, efforts which informed the architecture team. - Deployed a compliance chat bot to help the compliance team reduce the time spent on security RFPs. - Deployed API Security program, leveraging API Security Scanners integrated as side-car containers to identify API Security issues, leading to several critical issues being found. - Built a device compliance agent that helped us fill MDM gaps and understand whether an endpoint was compliant to our standards or not. - Helped the cloud operations team migrate to 0-CVE base images to reduce our attack surface. - Created automations to deploy honey tokens at scale across the enterprise. - Constant performing of cost optimizations to ensure the Security Footprint across the budget is as small as possible. - Web Application Security Testing