Okan Taşçıoğlu

Penetration Testing Specialist and Secure Backend Developer

Okan Taşçıoğlu
Istanbul, Turkey

Experience

Jan 2024 - Present
2 years 1 month
Istanbul, Turkey

Penetration Testing Specialist and Secure Backend Developer

Freelancer

  • Performed hands-on penetration tests on web apps, APIs, mobile (Android) and network environments; identified and validated real-world security issues like injection flaws, access control problems and privilege escalation paths.

  • Carried out security tests and reverse engineering on Android apps; analyzed app logic, insecure storage and authentication flows.

  • Applied offensive security techniques throughout the attack lifecycle on Linux and Windows, including reconnaissance, exploitation, post-exploitation and lateral movement.

  • Achieved 105th place in the TryHackMe global ranking, demonstrating strong practical experience in offensive security, red teaming concepts and defense awareness.

  • Worked with industry-standard security tools and methodologies to simulate realistic attack scenarios and delivered actionable findings aligned with OWASP standards.

  • Developed secure, production-ready REST APIs using Python (FastAPI) and Java (Spring Boot) with JWT/OAuth2 based authentication and role-based access control.

  • Implemented application security controls in line with OWASP principles, including input validation, authorization, secure data handling and audit logging.

  • Designed and integrated Keycloak for centralized identity and access management; applied encrypted data storage (field-level encryption) where needed.

  • Containerized applications using Docker have CI/CD pipelines to support secure build and deployment workflows.

  • Key projects include a secure note management API and backend services focused on authentication, authorization and API security best practices.

Summary

Hands-on experience in web, Android, API and network penetration testing. TryHackMe global ranking #105. Strong offensive security skills and secure backend development with FastAPI and Spring Boot focused on OWASP Top 10, authentication, authorization and data protection.

Skills

  • Fastapi: Python
  • Spring Boot: Java
  • Jwt/oauth2: Secure Api Design
  • Aws Kms: Encrypted Mongodb
  • Fastapi, Spring Boot, Jwt/oauth2, Keycloak, Aws Kms, Web/mobile/api And Network Penetration Testing, Burp Suite, Metasploit, Nmap, Wireshark, Sqlmap, Owasp Zap, Gobuster, Kernels, Owasp 2025 Compliance, Secure By Design, Devsecops Practices, Linpeas/winpeas, Linux/windows Privilege Escalation

Languages

Turkish
Native
English
Intermediate
Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions

Similar Freelancers

Discover other experts with similar qualifications and experience

Mevlüt Yıldırım
Mevlüt Yıldırım

Project

View Profile
Stefan Radushev
Stefan Radushev

ISO27001 Certification

View Profile
Benedek Galácz
Benedek Galácz

CTO/CISO

View Profile
Alexander Nagy
Alexander Nagy

Security Expert

View Profile
Andrei Closca
Andrei Closca

Java Software Engineer

View Profile
Enis Spahi
Enis Spahi

Software Developer

View Profile
Niels Aerts
Niels Aerts

Azure Architect

View Profile
Syed ghazanfar Abbas
Syed ghazanfar Abbas

Information Security Consultant

View Profile
Shamaila Mahmood
Shamaila Mahmood

Senior Software Architect

View Profile
Rick Grassmann
Rick Grassmann

Interim IT Security Analyst

View Profile
Seyed farhad Miri
Seyed farhad Miri

Senior Product Security Engineer

View Profile
Sokol Çavdarbasha
Sokol Çavdarbasha

Cybersecurity Engineer

View Profile
Hossam Abdelaziz
Hossam Abdelaziz

Freelance Cybersecurity Specialist

View Profile
Arne Hendricks
Arne Hendricks

Embedded Fullstack Developer

View Profile
Bernhard Bowitz
Bernhard Bowitz

Senior Security Architect

View Profile
Maryam Mouzarani
Maryam Mouzarani

AI Red Team Engineer

View Profile
Erald Kerciku
Erald Kerciku

AWS Cloud Solutions Architect

View Profile
Omonefe Oseremen
Omonefe Oseremen

Web Developer Intern

View Profile
Satya Vulise
Satya Vulise

Lead Developer

View Profile
Antoine Liblin
Antoine Liblin

Middleware, GCP Cloud and DevOps Engineer

View Profile
Ilker Baltaci
Ilker Baltaci

Freelance Mobile Developer

View Profile
Adrian Ion
Adrian Ion

Strategic Technology Leadership & Digital/AI Transformation

View Profile
Mohit Dabas
Mohit Dabas

Senior Security Technologist

View Profile
Sascha Leitner
Sascha Leitner

CEO

View Profile
Abdelmajid Dakhli
Abdelmajid Dakhli

Leader, Architect and Senior Developer

View Profile
Zeeshan Adil
Zeeshan Adil

Sanad Chat-Based Application for Search & Rescue Ops

View Profile
Muhammad Daniyal
Muhammad Daniyal

Senior Penetration Tester

View Profile
Timon Ringwald
Timon Ringwald

Database Developer – Research Project – Healthcare Billing

View Profile
Rashida Alexander
Rashida Alexander

Security Research Engineer

View Profile
Steven Mohr
Steven Mohr

Freelance Trainer

View Profile