Tel Aviv, Israel

Michael Azoulay

Application Penetration Tester

Specializing in Web, API, Mobile, and Thick Client application security assessments.

Professional Summary

Michael is a penetration tester specializing in application security across Web, API, Mobile, and Thick Client environments. His work includes scoping, threat modeling, hands-on exploitation, proof-of-concept development, remediation guidance, and professional reporting.

His background combines client-facing application assessments with incident response, cyber threat intelligence, Python-based tooling, and security automation. He is currently advancing Red Team and Active Directory offensive capabilities.

Experience

Application Penetration Tester

MADSEC Security LTD - Tel Aviv

Performs application security assessments across Web, API, Mobile, and Thick Client environments, with ownership of the testing lifecycle from scoping through exploitation, proof-of-concept development, and reporting.

Identifies complex vulnerabilities beyond OWASP Top 10, including business logic flaws and authorization weaknesses, and collaborates directly with developers, DevOps, and product teams on remediation guidance.

Application Penetration Tester and Security Consultant

Freelance

Provides application security consulting. Among my clients: Plonter and R2M Group.

Scope can include application security review, site feature consultation, and practical remediation guidance where public disclosure is approved.

Cyber Security Analyst and Incident Response

N.E.S.S - Clalit Healthcare - Israel

Performed proactive threat analysis and incident response for cybersecurity events, helping protect healthcare data and infrastructure while investigating malware activity, network abnormalities, and breach attempts.

Developed custom tools and dashboards to improve detection accuracy and streamline investigations. Enriched cyber threat intelligence using sources including CERT-IL and NGOs, converting raw indicators into actionable recommendations for engineering and SecOps teams.

Security Operations Center Analyst

Citadel Cyber Security - Rehovot

Conducted threat analysis in a 24/7 environment, responded to alerts from multiple security systems, and documented security incidents in English and Hebrew.

Worked hands-on with EDR, SIEM, SOAR, firewall, cloud security, IDS, proxy, NAC, mail relay, sandboxing, ticketing, and Active Directory tooling across MSSP customer environments.

Computer Technician and Security Consultant

Plonter Technologies LTD - Tel Aviv District

Provided computer setup, system installation, hardware troubleshooting, and specification assembly for clients, alongside scripting for automated system testing and security consultation for site features.

Computer Technician

Plonter Technologies LTD - Tel Aviv District

Supported computer setup, system installation, hardware installation, BIOS and system troubleshooting, and on-demand client workstation specifications.

Spokesperson Photographer

Magen David Adom in Israel - Tel Aviv District

Produced photography, videography, and editing for MDA operations and media.

Selected Projects

File Upload Testing

UploadBuster

Upload restriction testing utility for application security assessments.

View repository

TLS Analysis Tool

TlsCipherAuditor

TLS cipher and protocol review for transport security audits.

View repository

Web Utility

xPathgrabber

XPath-oriented extraction of visible text elements from websites.

View repository

Technical Profiles

Focus Areas

Application Security

  • Web Application Security
  • API Security
  • Mobile Application Security
  • Thick Client Security
  • Authentication and Authorization Testing
  • Business Logic Testing

Assessment Delivery

  • Scoping and Threat Modeling
  • Hands-on Exploitation
  • Proof-of-Concept Development
  • Vulnerability Validation
  • Remediation Guidance
  • Clear Technical Reporting

Supporting Capabilities

  • PortSwigger Burp Suite
  • Python Tooling and Automation
  • Incident Response
  • Cyber Threat Intelligence
  • Security Research
  • Offensive Lab Development

Training

Certified Red Team Professional (CRTP)

Altered Security

Current

Malware Analysis and Triage

TCM Security

2024

Mobile Application Penetration Testing

TCM Security

2023

CEH - Ethical Hacking

HackerU

2019 - 2020

Education

Cyber and Information Security

HackerU

Feb 2019 - Aug 2020

Covered networking foundations, Windows Active Directory, Linux and Bash, Python, application and infrastructure penetration testing, mobile penetration testing, and reverse engineering. Led activity on the HackerU CTF platform while completing the program.

Advanced Computer Installation and Repair Technology

Ness Digital Engineering

2013

Certified Advanced Computer Technician.

Contact

For application security assessments, consulting, or professional opportunities, use the contact details below.