Ilyas Ousbaa

Cyber Security Consultant

Ilyas Ousbaa

I study attacker behavior to design defenses that actually hold up.

Currently hunting on HackerOne and researching secret-exposure detection.

Morocco

/

Arabic, English, French

Whoami

I’m a cyber security consultant and analyst with 3+ years of experience spanning SOC operations, threat hunting, and vulnerability management, reinforced by mission-critical and freelance engagements. I bring an offensive security mindset to defensive work, studying attacker behavior and mapping exploit paths to cut through noise and prioritize what actually matters.

My methodology is analytical and strategic: I identify exploitable flaws, then design and automate proactive defenses to reduce risk. I collaborate closely with IAM, Vulnerability Management, Penetration Testing, and operations teams, adapting to evolving attack vectors and closing remediation loops end-to-end.

I’m based in Morocco, currently researching on HackerOne, and open to consulting and full-time roles in detection engineering, threat hunting, and offensive-informed defense.

Technologies

Network Security & Defense

FortiGate

Sophos

Check Point

Wazuh (SIEM/XDR)

Reconnaissance & Assessment

Burp Suite

Nuclei

Nmap

Amass

Vulnerability Management

Tenable Nessus

MISP

OpenCTI

CVSS / EPSS

Vulnerability Management

Tenable Nessus

MISP

OpenCTI

CVSS / EPSS

Automation & Engineering

Python

Go

PowerShell

Docker

Experiences

Security Researcher & Detection Engineer

/

HackerOne

Jun 2025

-

Present

  • Conduct web application penetration testing with responsible disclosure via structured reports.

  • Research authentication flows, access control weaknesses, and real-world misconfigurations with an exploitability focus.

  • Continuous hands-on training via TryHackMe, HackTheBox, and PortSwigger Web Security Academy, reinforcing exploitation technique across web, network, and API targets.

Security Researcher & Detection Engineer

/

HackerOne

Jun 2025

-

Present

  • Conduct web application penetration testing with responsible disclosure via structured reports.

  • Research authentication flows, access control weaknesses, and real-world misconfigurations with an exploitability focus.

  • Continuous hands-on training via TryHackMe, HackTheBox, and PortSwigger Web Security Academy, reinforcing exploitation technique across web, network, and API targets.

Security Researcher & Detection Engineer

HackerOne

Jun 2025

-

Present

  • Conduct web application penetration testing with responsible disclosure via structured reports.

  • Research authentication flows, access control weaknesses, and real-world misconfigurations with an exploitability focus.

  • Continuous hands-on training via TryHackMe, HackTheBox, and PortSwigger Web Security Academy, reinforcing exploitation technique across web, network, and API targets.

Cyber Security Consultant

/

AXA GBS (via WITKY Group)

Mar 2024

-

May 2025

  • Developed a credential-exposure detection tool in PowerShell, scanning local systems, GitHub, SharePoint, Confluence, and NAS environments while substantially reducing false positives.

  • Refined and enhanced regex-based pattern matching and YAML detection rules, driving a significant reduction in false positives and enabling prioritized, actionable findings.

  • Closed the remediation loop end-to-end - automated owner lookup, revocation notifications, and validation checks - improving identity hygiene and remediation turnaround.

Cyber Security Consultant

/

AXA GBS (via WITKY Group)

Mar 2024

-

May 2025

  • Developed a credential-exposure detection tool in PowerShell, scanning local systems, GitHub, SharePoint, Confluence, and NAS environments while substantially reducing false positives.

  • Refined and enhanced regex-based pattern matching and YAML detection rules, driving a significant reduction in false positives and enabling prioritized, actionable findings.

  • Closed the remediation loop end-to-end - automated owner lookup, revocation notifications, and validation checks - improving identity hygiene and remediation turnaround.

Cyber Security Consultant

AXA GBS (via WITKY Group)

Mar 2024

-

May 2025

  • Developed a credential-exposure detection tool in PowerShell, scanning local systems, GitHub, SharePoint, Confluence, and NAS environments while substantially reducing false positives.

  • Refined and enhanced regex-based pattern matching and YAML detection rules, driving a significant reduction in false positives and enabling prioritized, actionable findings.

  • Closed the remediation loop end-to-end - automated owner lookup, revocation notifications, and validation checks - improving identity hygiene and remediation turnaround.

Cyber Security Operations Analyst

/

SMA Services

Apr 2023

-

Jun 2023

  • Monitored threats across B2B infrastructure using FortiGate, Sophos, Check Point, Nessus, and Tenable SC.

  • Deployed and hardened VPNs, routing/switching, and Access Points to secure client network operations.

Cyber Security Operations Analyst

/

SMA Services

Apr 2023

-

Jun 2023

  • Monitored threats across B2B infrastructure using FortiGate, Sophos, Check Point, Nessus, and Tenable SC.

  • Deployed and hardened VPNs, routing/switching, and Access Points to secure client network operations.

Cyber Security Operations Analyst

SMA Services

Apr 2023

-

Jun 2023

  • Monitored threats across B2B infrastructure using FortiGate, Sophos, Check Point, Nessus, and Tenable SC.

  • Deployed and hardened VPNs, routing/switching, and Access Points to secure client network operations.

Cyber Security Analyst

/

Direction Centrale des Systemes d'Information, Barid Al-Maghreb

Jan 2023

-

Mar 2023

  • Improved SOC detection pipeline efficiency by refining alert logic and detection rules, enhancing alert fidelity and prioritization.

  • Rebuilt SIEM/XDR log pipelines on Wazuh and Docker, increasing log coverage and detection performance for a government-scale environment.

  • Supported incident response and monitoring operations.

Cyber Security Analyst

/

Direction Centrale des Systemes d'Information, Barid Al-Maghreb

Jan 2023

-

Mar 2023

  • Improved SOC detection pipeline efficiency by refining alert logic and detection rules, enhancing alert fidelity and prioritization.

  • Rebuilt SIEM/XDR log pipelines on Wazuh and Docker, increasing log coverage and detection performance for a government-scale environment.

  • Supported incident response and monitoring operations.

Cyber Security Analyst

Direction Centrale des Systemes d'Information, Barid Al-Maghreb

Jan 2023

-

Mar 2023

  • Improved SOC detection pipeline efficiency by refining alert logic and detection rules, enhancing alert fidelity and prioritization.

  • Rebuilt SIEM/XDR log pipelines on Wazuh and Docker, increasing log coverage and detection performance for a government-scale environment.

  • Supported incident response and monitoring operations.

Information Technology Security Specialist

/

Provincial Delegation of Health

May 2022

-

Jun 2022

  • Implemented security hardening measures, reducing overall vulnerability exposure.

  • Maintained critical infrastructure with consistent high availability, ensuring business continuity.

Information Technology Security Specialist

/

Provincial Delegation of Health

May 2022

-

Jun 2022

  • Implemented security hardening measures, reducing overall vulnerability exposure.

  • Maintained critical infrastructure with consistent high availability, ensuring business continuity.

Information Technology Security Specialist

Provincial Delegation of Health

May 2022

-

Jun 2022

  • Implemented security hardening measures, reducing overall vulnerability exposure.

  • Maintained critical infrastructure with consistent high availability, ensuring business continuity.

Information Technology Security Specialist

/

Provincial Hospital of Khenifra

Jun 2021

-

Jul 2021

  • Optimized and hardened IT infrastructure across clinical and administrative environments.

  • Improved system stability, responsiveness, and security while resolving technical support tickets.

  • Collaborated with healthcare staff to tailor IT solutions to clinical workflows, ensuring operational alignment.

Information Technology Security Specialist

/

Provincial Hospital of Khenifra

Jun 2021

-

Jul 2021

  • Optimized and hardened IT infrastructure across clinical and administrative environments.

  • Improved system stability, responsiveness, and security while resolving technical support tickets.

  • Collaborated with healthcare staff to tailor IT solutions to clinical workflows, ensuring operational alignment.

Information Technology Security Specialist

Provincial Hospital of Khenifra

Jun 2021

-

Jul 2021

  • Optimized and hardened IT infrastructure across clinical and administrative environments.

  • Improved system stability, responsiveness, and security while resolving technical support tickets.

  • Collaborated with healthcare staff to tailor IT solutions to clinical workflows, ensuring operational alignment.

Recent Projects

Latest Research

Compound Exposure Model (CEM) for Software Secret Severity

Preprint

Ilyas Ousbaa

A deterministic hybrid framework combining additive structural severity (5 facets) and noisy-OR exposure (8 factors), with an independent Confidence Index and Floor/Ceiling dual-scoring, validated against 1,373 unified detectors from GitGuardian x TruffleHog.

Skills

Network Architecture & Administration

Routing, switching, VPN deployment, firewall policy management, and high-availability infrastructure maintenance.

Systems Hardening & IT Operations

OS-level security configuration, vulnerability exposure reduction, performance optimization, and business continuity support.

Security Operations (SOC)

Incident response, log analysis, alert tuning, anomaly detection, and SIEM/XDR pipeline engineering.

Vulnerability Management Lifecycle

End-to-end assessment, prioritization via CVSS/EPSS, remediation tracking, patch validation, and SLA-driven risk reduction across hybrid infrastructures.

Identity & Access Management (IAM)

Credential hygiene, privileged access workflows, zero-trust principles, and MITRE ATT&CK-driven detection logic.

Threat Intelligence & Reconnaissance

Attack surface discovery, OSINT gathering, and proactive threat hunting across internal and external environments.

Detection Engineering & Automation

Custom rule development in SIGMA, YARA, and regex, exploit-path prioritization, and CI/CD pipeline security.

Cyber Threat Hunting & Analysis

Studying attacker behavior and mapping exploit paths to prioritize what matters, reinforced through TryHackMe, HackTheBox, and PortSwigger training.

Ilyas Ousbaa

Open to Work

© 2026 Ilyas Ousbaa

Create a free website with Framer, the website builder loved by startups, designers and agencies.