Default Avatar
Candidate Name
Red Team Member
Türkiye
Summary

Hello, my name is Mustafa Bilgici. I am an Application Security Engineer from Turkey.

I have worked with several cybersecurity companies, including TÜV Austria Sybercode and similar organizations. I have experience working in professional security teams and enterprise environments.

I was also accepted to present my own secure source code analysis tool at world-famous cybersecurity conferences such as DEF CON and Black Hat. These are some of the most important cybersecurity conferences in the world, and I had the opportunity to present my research and tool there. Also I have OSWE certificate from OffSec.
I worked at SansTech, where I was part of the security team for critical betting system infrastructures . SansTech has one of the largest betting system infrastructures in Turkey, including platforms like iddaa, misli.com, and milli piyango.
During my time there, I reported hundreds of security vulnerabilities and worked closely with developers to fix and close these issues. I was responsible for the full DevSecOps process and helped design and build the security architecture.

I am also a member of the Synack Red Team, which is a private global security research platform now . It includes security researchers from more than 20 countries across 6 continents and provides web, mobile, API, and infrastructure penetration testing. On this platform, I am ranked in the top 30 security researchers worldwide.
I have strong experience in application security,Web Application Penetration Testing, source code review, vulnerability management, and DevSecOps. I enjoy working with development teams and improving secure systems.

Work experience
01/07/2024
05/01/2026
Red Team Member
01/04/2023
01/03/2025
Co-Founder
01/04/2023
01/03/2025
Senior Application Security Engineer
Education & certifications
01/09/2022
01/07/2025
Bachelor’s Degree
Management Information Systems, General
01/01/2018
01/01/2023
Bachelor’s Degree
Electrical and Electronics Engineering
Open to relocate
Skills
Cybersecurity Penetration Testing Ethical Hacking Cloud Security Application Security Threat Modeling Python Scripting DevSecOps Mobile Security Red Team Exercises Security Testing Vulnerability Management Bash Secure SDLC Red Team Engagement Support API Security Testing Django Flask Docker Jenkins GitLab AWS Vulnerability Assessment Security Auditing Burp Suite Nmap Security Research Security Consulting Web Security Practices Infrastructure as Code (IaC) Security Code Review Practices

You need to log in as an employer to view full candidate details.