Anas Hamidi

Anas Hamidi

Application Security · Penetration Tester · Cybersecurity Specialist

Penetration Tester and Application Security specialist with 2+ years of hands-on offensive-security experience. Specialized in web and API penetration testing, with experience in mobile app security, business-logic vulnerabilities, and security automation. I integrate LLM-assisted workflows to speed up recon, payload generation, and code analysis. Enrolled in the M.Sc. Information Systems programme at the University of Würzburg — open to internships and permanent roles in IT security.

Key Achievements

  • $$,$$$ bounty for a critical vulnerability at Canva
  • #1 in the Hall of Fame of two private HackerOne programs (50+ researchers each)
  • #9 in Canva’s Hall of Fame (200+ researchers)
  • Consistent five-figure (USD) bug-bounty payouts through sustained research
  • 50+ verified reports across HackerOne and Bugcrowd
  • Recognized reports at Canva, Pexels, Lichess, Glance CX, Inshur, and ClassDojo

Experience

Independent Security Researcher / Penetration Tester HackerOne & Bugcrowd · Feb 2023 – Present · Remote

  • Real-world web and API penetration testing from an attacker’s perspective for international platforms
  • Found and responsibly reported 50+ vulnerabilities: IDOR, XSS, SSRF, SQLi, authentication and business-logic flaws
  • Uncovered a critical vulnerability at Canva, rewarded with a $$,$$$ bounty
  • Web Application Firewall (WAF) analysis and filter-bypass techniques
  • Professional technical reports with reproduction steps, CVSS scoring, and remediation guidance
  • Built custom Python and Bash tooling to automate recon, vulnerability triage, and data analysis
  • Used LLM-assisted workflows (ChatGPT, Claude) for recon automation, payload generation, and source-code analysis
  • Early hands-on mobile pentesting (Android, OWASP)
  • Advised development teams on identified issues and secure-coding recommendations

Training & Certifications

  • PNPT and HTB CPTS — currently preparing through self-study
  • TryHackMe — hands-on training in web security and penetration testing

Community & Mentoring

  • Mentor — Rushd Cybersecurity Cohort — deliver live offensive-security sessions (web exploitation, network penetration testing, and a hands-on CTF) to students at Aleppo and Homs universities; the first cohort drew 600+ students and 1,000+ live attendees.
  • Member — HAK-MZ — a security research collective working across web application, AI, and infrastructure security, focused on reproducible findings and honest severity.

Volunteering

Technical Lead — ICPC, Aleppo University (Jan–Feb 2023) — led technical teams organizing an international programming contest.