Security Engineer · Freelance & research

Jude Demornay.

Freelance application & AI/LLM security, penetration testing, secure code review, and securing AI-driven systems, backed by banking-grade experience.

Role
Freelance Security Engineer - AppSec & AI/LLM Security
Focus
Penetration testing · Secure code review · AI/LLM security · Threat modeling
Languages
English (native) · French (native) · Spanish (intermediate) · Chinese (basic)
Based in
Brittany, France · Available remotely
Availability
Evenings (from 5pm) & weekends
Status
Available for freelance
01

About

I'm a security engineer specializing in application security and the security of AI/LLM-driven systems. I've spent three years embedded in the security team at a major French bank, running penetration tests across web, mobile, and infrastructure, reviewing code for critical vulnerabilities, and delivering security training , plus an international stint pentesting a product startup in Reykjavík.

Alongside consulting, I research how AI and large language models can be applied to security engineering. My most recent project includes a working pipeline that uses locally-hosted language models to cut static-analysis false positives. I take on freelance work outside my day role, evenings and weekends, so I'm best suited to focused, well-scoped engagements. If you need an appsec or LLM-security specialist, I'd be glad to talk.

02

Services

SVC-01

Penetration testing

Web, API, network, and infrastructure testing, surfacing critical and high-severity issues and supporting remediation.

SVC-02

Secure code review & SAST

Manual and tool-assisted review, static-analysis triage, and practical, prioritized remediation guidance.

SVC-03

AI / LLM security

Threat modeling and testing for LLM-backed and AI-driven applications, including on-premise deployments.

SVC-04

Threat modeling & risk analysis

Structured analysis of attack surface across applications, services, and data flows.

SVC-05

Security training

Hands-on sessions on vulnerability management and penetration testing for engineering teams.

// stack & tooling

Offensive
Burp Suite Sqlmap Nmap Hydra Postman MobSF Wireshark Autopsy
Code analysis
SonarQube Joern SAST
Languages
Python Java JavaScript Scala SQL Bash C / C++
AI & infra
Ollama RAG pipelines Docker Git
03

Rates

DAY RATE
€550 / day

Baseline for time-based or ongoing work. Book via Malt →

PER PROJECT
Fixed quote

Most engagements are priced per project after a short scoping call, so you know the full cost up front.

04

Experience

Sep 2023 — Present

Cybersecurity Engineer

Crédit Mutuel Arkéa · Brest

Penetration testing across web, mobile, and infrastructure environments; static code analysis uncovering complex vulnerabilities; vulnerability tracking and remediation; and delivering security training to engineering teams.

Jun — Aug 2024

Cybersecurity Engineer

Leviosa · Reykjavík, Iceland

Comprehensive penetration testing of the Leviosa platform; developed and implemented security policies and guidelines to establish organizational security standards.

// Education & Credentials

2023 — 2026
Engineering Degree, Cybersecurity & Data Science — ENSIBS, Vannes
2025 — 2026
Research Master's, Computer Science — UBS, Vannes
2020 — 2023
Bachelor's, Computer Science — Université de Rennes 1
Certification
Cisco Ethical Hacker — issued by Cisco (verify on Credly)
05

Research

My research focuses on AI and large language model applications to security engineering. For my engineering final-year project I built an autonomous pipeline that reduces static-analysis (SAST) false positives using locally-hosted large language models, benchmarked against classical machine-learning baselines and retrieval-augmented (RAG) approaches across multiple vulnerability categories

My research Master's dissertation is a state-of-the-art review of AI-based approaches to software vulnerability detection — surveying the current landscape and mapping the open problems. The work is currently unpublished; I'm happy to discuss it on request.

06

Selected work

view all work →

07

Contact

Available for freelance engagements in application and AI/LLM security. Send an enquiry below, or reach me directly.