Jean-Marie Bourbon

Offensive Security Expert / founder

Salary / Daily rate

Troisvierges, Luxembourg

Freelance

Can come onsite

Skills

CybersecurityCConsulting CybersecurityHTMLPythonGitJenkinsZAPBurp SuiteLinuxSnortStrategy & Consulting

Languages

English (Native)French (Native)Italian (Native)Luxembourgish

About me

Intro

Cybersecurity leader with extensive offensive security expertise. OSCP/OSCE certified professional with proven experience in Red Team operations, penetration testing, and vulnerability research (multiple CVE publications). Offering comprehensive offensive/defensive security scenarios, strategic thinking and expert team leadership to strengthen your organization's security posture through practical attack simulations and bringing an innovative attacker's mindset to your IT security projects.

Links

Work experience

Founder

Bourbon Offensive Security ServicesFreelance

May 2025 - Present

1 year 2 months

Luxembourg

Bourbon Jean-Marie is an independent cybersecurity expert specializing in offensive and defensive security. Through his company Bourbon OffSec Services, he helps businesses, SMEs and government agencies, strengthen their security posture against modern threats. • Offensive Security • Defensive Security • Consulting & Training With internationally recognized technical expertise, he takes a pragmatic and strategic approach, combining hands-on experience with real-world adaptability. His hybrid business model (both physical and online), along with a cloud-based testing lab in Luxembourg, enables him to operate on an international scale.

Head of CyberForce Offensive Security (COS)

POST Luxembourg

Sep 2020 - Present

5 years 10 months

Luxembourg, Luxembourg

Offensive Security team leader activities at POST Luxembourg. Main activities of the OffSec service are: Penetration Testing in various context, Adversary Simulations, Red-Team engagements (TIBER-LU/EU), Purple-Team exercise, R&D and Vulnerability Research in closed product. Team lead key roles: perimeter scoping out and associated sizing (presales), kick-off meetings, document writing, closure meetings, follow-up (project mgmt) execution plan and custom scenarios definition alligned with customers core activities. Team management and sales activities within an international context inluding plannings and resources management, budgets, marketing/communication plan, strategy definition, service offers definition, business development, recruitment...

Senior Pentester/Red Teamer (LU team leader)

Hacknowledge

May 2019 - Oct 2020

1 year 6 months

Luxembourg

- As a Team leader, my role is: * Project management: perimeter scoping out, kickoff, proposal writing, closure meeting * Team management in international context (English speaking) * Sales offers creation and presales * Recruitment - As an experimented penetration tester and red team operator: * Plan, drive, execute Red/Purple Team operations * Implement and execute adversary tactics, techniques and procedures (TTPs) * Perform pentests in mixed and complex environments (internal/external scopes, thick client, Citrix, web app...) in worldwide sized companies, around different countries, implementing defensive tools requiring bypass techs. knowledge * Add value in post-exploitation phases * Conduct manual vulnerability assessment and exploitation in critical applications with some publication such like CVE-2019-14252, CVE-2019-14253, CVE-2019-14254 (same exploit chain), CVE-2019-14251 etc ... (full CVE id list available in the "publications" part) * Physical penetration testing (dumpster diving, lock-picking, illegitimate offices access through physical security weaknesses, custom USB sticks/LAN turtle usage to gain internal subnet access,...) * Offensive Security speaker and trainer

Senior Penetration Tester / RedTeamer

Excellium Services

Jul 2017 - May 2019

1 year 11 months

Luxembourg

* Penetration tests (internal network, thick client, remote access, web...) in worldwide sized companies with high security level most often without classical workstations (VDI), using defensive tools (that require bypass mechanisms knowledge) and frequently evaluated infrastructure * High skills in post-exploitation steps including latest lateral movements techniques, pivoting, persistence tricks, domain takeover, data exfiltration,... * Vulnerability assessment and exploitation with some publication such like CVE-2019-6970, CVE-2018-6758, CVE 2018-20237, ... (full CVE id list available in the "publications" part) * Physical penetration testing (dumpster diving, lock-picking, illegitimate offices access through physical security weaknesses, custom USB sticks/LAN turtle usage to gain internal subnet access,...) * Red Team engagements elaboration and execution (physical security, S.E, phishing,...) the most creative that mix all offensive security techniques with one goal: identify the weaknesses no matter the technique used to a better protection for customers * Offensive security trainer * Project management: perimeter scoping out, kickoff, (in some case proposal writing), closure meeting

Senior Penetration Tester / RedTeamer

Akerva

Jan 2016 - Jul 2017

1 year 7 months

Paris Area, France

Penetration testings in complex and varied environments (Citrix, SCADA, iSeries, AIX, Brocade ...) Red team / Purple team pentests Vulnerabilities research, assessment & exploitations Post-exploitation Physical pentests Research of bypassing technics Exploits writing Forensics Offensive team leader / Pre-sales

Penetration Tester

Advens

Nov 2015 - Jan 2016

3 months

Paris Area, France

Internal/external penetration testings Application penetration testing Configuration and code audits Network protocols security audits Forensics

Offensive Security Consultant

armature technologies

Oct 2014 - Dec 2015

1 year 3 months

Région de Paris, France

Penetrations testings Advanced malware analysis Research and development Vulnerability research, assessment and exploitation Incident response Forensic analysis Exploit development Sandbox escapes Security and vulnerabilities exploitations trainings

Security Consultant

ESEC Sogeti

Feb 2014 - Oct 2014

9 months

Région de Toulouse , France

S.O.C teams formation trainings Penetration testings

Consultant / developper

ITS GROUP S.A.

Jan 2013 - Mar 2014

1 year 3 months

Région de Toulouse, France

Perl developer on monitoring project (nagios - nagvis) Perl developer on security project (vulnerabilities research)

Perl developer/ consultant

infomil

Feb 2012 - Jan 2013

1 year

Région de Toulouse , France

System administration (Windows 2008R2 and CentOS RHEL6 systems) : Kerberos/LDAP overs SSH authentication Powershell development in migration project (Windows 2008 R2) VBS development (security fix)

Challenger (private CTF) and speaker

NDH

Jun 2010 - Jul 2012

2 years 2 months

Région de Paris, France

CTF participations (2010, 2011, 2014) "Crawling into ISP" conference (2011)

Perl development and network/system administrator

CAF de l'Aude

Sep 2011 - Mar 2012

7 months

Carcassonne, france

Technology watch Perl development in a park administration project Servers monitoring

Network Security Consultant

ASKIP

Jul 2011 - Oct 2011

4 months

Région de Nîmes , France

VNC over VPN (OpenVpn) authentication installation Firewall, NAS, Active Directory (Windows 2003) installation and configuration Security audit

Network administrator / pentester

CCI de Nimes

Nov 2010 - Jul 2011

9 months

Nîmes et périphérie

-Pentests ( network, applications and systems) -development (POWERSHELL) : VHD migration tool -Secure wireless acces point with IpFire proxy (Linux) and full network configuration


Education

Offensive Security

OSCE

2018 - 2018

1 month

Offensive Security

OSCP

2017 - 2017

2 months

EC-Council University

CEH - Certified Ethical Hacker - v8

2013 - 2013

1 month

IPS formation

Bachelor's degree

2010 - 2011

1 year 1 month


Licenses & certifications

Offensive Security Certified Expert (OSCE)

Issued: Jun 2018

Certified by OffSec

Offensive Security Certified Professional (OSCP)

Issued: Jan 2017

Certified by OffSec

Portfolio

Security audit & pentesting exercises

Professional network built for talents

© 2026. All Rights Reserved.