Incoming Apprenti Ingénieur Cybersécurité @ Société Générale (Oct. 2026) | MSc MBA @ Epitech Paris
Ancien Alternant Data & Automation @ SNCF Voyageurs | L3 Computer Science @ Université Gustave Eiffel
🌐 Portfolio : vincent-p-essy.github.io
- 🔐 Interested in backend, systems and cybersecurity
- 🐧 Linux user
Projets en C, Java et Python autour des systèmes, des jeux et de la sécurité applicative.
| Project | Technical focus |
|---|---|
| BackPack Hero | Java, turn-based combat, inventory and equipment |
| Minecraft Clone | TypeScript, WebGL, voxel generation and block interaction |
| CyberPass | Next.js frontend and FastAPI backend for security evidence |
| Memory allocator | C, manual memory management and linked blocks |
| Kernel Sentinel | Go, eBPF and event replay for security detection |
📄 I built an automated DORA compliance engine in Python — here's what I learned about regulatory engineering
How I automated 200–400h of manual audit work using OPA/Rego policies, evidence vaults with immutability triggers, and CI/CD gates — with a deliberate 75/100 score to prove the detection actually works.
Plutôt que des dépôts isolés, mon GitHub héberge un écosystème complet de détection, corrélation et traitement des incidents, conçu selon les principes de la Clean Architecture et du TDD.
[ pcap-analyzer ] (C Parser)
│
▼ (JSON Flux)
[ threat-correlation-engine ] (YAML Rules) ◄─── [ vuln-digest ] (Threat Intel)
│
▼ (Trigger)
[ incident-tracker-api ] (Flask REST RBAC) ◄─── [ llm-triage ] (AI Guardrails)
│
▼
[ cyber-dashboard ] (MTTD / MTTR Real-time metrics)
[ dora-compliance-engine ] ──────────────────────► CI/CD Gate (DORA / ISO 27001)
- pcap-analyzer : Analyseur réseau écrit en C pur. Détecteurs : Port scan, ARP spoofing, DNS tunneling. Output JSON.
- threat-correlation-engine : Pipeline Loader → Correlator → Dispatcher sur fenêtres glissantes et règles YAML.
- vuln-digest : Threat Intel quotidien NVD + CISA KEV + GitHub Advisories, scoring CVSS v3 bancaire, rapport HTML.
- security-audit-logger : Clean Architecture .NET 8, TDD xUnit, CI/CD Trivy, Docker non-root.
- incident-tracker-api : API REST Flask/PostgreSQL, JWT, RBAC 3 rôles, 97% test coverage.
- llm-triage : Triage LLM sous contraintes DORA/PCI-DSS, prompts Jinja2 structurés.
- dora-compliance-engine : Conformité DORA/ISO 27001 automatisée. OPA/Rego, evidence vault immuable, gate CI/CD, drift scoring. 97 tests, 96% coverage. Article Medium →
- ci-security-gate : GitHub Action centralisée — entropie Shannon, pip-audit, Dockerfile lint.
- cyber-dashboard : Console MTTD/MTTR temps réel, mode démo standalone.
- SNCF Voyageurs (Transilien) : Scénar'Express — application d'aide à la décision temps réel au COT. Power BI, automatisation.
- Apex 3D : Co-fondateur e-commerce, site de catalogue HTML/CSS/JS avec réponses prédéfinies dans le chat.
- Cyber : Google Cybersecurity Professional, Fortinet FCF, Splunk SOC Essentials, Cisco Cyber.
- Langages : C, .NET 8 (C#), Python (Flask), Bash, SQL (PostgreSQL), Java, JavaScript.
- Ops : Docker, GitHub Actions CI/CD, Linux (Debian), Wireshark.
I enjoy working close to the system (C, Linux) and building backend/data applications (Python, SQL).
Feel free to contact me for any opportunity.




