CV
Application Security · Penetration Tester · Cybersecurity Specialist
Penetration Tester and Application Security specialist with 3+ years of hands-on offensive-security experience. Specialized in web and API penetration testing, with experience in mobile app security, business-logic vulnerabilities, and security automation. I integrate LLM-assisted workflows to speed up recon, payload generation, and code analysis.
Key Achievements
- $$,$$$ bounty for some vulnerabilities at Canva
- #1 in the Hall of Fame of two private HackerOne programs (50+ researchers each)
- #9 in Canva’s Hall of Fame (200+ researchers)
- Consistent five-figure (USD) bug-bounty payouts through sustained research
- 50+ verified reports across HackerOne and Bugcrowd
- Recognized reports at Canva, Pexels, Lichess, Glance CX, Inshur, and ClassDojo
Experience
Independent Security Researcher / Penetration Tester HackerOne & Bugcrowd · Feb 2023 – Present · Remote
- Real-world web and API penetration testing from an attacker’s perspective for international platforms
- Found and responsibly reported 50+ vulnerabilities: IDOR, XSS, SSRF, SQLi, authentication and business-logic flaws
- Web Application Firewall (WAF) analysis and filter-bypass techniques
- Professional technical reports with reproduction steps, CVSS scoring, and remediation guidance
- Built custom Python and Bash tooling to automate recon, vulnerability triage, and data analysis
- Used LLM-assisted workflows (ChatGPT, Claude) for recon automation, payload generation, and source-code analysis
- Early hands-on mobile pentesting (Android, OWASP)
- Advised development teams on identified issues and secure-coding recommendations
Skills & Tools
- Web & API Security: Burp Suite, OWASP ZAP, Metasploit, Postman
- Vulnerability Scanning: Nessus, Metasploit, Nmap
- Exploitation & Recon: SQLmap, FFUF, Subfinder, Amass, Nuclei
- Mobile Pentesting: Android (Frida basics, APK analysis), OWASP MASVS
- Methodologies: OWASP Top 10, OWASP API Security Top 10, OWASP MASVS, SANS Top 25
- Automation / AI: LLM-assisted recon, payload generation & code analysis; custom scripts
- Scripting: Bash, Python, PHP, JavaScript (basics)
- Operating Systems: Linux (Kali, Ubuntu), Windows
Areas of Focus
IDOR · XSS · SSRF · SQLi · authentication & OTP/2FA bypass · business-logic flaws · sensitive information disclosure · OWASP Top 10 & API Top 10
Education
- M.Sc. Information Systems — Julius-Maximilians-Universität (JMU) Würzburg
- B.Sc. Information Technology Engineering — University of Aleppo (2024)
Community & Mentoring
- Mentor — Rushd Cybersecurity Cohort — deliver live offensive-security sessions (web exploitation, network penetration testing, and a hands-on CTF) to students at Aleppo and Homs universities; the first cohort drew 600+ students and 1,000+ live attendees.
- Member — HAK-MZ — a security research collective working across web application, AI, and infrastructure security, focused on reproducible findings and honest severity.
Volunteering
Technical Lead — ICPC, Aleppo University (Jan–Feb 2023) — led technical teams organizing an international programming contest.
Languages
Arabic (Native) · English (Fluent) · German (B2, telc)