g
g33k7r

Sohaib

@g33k7r

Information Security Expert, VAPT, CISM, IS Auditor, Incident Response

Pakistán
Inglés
Parte de la información aparece en idioma inglés.
Sobre mí
I am an Information Security Architect and Cybersecurity Professional with 8+ years of experience in penetration testing, vulnerability assessment, security architecture, SOC operations, threat intelligence, and digital forensics. I help businesses identify security weaknesses and protect their applications, APIs, networks, and infrastructure. I provide practical security assessments, detailed vulnerability reports, risk analysis, and clear remediation guidance focused on improving your overall security posture.... Lee más

Habilidades

g
g33k7r
Sohaib
desconectado • 
Tiempo medio de respuesta: 1 hora

Revisa mis servicios

Programación y tecnología
I will perform penetration testing and security assessment
Programación y tecnología
I will conduct a full scope red team operation and adversary simulation

Porfolio

Experiencia laboral

Confidentials

Cyber Security Architect

Confidentials

Apr 2018 - Present8 yrs 5 mos

Professional Experience Information Security Architect | May 2018 – Present * Design and assess enterprise information security architecture, controls, and security processes. * Conduct VAPT for web applications, APIs, networks, and infrastructure. * Perform manual and automated security testing covering authentication, authorization, session management, APIs, input validation, business logic, access control, and security configuration. * Identify and validate vulnerabilities using controlled PoC techniques while minimizing false positives. * Prepare professional security reports with technical evidence, severity, business impact, OWASP/CWE mapping, and remediation guidance. * Design and improve SOC workflows for security monitoring, incident detection, investigation, and response. * Work with SIEM and security technologies including IBM QRadar, Wazuh, Splunk, firewalls, and endpoint security solutions. * Apply MITRE ATT&CK and Cyber Kill Chain methodologies for threat analysis and incident investigation. * Conduct security architecture reviews and threat modeling using STRIDE, PASTA, NIST CSF, and ISO 27001. * Develop risk-based vulnerability scoring and prioritization approaches. Selected Projects Web Application & API Penetration Testing: * Assessed modern web applications and APIs for authentication weaknesses, authorization flaws, business-logic vulnerabilities, injection risks, API security issues, rate-limit weaknesses, and payment-flow vulnerabilities. * Delivered detailed penetration-testing reports with reproducible PoCs and actionable remediation. Automated Vulnerability Assessment Platform: * Designed an agentless security assessment platform covering reconnaissance, crawling, endpoint discovery, parameter analysis, vulnerability testing, validation, and automated reporting. Developed multiple testing strategies aligned with OWASP, SANS, penetration testing, vulnerability assessment, SSL/TLS, CMS, and deep-scan requirements.