
Stephane Belkheraz
Instructor
Stephane Belkheraz is an Application Security and DevSecOps engineer — and before that he spent more than 20 years architecting and leading the development of complex .NET systems. That combination is the point: he secures software the way an architect thinks, not just the way a scanner reports.
Most recently, at the international medical device manufacturer Stago, he secured APIs, web applications and systems, introduced a secure SDLC, ran bug bounty campaigns with YesWeHack and provided ongoing security training to the development teams. Before that he was AppSec and Tech Lead at Groupe TF1 and LINXEA, where he integrated SAST, SCA and DAST tools into Azure DevOps pipelines, ran DAST testing with OWASP ZAP and designed and delivered training on application security and software craftsmanship. Earlier roles include Senior .NET Security Developer at the French Treasury (Direction générale du Trésor), .NET architect at Veepee and Premier Field Engineer at Microsoft France.
His toolbox covers the whole pipeline: OWASP Top 10 for web and APIs, SAST and SCA with Snyk, Sonar, Checkmarx or Mend, DAST with Burp and ZAP, scanners such as Qualys and Nessus, Cloudflare as WAF, identity with Entra ID, Auth0 and OAuth/OpenID Connect, plus Azure DevOps, GitHub Actions and Terraform. On top of that he secures AI and LLM environments: prompt injection, the OWASP LLM Top 10, MCP and agent security and AI red teaming.
Sharing knowledge runs through his whole career: he co-authored the “ASP.NET Core MVC 2.0 Cookbook” (Packt Publishing, 2018), produced the video course “jQuery — Maîtrisez les concepts de base” for Editions ENI and was technical reviewer of “Mastering ServiceStack” (Packt). As a Premier Field Engineer at Microsoft France he delivered workshops and code reviews on customer sites, at Petit Forestier and IP New Generation he was architect and trainer at the same time, and at TF1 and LINXEA he built his own security training programs for development teams. He deepened his security education at ESD Academy, studied software architecture at the Conservatoire National des Arts et Métiers (CNAM), and holds several Microsoft certifications (MCSD App Builder, MCSA Web Applications, MCPD).
At letsboot he runs trainings on DevSecOps and application security — hands-on, grounded in real projects, and aimed at getting security into the pipeline rather than into a report.