loading...

Resume

About Information
About Information

Hello! I’m Kendal Yaman, an Ethical Hacker, GRC Consultant, and Incident Handler from Geneva. I have extensive experience in identifying vulnerabilities, implementing governance, risk, and compliance strategies, and handling cybersecurity incidents.

  • Age: 32
  • Address: Geneva, Switzerland
  • E-mail: kendal.yaman[at]gmail.com
Experience
2026 - Present
Cybersecurity Consultant (OCSIN - Genève) - Keyteo

Drive end-to-end vulnerability management by overseeing Bug Bounty programs and coordinating penetration tests and audits with rigorous remediation tracking. Strengthen incident readiness through Tier 2/3 SOC operations, SIEM dashboard optimization, and the design of Tabletop exercises and specialized training to enhance team response capabilities.

2023 - 2026
Cybersecurity GRC Consultant and Pentester - ZENDATA

Provide comprehensive Governance, Risk, and Compliance (GRC) consulting by assessing organizational security policies and frameworks, while performing penetration testing to identify vulnerabilities, ensure regulatory compliance, and deliver strategic recommendations to enhance overall cybersecurity posture.

2022
Incident Handler - Court de Justice de l’Union Européenne

Managed and responded to cybersecurity incidents by investigating breaches, analyzing threats, and implementing containment, eradication, and recovery measures, while coordinating with stakeholders to minimize impact and prevent future incidents.

2020 - 2022
Ethical Hacker- itrust consulting

Conducted penetration testing and vulnerability assessments to identify security weaknesses in systems, networks, and applications, providing actionable recommendations to strengthen defenses and prevent potential cyberattacks, while ensuring compliance with industry standards and best practices.

Education
2026
Pre-Security (SEC0) - TryHackMe

Demonstrated foundational knowledge and practical skills in network security, web application security, and operating system fundamentals. Validated the essential technical prerequisites required for advanced security analysis and offensive security operations.

2024
Lead Auditor in Information Security Management Systems - Exemplar Global

Expertise in conducting first, second, and third-party audits of Information Security Management Systems (ISMS). Proficient in leading audit teams, assessing risk controls, and ensuring organizational compliance with ISO/IEC 27001:2022 standards.

2024
INE Certified Cloud Associate - INE Security

Proficient in deploying and managing cloud solutions to optimize performance, enhance security, and support scalable infrastructure within cloud environments.

2024
Certified Data Privacy Manager - AMPCUS cyber

Skilled in implementing data privacy frameworks to ensure compliance, mitigate privacy risks, and strengthen organizational data protection practices.

2024
Certified NIST CSF v2.0 Specialist - AMPCUS cyber

Developed expertise in implementing and managing the NIST Cybersecurity Framework to enhance organizational cybersecurity posture and risk management strategies.

2024
Certified in Cybersecurity - ISC2

Gained foundational knowledge and skills in cybersecurity principles, including risk management, security controls, and incident response.

2024
eJPTv2 - INE Security

Acquired expertise in penetration testing and vulnerability assessment, focusing on identifying and mitigating security risks in systems and networks.

2018-2020
M.Sc. in Information and Computer Sciences - Information Security - Université du Luxembourg

Earned an M.Sc. in Information and Computer Sciences with a specialization in Information Security, gaining in-depth knowledge of cybersecurity principles, cryptography, network security, and risk management, and applying advanced techniques to protect information systems and data from evolving threats.

Services

Penetration test

Conduct thorough penetration tests to identify and exploit vulnerabilities in systems and applications.

GRC Consulting

Assist organizations in establishing and maintaining governance frameworks and ensuring compliance with relevant regulations.

Incident Handling

Respond to and manage cybersecurity incidents, conducting root cause analysis and implementing remediation strategies.

Threat Intelligence

Analyze threat data to identify emerging risks and vulnerabilities, providing actionable insights for proactive security measures.

Security Audit

Perform security audits to assess compliance with industry standards and best practices, and provide recommendations for improvement.

Security Solutions

Design and implement security solutions tailored to the specific needs of an organization, ensuring robust protection of assets.

Skills

  • Networs and Systems Hardening
    80%
  • Cloud Security
    80%
  • Offensive Security
    75%
  • Cybersecurity Incident Management
    70%
  • Risk Management
    70%
  • Forensic
    70%
  • Threat Intelligence
    60%

Languages Skills

  • French
    100%
  • English
    85%
  • German
    30%
  • Italian
    30%

Interests

Football

I enjoy playing regularly and staying active, which not only enhances my teamwork skills but also keeps me disciplined and focused.

Chess

I enjoy the mental challenge of anticipating opponents' moves and devising winning strategies, which sharpens my critical thinking and problem-solving skills.

Formula 1

I closely follow races and analyze team strategies, which fuels my passion for high-performance engineering and competitive dynamics.