n
nizaw1

Ni Zaw

@nizaw1

Web Application Penetration Tester and API Security Specialist

Myanmar [Burma]
Englisch, Russisch
Einige Informationen werden in englischer Sprache angezeigt.
Über mich
Dedicated Cybersecurity Analyst and Web Application Penetration Tester specializing in OWASP Top 10 vulnerabilities, API integrity mapping, and complex business logic flaws. I deeply analyze backend architectures and item quantity validations to uncover structural weaknesses automated scanners miss. I work entirely via secure chat and deliver high-quality, professional Markdown/PDF penetration testing reports with clear remediation guidance. Let's make your web systems robust and secure.... Mehr lesen

Kompetenzen

n
nizaw1
Ni Zaw
offline • 

Meine Dienstleistungen

Fehlerbehebung
I will be your web application penetration tester and security auditor

Arbeitserfahrung

Upwork

Independent Application Security Researcher

Upwork • Freiberufler

Apr 2024 - Present2 yrs 3 mos

Conducted authorized security assessments and logic analysis on enterprise web applications. Specialized in identifying complex Business Logic Flaws, API integrity issues, and item quantity validation flaws. Responsibly disclosed vulnerabilities to help organizations improve their backend structural defense.

Self_Employed

Web Application Penetration Tester and API Security Specialist

Self Employed • Freiberufler

May 2020 - Present6 yrs 2 mos

Performed comprehensive web application penetration testing and vulnerability assessments within diverse target environments. Focused on mapping and exploiting technical vulnerabilities aligned with the OWASP Top 10 framework, including broken access control, injection flaws, IDOR, and severe security misconfigurations. Investigated complex technical parsing behaviors, input-handling routines, and authentication bypasses across Linux host environments and containerized backend applications. Crafted detailed, structured penetration testing documentation outlining exact exploit vectors, architectural impact assessments, and actionable mitigation blueprints. Provided reliable, zero-noise technical insights to client security teams exclusively through high-quality written reports and structured asynchronous communication channels.