a
amjad_cybersec

Amjad K

@amjad_cybersec

Offensive Security Expert

Pakistan
Englisch, Urdu
Einige Informationen werden in englischer Sprache angezeigt.
Über mich
Offensive Security Professional with 5+ years of experience in penetration testing and application security across web, mobile, API, thick-client, network, cloud, and Active Directory environments. OSCP+ and CRTP certified, experienced in SDLC security, threat modeling, secure code review, SAST/DAST/SCA, CI/CD security gates, MDM, and kiosk hardening. Skilled across reconnaissance, exploitation, privilege escalation, and post-exploitation. Recognized for responsible disclosures by LinkedIn, OKX, Bitget, Nextcloud, and UNESCO.... Mehr lesen

Kompetenzen

a
amjad_cybersec
Amjad K
offline • 
Durchschnittliche Antwortzeit: 1 Stunde

Meine Dienstleistungen

Programmierung & Technik
I will perform web and API penetration testing and vulnerability assessment

Arbeitserfahrung

Narcotics_Control Division

Offensive Security Expert

Narcotics Control Division • Vollzeit

Feb 2026 - Present • 8 mos

• Conducted security assessments and penetration tests for web applications, mobile applications, APIs, internal/external networks, cloud infrastructure, and enterprise environments. • Performed application security testing, identifying vulnerabilities such as authentication and authorization flaws, OWASP Top 10 issues, business logic vulnerabilities, insecure configurations, and API security weaknesses. • Conducted internal and external network penetration testing, focusing on network protocols, exposed services, configurations, privilege escalation, and Active Directory access control weaknesses. • Performed source code reviews to identify security vulnerabilities, insecure coding practices, and application logic flaws, and provided remediation recommendations to development teams. • Integrated security practices into the SDLC and DevSecOps processes, supporting secure development, vulnerability management, and remediation workflows. • Conducted cloud security assessments and configuration reviews, identifying misconfigurations and security weaknesses across cloud-based infrastructure and storage services (AWS/Azure). • Performed system and application configuration security reviews against CIS Benchmarks and industry security best practices. • Developed and executed authorized, controlled DDoS resilience and stress-testing simulations within approved assessment environments. • Identified critical and high-risk vulnerabilities and provided detailed technical findings, proof-of-concept evidence, risk ratings, and remediation recommendations. • Conducted post-remediation penetration testing to verify security patches, validate vulnerability fixes, and ensure identified security issues were properly resolved. • Performed access control and privilege reviews to identify excessive permissions, insecure access rights, and potential privilege escalation risks. • Supported security and compliance requirements aligned with ISO 27001, PCI-DSS, SAMA, and other applicable ind

VaporVM

Penetration Tester

VaporVM • Vollzeit

Aug 2022 - Dec 2024 • 2 yrs 4 mos

• Conducted security assessments and penetration tests for web applications, mobile applications, APIs, internal/external networks, cloud infrastructure, and enterprise environments. • Performed application security testing, identifying vulnerabilities such as authentication and authorization flaws, OWASP Top 10 issues, business logic vulnerabilities, insecure configurations, and API security weaknesses. • Conducted internal and external network penetration testing, focusing on network protocols, exposed services, configurations, privilege escalation, and Active Directory access control weaknesses. • Performed source code reviews to identify security vulnerabilities, insecure coding practices, and application logic flaws, and provided remediation recommendations to development teams. • Integrated security practices into the SDLC and DevSecOps processes, supporting secure development, vulnerability management, and remediation workflows. • Conducted cloud security assessments and configuration reviews, identifying misconfigurations and security weaknesses across cloud-based infrastructure and storage services (AWS/Azure). • Performed system and application configuration security reviews against CIS Benchmarks and industry security best practices. • Developed and executed authorized, controlled DDoS resilience and stress-testing simulations within approved assessment environments. • Identified critical and high-risk vulnerabilities and provided detailed technical findings, proof-of-concept evidence, risk ratings, and remediation recommendations. • Conducted post-remediation penetration testing to verify security patches, validate vulnerability fixes, and ensure identified security issues were properly resolved. • Performed access control and privilege reviews to identify excessive permissions, insecure access rights, and potential privilege escalation risks. • Supported security and compliance requirements aligned with ISO 27001, PCI-DSS, SAMA, and other applicable ind

KloudEdge_Technologies

CyberSecurity Analyst

KloudEdge Technologies • Vollzeit

Jul 2021 - Jul 2022 • 1 yr

• Conducted security assessments of web and mobile applications, identifying vulnerabilities like SQL injection, XSS, and CSRF. • Collaborated with development teams to provide remediation guidance for identified security issues. • Performed penetration tests on internal and external networks, focusing on network protocols and configurations. • Researched and stayed current with cybersecurity trends and exploit methodologies to enhance testing strategies. • Developed detailed documentation and reports for security assessments, communicating findings to stakeholders.