Emin Fidan

Emin Fidan

Security Engineer @ Midas

About

I am a Security Engineer with a strong focus on Application Security, DevSecOps, and Security Architecture, currently working at Midas. I combine offensive security expertise with defensive and preventive security practices to design scalable, developer-friendly, and risk-driven security programs. With 3+ years of hands-on experience, I work closely with engineering, platform, and leadership teams to embed security into the SDLC—not as a blocker, but as an enabler. My approach is pragmatic, automation-driven, and rooted in real-world threat models. Domains of expertise - Application Security - DevSecOps & Security Automation - Security Architecture - Cloud & Container Security - Vulnerability & Exposure Management Certifications: OSCP+, OSCP, OSWP, CKS, CKA, eMAPTv2, CAPT, CIPT, eWPTXv2, AWS-CCP, C-AI/MLPen, LFS-182, CASA, API-Pentest (CVE contributor: CVE-2025-22970) Medium: https://medium.com/@eminf.egitim GitHub: https://github.com/Emin-F

Country

-

City

Türkiye

Industry

Information Services

Skill

Development, Container Security, Mobile Application Security, Application Security, Dynamic Code Analysis, Static Code Analysis, Source Code Analysis, Vulnerability Assesment, API Pentest, Siber Güvenlik, Linux, Python, Bash, Information Security, Penetration Testing, Web Application Security

Experience

Midas

Security Engineer

Midas

LinkedIn
2025-5 - Present · 1 yr 5 mos

İstanbul, Türkiye

Key Responsibilities & Achievements: Security Architecture & Consultancy - Established the organization's Security Architecture Review standards and guides, conducting proactive reviews with engineering teams during the design phase to ensure "Security by Design." - Acted as a security consultant for internal process designs, ensuring compliant and secure data flows across services. AppSec & DevSecOps - Conducted whitebox security testing - Implemented Software Supply Chain Security protocols to detect and remediate vulns. - Developed and implemented a custom Security Step for CI/CD pipelines from scratch. - Guided the production of Secure Base Images and oversaw Image Signing processes to enhance container security. - Implemented Secure Code Warrior platform to gamify security training for the developer community. Vulnerability Management & Offensive Security - Managed the end-to-end Bug Bounty Program, including policy definition, CVSS scoring, verification, and remediation coordination. - Orchestrated Outsource Penetration Testing cycles, managing scoping, procurement, and retest processes. - Conducted manual security assessments for services prior to production releases. Network & Cloud Security - Managed & Revise WAF rules - Managed & Revise Security Groups IAM - Hardened infrastructure via managed granular IAM policies on VPNs based on the principle of least privilege. - Analyse & Revise Application RBAC Controls and Rules Incident Response & CTI - Contribute Incident Response Playbooks for phishing and malware analysis; managed real-time response, forensics, and post-incident reviews. - Contribute Cyber Threat Intelligence (CTI) efforts, monitoring for leaked credentials/domains and managing takedown processes (USOM/Registrars). - Contribute Fine-tunning SIEM & EDR alerts to improve detection accuracy

Trendyol Group

Associate Security Engineer

Trendyol Group

LinkedIn
2023-9 - 2025-5 · 1 yr 9 mos

İzmir, Türkiye

- Performed manual source code reviews, security audits, and targeted security research for assessed products - Developed internal tools and solutions to improve application security processes - Acted as a security subject matter expert for secure coding, security testing, mobile, cloud, container, and application security - Configured and analyzed SAST, DAST and IAST scans - Conducted manual application security testing - Supported the Bug Bounty Program, including validation and triage - Assisted teams with reproducing, triaging, and remediating application security vulnerabilities - Contributed to security processes and automation to prevent recurring vulnerability classes - Enforced application security standards and guidelines across the Secure SDLC - Helped development teams understand and prioritize security findings from scanning tools - Collaborated with development and infrastructure teams to secure cloud-native applications (containers, microservices, serverless) - Worked with teams to identify and remediate cloud environment vulnerabilities - Collaborate adding mobile application security controls into CI/CD pipelines - Delivered web, mobile, and secure code review training during security hackathons

BGA Bilgi Güvenliği

Penetration Testing Specialist

BGA Bilgi Güvenliği

LinkedIn
2023-1 - 2023-9 · 9 mos

- Web Application Penetration Testing - Mobile Application Penetration Testing - API Pentesting - Static Code Analysis - Dynamic Code Analysis - Vulnerability Management / Assesment - Penetration Test Reporting Process

BGA Bilgi Güvenliği

Jr Penetration Tester

BGA Bilgi Güvenliği

LinkedIn
2022-8 - 2023-1 · 6 mos

- Web Application Penetration Testing - API Pentesting - Application Security Research - Secure Code Review - Vulnerability Management / Assesment - Penetration Test Reporting Process

BGA Bilgi Güvenliği

Part Time Penetration Tester

BGA Bilgi Güvenliği

LinkedIn
2022-3 - 2022-8 · 6 mos

İstanbul, Türkiye

- Vulnerability Reporting Process - Security Research - Web Pentesting Studies • Information Security • Vulnerability Managment

BGA Bilgi Güvenliği

Penetration Tester Intern

BGA Bilgi Güvenliği

LinkedIn
2021-11 - 2022-3 · 5 mos

İstanbul, Türkiye

- Vulnerability Reporting Process - Security Research

Medium

Content Creator

Medium

LinkedIn
2022-3 - 2023-9 · 1 yr 7 mos

Offensive & AppSec studies, lab solutions and writes-up on cyber security. https://medium.com/@eminf.egitim

Platin Bilişim

Cyber Security Intern

Platin Bilişim

LinkedIn
2021-8 - 2021-9 · 2 mos

İstanbul, Türkiye

- Simulate Web Security Attacks on Vulnerable Machine - Bash Scripting - Observation SOC Team Process and Case Studies on IBM QRadar • Make Presentation on Phishing

Ege ROV Takımı

Technical Team Member

Ege ROV Takımı

LinkedIn
2020-3 - 2020-8 · 6 mos

İzmir

2020 Teknofest Unmanned Underwater Vehicle Competition Finalist Team Image Processing and Software Team Leader - Image Processing - Software Development - Reporting Process - Rasberry Pi

Ege Üniversitesi Savunma Teknolojileri Topluluğu

Yönetim Kurulu Üyesi

Ege Üniversitesi Savunma Teknolojileri Topluluğu

LinkedIn
2020-3 - 2020-6 · 4 mos

İzmir

Ege University Technology Community member and Board Treasurer - Technical Project Planning - Training Coordination - Sponsorship Negotiations - Social Media Management

Education

Ege University

Ege University

LinkedIn

Bilgisayar Mühendisliği

2018 - 2022 · 4 yrs

Emin Fidan's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.