s
shahzaibx21

Shahzaib Ahmed

@shahzaibx21

Reverse Engineer

Pakistan
Englisch, Urdu
Einige Informationen werden in englischer Sprache angezeigt.
Über mich
Certified Android Reverse Engineer | Penetration Tester | Mobile App Security Specialist Are you concerned your Android application or backend API may be vulnerable to reverse engineering, repackaging, or exploitation? I help companies proactively identify and eliminate critical security weaknesses — before real attackers find them. With over 5 years of hands-on experience in Android reverse engineering, mobile application penetration testing, and API security assessment, I specialize in uncovering high-impact vulnerabilities through structured, ethical, and technically rigorous testing.... Mehr lesen

Kompetenzen

s
shahzaibx21
Shahzaib Ahmed
offline • 
Durchschnittliche Antwortzeit: 1 Stunde

Meine Dienstleistungen

Programmierung & Technik
I will reverse private API , protobuf , encryptions , automation scraping
Programmierung & Technik
I will perform android app security testing and vulnerability assessment

Portfolio

Arbeitserfahrung

Systems_Limited

Mobile Application Security Consultant

Systems Limited • Vollzeit

Aug 2021 - Present5 yrs 1 mo

Providing authorized security assessments for Android applications and backend APIs, with a focus on identifying confirmed vulnerabilities and delivering practical remediation guidance. Key responsibilities: • Conduct static and dynamic security analysis of authorized Android applications. • Assess REST, GraphQL and mobile-backend APIs for authentication, authorization, access-control, input-validation and sensitive-data risks. • Analyze APK structure, Java and Kotlin components, native ARM or ARM64 libraries and runtime application behavior. • Review network communication, local data storage, cryptographic implementation and application security configurations. • Evaluate protections including obfuscation, root detection, anti-debugging and anti-tampering controls. • Apply OWASP MASVS, OWASP Mobile Top 10 and OWASP API Security Top 10 principles during assessments. • Use Frida, Burp Suite, Ghidra, JADX, MobSF, Postman, ADB and custom scripts within approved testing scopes. • Produce professional reports containing severity ratings, evidence, affected components, business impact and actionable remediation recommendations. All assessments are conducted only on systems owned by the client or explicitly authorized for testing.

ZZ_Group Company CCS

Android Reverse Engineer

ZZ Group Company CCS

Mar 2021 - Feb 20264 yrs 11 mos

Worked as an Android Reverse Engineer specializing in mobile application security testing, reverse engineering, and vulnerability assessment. Conducted in-depth static and dynamic analysis of Android applications to identify security flaws, logic vulnerabilities, and data exposure risks. Key Responsibilities & Achievements: Performed APK reverse engineering using Smali, JADX, Ghidra, and Apktool Conducted dynamic analysis and runtime instrumentation using Frida and Objection Identified and bypassed SSL pinning implementations for security testing purposes Analyzed API endpoints, authentication flows, and token security Executed mobile penetration tests using Burp Suite and MITM proxy tools Discovered critical vulnerabilities including insecure data storage, hardcoded secrets, and improper authentication Delivered detailed security assessment reports with CVSS scoring and remediation guidance Assisted development teams in implementing secure coding practices