A practice in offensive security, governance, and the slow work of clarity.
Every discipline begins as a question.
Mine was simple. What is a system worth, the moment before it fails?
I'm Johann. I live in the space between the rule and the risk.
Johann Lahoud is an Offensive Security Lead in financial services, running a 70+ engagement annual testing programme across BNP Paribas Asset Management and AXA Investment Managers.
A practitioner first. Years spent inside governance, pentest oversight, purple teaming, DORA delivery and executive reporting. The work moves between the boardroom and the engagement scope, translating regulatory weight into controls that hold up.
CyberWithJohann is the creator side. A brand built to give the next generation of cybersecurity professionals a real way in, without the hype and the gatekeeping the industry is known for.
The portrait. The practitioner. The same person who reads RFCs at night and presents to the CSO at dawn.
Security is not a feature.
It is the architecture beneath the architecture.
Six disciplines, one continuous practice. From the scope of a single engagement to the architecture of a regulatory programme — the work is the same: turn uncertainty into something measurable.
End-to-end stewardship of offensive programmes: engagement scoping, vendor coordination, remediation pressure, risk acceptance.
Orchestrating 70+ engagements a year across 12 testers, internal stakeholders and external providers.
Closing the loop between offense and defense through measurable, repeatable exercises and crisis simulations.
Leading DORA work-streams across departments, translating regulatory requirements into concrete control, governance and resilience actions.
From technical control assessments to remediation tracking, built on a Python automation stack that turns raw outputs into structured management reporting.
Authoring and presenting cybersecurity strategy to the CSO. Risk, maturity, and the initiatives a board can act on.
Four chapters. One throughline. Each role added a layer — governance, automation, programme leadership, the brand — to the same question I started with.
Certifications are a signal, not a substitute. The work comes first; the paper follows.
There is a generation waiting for a door.
I am building it slowly, on nights and weekends.
Built quietly, alongside a full-time offensive security role. The thesis is simple: the industry is hungry for clarity. The work is to deliver it with restraint.
CyberWithJohann is a creator brand built to demystify cybersecurity for the next generation: aspiring engineers, career switchers, and the curious. No hype, no gatekeeping, no recycled threat-intel.
A 100-page Career Guide. An 8-path Career Quiz. A growing community across TikTok and Instagram. The standards held to product design, not influencer content.
It bridges the boardroom and the bedroom developer. Built quietly, on nights and weekends, alongside a full-time offensive security role at one of Europe's largest asset managers.
A long game. The kind that compounds.
Tools, research, products. Some shipped. Some closed. All taught me something I still use.
A command-line tool to capture a fast, reproducible security posture snapshot of any web target. Faster than a scanner, deeper than a glance.
An 8-path diagnostic quiz that helps aspiring cybersecurity professionals find the role that actually matches their wiring.
100 pages. Five paths. The honest map I wished existed when I was starting out.
Research conducted at EPITA on the effectiveness of vulnerability detection methods used by Slither against Ethereum smart contracts.
Python-based data parsing and reporting automation for an investment management firm. Turning raw control assessments into structured dashboards.
A Unix shell built from scratch. Following the footsteps of Ken Thompson, Steve Bourne and David Korn, one syscall at a time.
The story is still being written.
If our paths cross, let's make it count.
Open to collaborations, speaking, and meaningful conversations.
Currently at BNP Paribas. Not available for freelance.