About / Experience & qualifications

Theodoros
Moutesidis.

Penetration tester, security engineer, and researcher. Based in Thessaloniki, working with teams on application security and the tools that support it.

A tester with an engineering background.

I break web applications and AI systems for a living, then build tools that make the work more effective. My focus is manual testing: understanding application behavior, following the evidence, and finding the authentication, authorization, and business-logic flaws that automated checks can miss.

As an independent consultant, I work through the full assessment lifecycle: defining scope, testing, validating findings, reporting, and discussing remediation. Alongside client work, I develop security tooling and conduct independent research.

My experience includes enterprise application portfolios, private vulnerability research programs, and security work involving government and European projects. I keep employer names, client identities, and private assessment details out of this public portfolio.

Having worked in development and infrastructure before specializing in security, I can discuss both the finding and the engineering decisions around fixing it.

Professional background

The work behind the title.

Selected work ↗
Consulting

Independent penetration testing

Full-cycle assessments for business clients, from scoping and manual testing through technical reports and findings presentations.

Responsibilities
  • Web application and API security assessments
  • Evidence validation, remediation guidance, and retesting
  • Direct communication with technical teams and stakeholders
Application security

Enterprise penetration testing

Ongoing assessment of enterprise application portfolios, with a focus on authentication, authorization, business logic, and how weaknesses interact.

Responsibilities
  • Manual testing and secure code review
  • SAST/SCA findings triage and validation
  • Working with engineers to investigate and remediate vulnerabilities
Vulnerability research

Private enterprise programs

Research in vetted, private vulnerability programs, investigating high-impact issues in enterprise applications.

Responsibilities
  • Independent analysis of complex application behavior
  • Findings documentation and responsible reporting
  • Manual investigation beyond scanner output
Security engineering

DevSecOps

Integrating security checks into delivery pipelines and making their output easier for engineering teams to use.

Responsibilities
  • CI/CD security controls and vulnerability tracking
  • Container and Kubernetes environments
  • Centralized logging, monitoring, and infrastructure automation
Engineering foundation

Development & Linux administration

Earlier work in software development, Linux systems, and DevOps established the practical foundation for my security work.

Responsibilities
  • Application development and operational troubleshooting
  • Service configuration, hardening, and deployment
  • Understanding systems from code through production operation
Practical qualifications

Certifications.

Penetration testing

OSCP+

OffSec Certified Professional+

Advanced web security

OSWE

OffSec Web Expert

Web application security

CWES

Certified Web Exploitation Specialist

Red team analysis

CRTA

Certified Red Team Analyst

Academic background

Education.

MSc Cyber Security

Postgraduate study in cybersecurity.

BSc Applied Informatics

University of Macedonia.

Hands-on experience

Across the stack.

Assessment & review

Burp Suite, manual web and API testing, Fortify, SAST/SCA triage, network and Active Directory security.

Development & automation

Python, Bash, JavaScript, report processing, custom assessment utilities, and LLM-assisted security tooling.

Infrastructure & delivery

Linux, Docker, Kubernetes, Helm, Jenkins, Terraform, Ansible, CI/CD security, logging, and monitoring.

Let’s talk about your security.

Tell me what you’re building and what you need assessed.

Discuss your project