
Jean-Marie Bourbon
Offensive Security Expert / founder
Salary / Daily rate
Troisvierges, Luxembourg
Freelance
Can come onsite
Skills
Languages
About me
Intro
Cybersecurity leader with extensive offensive security expertise. OSCP/OSCE certified professional with proven experience in Red Team operations, penetration testing, and vulnerability research (multiple CVE publications). Offering comprehensive offensive/defensive security scenarios, strategic thinking and expert team leadership to strengthen your organization's security posture through practical attack simulations and bringing an innovative attacker's mindset to your IT security projects.
Work experience
Founder
Bourbon Offensive Security ServicesFreelance
May 2025 - Present
1 year 2 months
Luxembourg
Bourbon Jean-Marie is an independent cybersecurity expert specializing in offensive and defensive security. Through his company Bourbon OffSec Services, he helps businesses, SMEs and government agencies, strengthen their security posture against modern threats. • Offensive Security • Defensive Security • Consulting & Training With internationally recognized technical expertise, he takes a pragmatic and strategic approach, combining hands-on experience with real-world adaptability. His hybrid business model (both physical and online), along with a cloud-based testing lab in Luxembourg, enables him to operate on an international scale.
Head of CyberForce Offensive Security (COS)
POST Luxembourg
Sep 2020 - Present
5 years 10 months
Luxembourg, Luxembourg
Offensive Security team leader activities at POST Luxembourg. Main activities of the OffSec service are: Penetration Testing in various context, Adversary Simulations, Red-Team engagements (TIBER-LU/EU), Purple-Team exercise, R&D and Vulnerability Research in closed product. Team lead key roles: perimeter scoping out and associated sizing (presales), kick-off meetings, document writing, closure meetings, follow-up (project mgmt) execution plan and custom scenarios definition alligned with customers core activities. Team management and sales activities within an international context inluding plannings and resources management, budgets, marketing/communication plan, strategy definition, service offers definition, business development, recruitment...
Senior Pentester/Red Teamer (LU team leader)
Hacknowledge
May 2019 - Oct 2020
1 year 6 months
Luxembourg
- As a Team leader, my role is: * Project management: perimeter scoping out, kickoff, proposal writing, closure meeting * Team management in international context (English speaking) * Sales offers creation and presales * Recruitment - As an experimented penetration tester and red team operator: * Plan, drive, execute Red/Purple Team operations * Implement and execute adversary tactics, techniques and procedures (TTPs) * Perform pentests in mixed and complex environments (internal/external scopes, thick client, Citrix, web app...) in worldwide sized companies, around different countries, implementing defensive tools requiring bypass techs. knowledge * Add value in post-exploitation phases * Conduct manual vulnerability assessment and exploitation in critical applications with some publication such like CVE-2019-14252, CVE-2019-14253, CVE-2019-14254 (same exploit chain), CVE-2019-14251 etc ... (full CVE id list available in the "publications" part) * Physical penetration testing (dumpster diving, lock-picking, illegitimate offices access through physical security weaknesses, custom USB sticks/LAN turtle usage to gain internal subnet access,...) * Offensive Security speaker and trainer
Senior Penetration Tester / RedTeamer
Excellium Services
Jul 2017 - May 2019
1 year 11 months
Luxembourg
* Penetration tests (internal network, thick client, remote access, web...) in worldwide sized companies with high security level most often without classical workstations (VDI), using defensive tools (that require bypass mechanisms knowledge) and frequently evaluated infrastructure * High skills in post-exploitation steps including latest lateral movements techniques, pivoting, persistence tricks, domain takeover, data exfiltration,... * Vulnerability assessment and exploitation with some publication such like CVE-2019-6970, CVE-2018-6758, CVE 2018-20237, ... (full CVE id list available in the "publications" part) * Physical penetration testing (dumpster diving, lock-picking, illegitimate offices access through physical security weaknesses, custom USB sticks/LAN turtle usage to gain internal subnet access,...) * Red Team engagements elaboration and execution (physical security, S.E, phishing,...) the most creative that mix all offensive security techniques with one goal: identify the weaknesses no matter the technique used to a better protection for customers * Offensive security trainer * Project management: perimeter scoping out, kickoff, (in some case proposal writing), closure meeting
Senior Penetration Tester / RedTeamer
Akerva
Jan 2016 - Jul 2017
1 year 7 months
Paris Area, France
Penetration testings in complex and varied environments (Citrix, SCADA, iSeries, AIX, Brocade ...) Red team / Purple team pentests Vulnerabilities research, assessment & exploitations Post-exploitation Physical pentests Research of bypassing technics Exploits writing Forensics Offensive team leader / Pre-sales
Penetration Tester
Advens
Nov 2015 - Jan 2016
3 months
Paris Area, France
Internal/external penetration testings Application penetration testing Configuration and code audits Network protocols security audits Forensics
Offensive Security Consultant
armature technologies
Oct 2014 - Dec 2015
1 year 3 months
Région de Paris, France
Penetrations testings Advanced malware analysis Research and development Vulnerability research, assessment and exploitation Incident response Forensic analysis Exploit development Sandbox escapes Security and vulnerabilities exploitations trainings
Security Consultant
ESEC Sogeti
Feb 2014 - Oct 2014
9 months
Région de Toulouse , France
S.O.C teams formation trainings Penetration testings
Consultant / developper
ITS GROUP S.A.
Jan 2013 - Mar 2014
1 year 3 months
Région de Toulouse, France
Perl developer on monitoring project (nagios - nagvis) Perl developer on security project (vulnerabilities research)
Perl developer/ consultant
infomil
Feb 2012 - Jan 2013
1 year
Région de Toulouse , France
System administration (Windows 2008R2 and CentOS RHEL6 systems) : Kerberos/LDAP overs SSH authentication Powershell development in migration project (Windows 2008 R2) VBS development (security fix)
Challenger (private CTF) and speaker
NDH
Jun 2010 - Jul 2012
2 years 2 months
Région de Paris, France
CTF participations (2010, 2011, 2014) "Crawling into ISP" conference (2011)
Perl development and network/system administrator
CAF de l'Aude
Sep 2011 - Mar 2012
7 months
Carcassonne, france
Technology watch Perl development in a park administration project Servers monitoring
Network Security Consultant
ASKIP
Jul 2011 - Oct 2011
4 months
Région de Nîmes , France
VNC over VPN (OpenVpn) authentication installation Firewall, NAS, Active Directory (Windows 2003) installation and configuration Security audit
Network administrator / pentester
CCI de Nimes
Nov 2010 - Jul 2011
9 months
Nîmes et périphérie
-Pentests ( network, applications and systems) -development (POWERSHELL) : VHD migration tool -Secure wireless acces point with IpFire proxy (Linux) and full network configuration
Education
Offensive Security
OSCE
2018 - 2018
1 month
Offensive Security
OSCP
2017 - 2017
2 months
EC-Council University
CEH - Certified Ethical Hacker - v8
2013 - 2013
1 month
IPS formation
Bachelor's degree
2010 - 2011
1 year 1 month
Licenses & certifications
Offensive Security Certified Expert (OSCE)
Issued: Jun 2018
Offensive Security Certified Professional (OSCP)
Issued: Jan 2017
Portfolio
