
Amjad K
Offensive Security Expert
Habilidades

Revisa mis servicios

Experiencia laboral
Offensive Security Expert
Narcotics Control Division • Tiempo completo
Feb 2026 - Present • 8 mos
• Conducted security assessments and penetration tests for web applications, mobile applications, APIs, internal/external networks, cloud infrastructure, and enterprise environments. • Performed application security testing, identifying vulnerabilities such as authentication and authorization flaws, OWASP Top 10 issues, business logic vulnerabilities, insecure configurations, and API security weaknesses. • Conducted internal and external network penetration testing, focusing on network protocols, exposed services, configurations, privilege escalation, and Active Directory access control weaknesses. • Performed source code reviews to identify security vulnerabilities, insecure coding practices, and application logic flaws, and provided remediation recommendations to development teams. • Integrated security practices into the SDLC and DevSecOps processes, supporting secure development, vulnerability management, and remediation workflows. • Conducted cloud security assessments and configuration reviews, identifying misconfigurations and security weaknesses across cloud-based infrastructure and storage services (AWS/Azure). • Performed system and application configuration security reviews against CIS Benchmarks and industry security best practices. • Developed and executed authorized, controlled DDoS resilience and stress-testing simulations within approved assessment environments. • Identified critical and high-risk vulnerabilities and provided detailed technical findings, proof-of-concept evidence, risk ratings, and remediation recommendations. • Conducted post-remediation penetration testing to verify security patches, validate vulnerability fixes, and ensure identified security issues were properly resolved. • Performed access control and privilege reviews to identify excessive permissions, insecure access rights, and potential privilege escalation risks. • Supported security and compliance requirements aligned with ISO 27001, PCI-DSS, SAMA, and other applicable ind
Penetration Tester
VaporVM • Tiempo completo
Aug 2022 - Dec 2024 • 2 yrs 4 mos
• Conducted security assessments and penetration tests for web applications, mobile applications, APIs, internal/external networks, cloud infrastructure, and enterprise environments. • Performed application security testing, identifying vulnerabilities such as authentication and authorization flaws, OWASP Top 10 issues, business logic vulnerabilities, insecure configurations, and API security weaknesses. • Conducted internal and external network penetration testing, focusing on network protocols, exposed services, configurations, privilege escalation, and Active Directory access control weaknesses. • Performed source code reviews to identify security vulnerabilities, insecure coding practices, and application logic flaws, and provided remediation recommendations to development teams. • Integrated security practices into the SDLC and DevSecOps processes, supporting secure development, vulnerability management, and remediation workflows. • Conducted cloud security assessments and configuration reviews, identifying misconfigurations and security weaknesses across cloud-based infrastructure and storage services (AWS/Azure). • Performed system and application configuration security reviews against CIS Benchmarks and industry security best practices. • Developed and executed authorized, controlled DDoS resilience and stress-testing simulations within approved assessment environments. • Identified critical and high-risk vulnerabilities and provided detailed technical findings, proof-of-concept evidence, risk ratings, and remediation recommendations. • Conducted post-remediation penetration testing to verify security patches, validate vulnerability fixes, and ensure identified security issues were properly resolved. • Performed access control and privilege reviews to identify excessive permissions, insecure access rights, and potential privilege escalation risks. • Supported security and compliance requirements aligned with ISO 27001, PCI-DSS, SAMA, and other applicable ind
CyberSecurity Analyst
KloudEdge Technologies • Tiempo completo
Jul 2021 - Jul 2022 • 1 yr
• Conducted security assessments of web and mobile applications, identifying vulnerabilities like SQL injection, XSS, and CSRF. • Collaborated with development teams to provide remediation guidance for identified security issues. • Performed penetration tests on internal and external networks, focusing on network protocols and configurations. • Researched and stayed current with cybersecurity trends and exploit methodologies to enhance testing strategies. • Developed detailed documentation and reports for security assessments, communicating findings to stakeholders.