Anas Hamidi
Application Security · Penetration Tester · Cybersecurity Specialist
Penetration Tester and Application Security specialist with 2+ years of hands-on offensive-security experience. Specialized in web and API penetration testing, with experience in mobile app security, business-logic vulnerabilities, and security automation. I integrate LLM-assisted workflows to speed up recon, payload generation, and code analysis. Enrolled in the M.Sc. Information Systems programme at the University of Würzburg — open to internships and permanent roles in IT security.
Key Achievements
- $$,$$$ bounty for a critical vulnerability at Canva
- #1 in the Hall of Fame of two private HackerOne programs (50+ researchers each)
- #9 in Canva’s Hall of Fame (200+ researchers)
- Consistent five-figure (USD) bug-bounty payouts through sustained research
- 50+ verified reports across HackerOne and Bugcrowd
- Recognized reports at Canva, Pexels, Lichess, Glance CX, Inshur, and ClassDojo
Experience
Independent Security Researcher / Penetration Tester HackerOne & Bugcrowd · Feb 2023 – Present · Remote
- Real-world web and API penetration testing from an attacker’s perspective for international platforms
- Found and responsibly reported 50+ vulnerabilities: IDOR, XSS, SSRF, SQLi, authentication and business-logic flaws
- Uncovered a critical vulnerability at Canva, rewarded with a $$,$$$ bounty
- Web Application Firewall (WAF) analysis and filter-bypass techniques
- Professional technical reports with reproduction steps, CVSS scoring, and remediation guidance
- Built custom Python and Bash tooling to automate recon, vulnerability triage, and data analysis
- Used LLM-assisted workflows (ChatGPT, Claude) for recon automation, payload generation, and source-code analysis
- Early hands-on mobile pentesting (Android, OWASP)
- Advised development teams on identified issues and secure-coding recommendations
Training & Certifications
- PNPT and HTB CPTS — currently preparing through self-study
- TryHackMe — hands-on training in web security and penetration testing
Community & Mentoring
- Mentor — Rushd Cybersecurity Cohort — deliver live offensive-security sessions (web exploitation, network penetration testing, and a hands-on CTF) to students at Aleppo and Homs universities; the first cohort drew 600+ students and 1,000+ live attendees.
- Member — HAK-MZ — a security research collective working across web application, AI, and infrastructure security, focused on reproducible findings and honest severity.
Volunteering
Technical Lead — ICPC, Aleppo University (Jan–Feb 2023) — led technical teams organizing an international programming contest.