Yassine SAHLI

Yassine SAHLI

System Security Engineer @ SAGEMCOM

About

Cybersecurity & Systems Security Engineer specializing in building, hardening, and automating secure infrastructures at scale. I combine hands-on engineering with modern security practices across Linux infrastructure, endpoint protection, network defense, and cloud-native environments. With experience spanning enterprise security operations, network defense engineering, digital forensics, and full-stack detection platforms, I focus on one mission: delivering resilient, compliant, and attack-ready systems. My work ranges from deploying enterprise EDR solutions and remediating high-severity CVEs, to designing hardened authentication services, to architecting end-to-end SOC and SIEM environments using open-source and enterprise tools. I thrive in technical environments where engineering meets security, and where reliability, automation, and compliance matter. Key Strengths Infrastructure & System Hardening: Automated patching, security baselines, and compliance across 60+ Linux servers using Ansible, achieving full patch compliance and zero-downtime operations. Endpoint & Threat Defense: Managed SentinelOne EDR deployment, investigating threats and collaborating with security teams to strengthen detection posture. Secure Architecture & Authentication: Developed containerized LDAPS solutions and private Harbor registries with Trivy scanning, Cosign signing, and RBAC-based access control. Network Security & Offensive Analysis: Conducted real-world attack simulations, configured NGFWs/IPS, deployed honeypots, and executed passive/active penetration testing across multi-site architectures. Threat Detection & Digital Forensics: Experience with Wazuh, TheHive, Cortex, MISP, Autopsy, Volatility, LimaCharlie rules, and custom YARA signatures for targeted detection. Engineering & Automation: Built unified security platforms integrating SIEM, SOAR, threat intelligence, patch automation, monitoring (CheckMK), and containerized services over Proxmox VE. Proficient across Linux, security automation, network defense, TLS fingerprinting, secure virtualization, and incident response methodologies. I bring a builder mindset, an attacker’s curiosity, and a defender’s discipline. Always engineering. Always improving. Always securing.

Country

Tunisia

City

Grand Tunis Metropolitan Area

Industry

Computer & Network Security

Skill

Security Patch Management, Splunk Enterprise Security, Linux Automation, Identity and Access Management (IAM), Security Engineering, Cyber Threat Intelligence (CTI), Governance, Risk Management, and Compliance (GRC), Cisco ASA, Elastic Stack (ELK), Wireshark, Linux System Administration, Infrastructure Automation, Authentication Systems, Ansible, Network Infrastructure Design, Penetration Testing, Cyber Defense Frameworks, Digital Forensics, Application-based vulnerabilities, Network-based vulnerabilities

Experience

SAGEMCOM

System Security Engineer

SAGEMCOM

LinkedIn
2024-11 - Present · 1 yr 11 mos

Tunisie

During this professional experience, I had the opportunity to manage infrastructure and security tasks, utilizing automation and monitoring tools to ensure system reliability while contributing to critical projects in IT systems: 1. Automated security updates across a large-scale Linux infrastructure using Ansible. Deployed custom roles for multiple distributions, enabling zero-downtime patching, centralized reporting, and daily email alerts, achieving 100% of the defined patch compliance across 90+ Production-Level Linux Servers. 2. Led critical CVE remediation operation by identifying vulnerable Linux systems across multiple sites, coordinating patching plans, and ensuring timely kernel updates to reduce exposure to threats. 3. Deployed and managed Sentinel EDR agents to secure critical endpoints. Collaborated with security teams to detect, analyze, and remediate threats, improving infrastructure resilience. 4. Ensured compliance with ISO 2700x standards by implementing and regularly updating organizational security policies. 4. Developed and containerized a secure Light LDAPS solution, modernizing legacy authentication across multiple client applications and significantly improving reliability and security. 5. Architected and deployed a secure local Harbor Registry integrated with Cosign (for container image signing) and Trivy (for vulnerability scanning). Enabled automated image scanning, signature validation, and policy enforcement for critical production environments. Overcame restricted network limitations through offline image handling, cache optimization, and custom Trivy adapter configurations. 7. Supported system updates, migrations, and certification renewals to meet security standards, incorporating the Data Life Cycle project for critical data archiving, along with backup strategies using HPE Smart Storage Administrator and Commvault.

TAWASOL TECHNOLOGY

Junior Cyber Security & Networking Consultant

TAWASOL TECHNOLOGY

LinkedIn
2023-6 - 2023-9 · 4 mos

Tunis, Tunisia

During this professional experience, I adeptly provide expert supervision and guidance to non-technical staff, while also educating them on security risk recognition. My proficiency extends to respond to various tenders, and accurate cost estimations for IT projects and delivering insightful technical reports on test findings, enhancing strategic decision-making.

TAWASOL TECHNOLOGY

Network Security Intern

TAWASOL TECHNOLOGY

LinkedIn
2023-2 - 2023-7 · 6 mos

Tunis, Tunisia

During this professional experience, I had the opportunity to work on a project titled "Study, Design and Deployment of a Secure Network for a University Campus". The main purpose of this project was to enhance the reliability of an already-existing networking infrastructure while ensuring optimal security, and that is done by: 1. Redesigning the Networking Architecture: We began by conducting a comprehensive assessment of the existing network architecture of the existing network architecture to identify areas in need of improvement. This allowed us to redesign a more optimized network. 2. Establishing a Primary Security Layer: Next, we applied basic security configurations to create an initial defense line for our network. This included implementing basic security policies, access control lists, and port security to prevent unauthorized access. 3. Assessment against Real-world Attack Scenarios: During the assesment phase, we conducted various types of attacks on our networking infrastructure - Router Exploitation - SSH Bruteforcing - Router Configuration Tampering -Post-Exploit - Machine Exploitation EternalBlue MS17-010 - WannaCry Ransomware Deployment -Post-Exploit - DoS & Distributed DoS Attacks - Man in The Middle Attacks - ARP Cache Poisoning By simulating real-world attacks, we were able to identify potential vulnerabilities and weaknesses in the security architecture. 4. Deploying Advanced Mitigation Measures: Based on the results of the attack phase, we applied several advanced security features to address the identified vulnerabilities. This included implementing NG-IPS, Setting up a FortiGate as a Firewall, and deploying a honey pot to lure attackers away from critical systems. Overall, this project provided me with a comprehensive understanding of network security. It involved designing a large-sized network architecture, identifying potential vulnerabilities, and developing effective solutions to mitigate possible risks.

Venari Security

Cyber Security Intern

Venari Security

LinkedIn
2022-10 - 2022-12 · 3 mos

Tunis, Tunisia

During this internship, I had the opportunity to conduct a comprehensive analysis of data collected from TLS handshake logs. This analysis allowed me to identify key trends and patterns that informed the development of a new client identification function. We've conducted the enhancement of the client identification process based solely on the fields in the “Client Hello” message during a TLS handshake, by creating a custom function that works with Levenshtein algorithm distances and takes as input unique TLSv1.3 fields ; 1. Studying key differences between TLSv1.2 and TLSv1.3 to determine new available methods to identify a client without decryption. 2. Preparing a Pre-Processing unit that applies different filtering operations on several pcap files to output an ideal data set of TLS sessions in a CSV File. 3. Developing a JA3 Fingerprinting Calculator from scratch using Python in Jupyter. 4. Implementing the SSdeep and Levenshtein to identifty clients based on JA3 fields and comparing the results with Heatmaps. 5. Creating a Custom Function that will work with Levenshtein and take as input specific TLSv1.3 fields that will identify clients in an even more reliable way. Overall, this internship provided me with valuable experience in data analysis and software development. I am confident that the skills I gained will be useful in my future career endeavors.

 Resys-Consultants

Penetration Tester Intern

Resys-Consultants

2022-6 - 2022-6 · 1 mo

Tunis, Tunisia

During this internship, I had the opportunity to acquire a diverse range of skills and knowledge in various areas of the industry. My primary focus was on web application vulnerabilities and exploitation, as well as basic pentesting, brute forcing, service, and Linux enumeration. In addition to these technical skills, I gained expertise in the OWASP TOP 10 standard awareness document by putting the framework into action. I used the SonarQube SAST engine to perform continuous inspection of code quality, which helped me to understand the importance of maintaining high-quality code. Furthermore, I was able to refine my communication and training abilities by delivering a programming training session with python and reporting vulnerabilities and bugs. These experiences helped me to develop a keen eye for detail and a strong sense of responsibility. I also developed a Python Automated Nmap Scanner Tool from scratch, which was a challenging yet rewarding experience. This project allowed me to apply my technical skills in a practical setting and gave me a sense of accomplishment. Overall, my internship provided me with a solid foundation in the field of cybersecurity, and I am eager to continue developing my skills in this area. I am excited to bring my knowledge and experience to a dynamic and innovative organization in the industry, where I can contribute to the growth and success of the company.

Amaris Consulting

Student Initiation Internship

Amaris Consulting

LinkedIn
2021-7 - 2021-7 · 1 mo

Tunis, Tunisie

During my initiation internship, I had the opportunity to develop my technical skills through my personal website development, while also gaining insight into the professional life in different departments of the host company. The internship introduced me to the Agile Methodology and allowed me to apply theoretical knowledge in real-life tasks. Through this experience, I developed a deeper understanding of the importance of collaboration and teamwork in achieving project goals, and I honed my ability to work efficiently in a fast-paced and dynamic environment. Overall, the internship provided me with valuable practical experience and helped me to further develop my skills and competencies in the field of web development.

Education

TEK-UP University of Digital Sciences

TEK-UP University of Digital Sciences

LinkedIn

Security of Computer Systems and Networks

2023-9 - 2026-11 · 3 yrs 3 mos

Relevant Courses: Cloud Security Operations ; AWS Security Architecture ; Cloud & Virtualization ; DevOps ; Network Security ; Secure Network Architecture ; Intrusion Detection & Alert Management ; Advanced Persistent Threats ; Penetration Testing ; Risk Management ; Security Auditing (ISO/IEC 27001) ; Secure App Development ; Secure Web Development ; OWASP ; System Administration ; Linux Automation (Ansible) ; CyberOps ; Database Security ; VPNs ; Threat Analysis ; Business Continuity Planning(BCP) ; Data Security ; Python for Cybersecurity ; Malware Analysis ; Reverse Engineering (ASM) ; Cryptography ; IoT Security ; Mobile Security (2G–5G) ; Blockchain Dev ; Version Control (DVCS) ; Biometrics ; Quantum Cryptography ; Post-Quantum Cryptography Fundamental Courses: Information Systems Modeling ; Assembly ; Computer Architecture ; Graph Theory ; Automata ; Database Design ; Operating Systems Logical Digital Systems ; Project Management ; Algorithms ; C / Java / Python Programming

Institut Supérieur des Etudes Technologiques en Communications de Tunis

Institut Supérieur des Etudes Technologiques en Communications de Tunis

LinkedIn

Network Security

2020-10 - 2023-7 · 2 yrs 10 mos

Relevant Courses: Algorithms & Data Structures ; C Programming ; Computer & Network Architecture ; Java OOP ; Database Design & Manipulation ; Telecommunication Systems ; Linux Administration ; Routing&Switching ; Network Security ; VHDL ; Software Design ; Security Assessment ; Protection Techniques in Networks ; Cloud Computing ; Artificial Intelligence ; Internet of Things ; Wireless Networks ; Mobile Development ; Systems & Network Administration ; Security Auditing ; Systems and Services Security ; Wireless Networks Security ; Mobile Security ; IP Switching With MPLS ; VPN ; Data Science ; 2G,3G,4G and 5G Mobile Systems Fundamental Courses: Probability and statistics ; Electromagnetism ; Introduction to Signals & Systems ; Signal Processing ; Electromagnetic Wave Propagation ; Geometric Optics ; Analog electronics & components ; Digital Electronics ; Antennas & Microwave Devices ; Optical Transmissions ; Transmission Electronics ; Programmable circuits ; Optical Access Networks

Yassine SAHLI's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.