Emin Fidan
Security Engineer @ Midas
About
I am a Security Engineer with a strong focus on Application Security, DevSecOps, and Security Architecture, currently working at Midas. I combine offensive security expertise with defensive and preventive security practices to design scalable, developer-friendly, and risk-driven security programs. With 3+ years of hands-on experience, I work closely with engineering, platform, and leadership teams to embed security into the SDLC—not as a blocker, but as an enabler. My approach is pragmatic, automation-driven, and rooted in real-world threat models. Domains of expertise - Application Security - DevSecOps & Security Automation - Security Architecture - Cloud & Container Security - Vulnerability & Exposure Management Certifications: OSCP+, OSCP, OSWP, CKS, CKA, eMAPTv2, CAPT, CIPT, eWPTXv2, AWS-CCP, C-AI/MLPen, LFS-182, CASA, API-Pentest (CVE contributor: CVE-2025-22970) Medium: https://medium.com/@eminf.egitim GitHub: https://github.com/Emin-F
-
Türkiye
Information Services
Development, Container Security, Mobile Application Security, Application Security, Dynamic Code Analysis, Static Code Analysis, Source Code Analysis, Vulnerability Assesment, API Pentest, Siber Güvenlik, Linux, Python, Bash, Information Security, Penetration Testing, Web Application Security
Experience

Security Engineer
İstanbul, Türkiye
Key Responsibilities & Achievements: Security Architecture & Consultancy - Established the organization's Security Architecture Review standards and guides, conducting proactive reviews with engineering teams during the design phase to ensure "Security by Design." - Acted as a security consultant for internal process designs, ensuring compliant and secure data flows across services. AppSec & DevSecOps - Conducted whitebox security testing - Implemented Software Supply Chain Security protocols to detect and remediate vulns. - Developed and implemented a custom Security Step for CI/CD pipelines from scratch. - Guided the production of Secure Base Images and oversaw Image Signing processes to enhance container security. - Implemented Secure Code Warrior platform to gamify security training for the developer community. Vulnerability Management & Offensive Security - Managed the end-to-end Bug Bounty Program, including policy definition, CVSS scoring, verification, and remediation coordination. - Orchestrated Outsource Penetration Testing cycles, managing scoping, procurement, and retest processes. - Conducted manual security assessments for services prior to production releases. Network & Cloud Security - Managed & Revise WAF rules - Managed & Revise Security Groups IAM - Hardened infrastructure via managed granular IAM policies on VPNs based on the principle of least privilege. - Analyse & Revise Application RBAC Controls and Rules Incident Response & CTI - Contribute Incident Response Playbooks for phishing and malware analysis; managed real-time response, forensics, and post-incident reviews. - Contribute Cyber Threat Intelligence (CTI) efforts, monitoring for leaked credentials/domains and managing takedown processes (USOM/Registrars). - Contribute Fine-tunning SIEM & EDR alerts to improve detection accuracy

Associate Security Engineer
İzmir, Türkiye
- Performed manual source code reviews, security audits, and targeted security research for assessed products - Developed internal tools and solutions to improve application security processes - Acted as a security subject matter expert for secure coding, security testing, mobile, cloud, container, and application security - Configured and analyzed SAST, DAST and IAST scans - Conducted manual application security testing - Supported the Bug Bounty Program, including validation and triage - Assisted teams with reproducing, triaging, and remediating application security vulnerabilities - Contributed to security processes and automation to prevent recurring vulnerability classes - Enforced application security standards and guidelines across the Secure SDLC - Helped development teams understand and prioritize security findings from scanning tools - Collaborated with development and infrastructure teams to secure cloud-native applications (containers, microservices, serverless) - Worked with teams to identify and remediate cloud environment vulnerabilities - Collaborate adding mobile application security controls into CI/CD pipelines - Delivered web, mobile, and secure code review training during security hackathons
Emin Fidan's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.







