LUCAS HANSON

Cyber Security Consultant and CTF player.

Experience

Cyber Security Consultant @ Cabinet Thierry MEYER Consultants

September 2025 - Present | Bordeaux, France

  • Conduct white-box, grey-box, and black-box penetration tests on client web applications, APIs, and internal systems.
  • Research new offensive-security techniques and turn useful findings into repeatable testing methods for client engagements.
  • Build internal tools to automate reconnaissance, testing workflows, and vulnerability reproduction, using AI-assisted development where appropriate
  • Review the code and threat models of internal tools before they are used on client engagements.

InfoSec Lab Co-Lead (Volunteer) @ Bordeaux Ynov Campus

September 2024 - Present | Bordeaux, France

  • Co-lead a cybersecurity lab with around 40 student members, manage its day-to-day operations, and organize regular technical activities.
  • Supervise student projects and mentor participants in web and offensive security.
  • Created and delivered a hands-on CSP workshop covering policy construction, browser enforcement, testing, and common bypasses caused by weak configurations.
  • Created and delivered a hands-on SSRF workshop covering internal services, cloud metadata endpoints, blind SSRF, and common filter bypasses.
  • Delivered a bug bounty workshop focused on reconnaissance, application mapping, and systematic vulnerability testing.
  • Created and delivered an introductory web security workshop in which students built, exploited, and fixed vulnerable web application features.
  • Design challenges and organize the lab's annual CTF.

Application Security Engineer @ DGFiP

September 2024 - September 2025 | Bordeaux, France

  • Performed secure code reviews and triaged findings as part of the Code Review team.
  • Conducted penetration tests on large-scale web and mobile applications.
  • Delivered application security training to development teams.
  • Built tailored tools to detect and exploit vulnerabilities within proprietary frameworks.

Cybersecurity Intern @ Knock Knock

June 2024 - July 2024 | Bègles, France

  • Developed Python tools to automate penetration testing workflows.
  • Researched tools and techniques in penetration testing.
  • Conducted web application penetration tests.

Side Projects & Tooling

Education

Integrated master’s degree in Information Security

Bordeaux Ynov Campus | 2022 - 2027

CVEs