CV

Application Security · Penetration Tester · Cybersecurity Specialist

Penetration Tester and Application Security specialist with 3+ years of hands-on offensive-security experience. Specialized in web and API penetration testing, with experience in mobile app security, business-logic vulnerabilities, and security automation. I integrate LLM-assisted workflows to speed up recon, payload generation, and code analysis.

Key Achievements

  • $$,$$$ bounty for some vulnerabilities at Canva
  • #1 in the Hall of Fame of two private HackerOne programs (50+ researchers each)
  • #9 in Canva’s Hall of Fame (200+ researchers)
  • Consistent five-figure (USD) bug-bounty payouts through sustained research
  • 50+ verified reports across HackerOne and Bugcrowd
  • Recognized reports at Canva, Pexels, Lichess, Glance CX, Inshur, and ClassDojo

Experience

Independent Security Researcher / Penetration Tester HackerOne & Bugcrowd · Feb 2023 – Present · Remote

  • Real-world web and API penetration testing from an attacker’s perspective for international platforms
  • Found and responsibly reported 50+ vulnerabilities: IDOR, XSS, SSRF, SQLi, authentication and business-logic flaws
  • Web Application Firewall (WAF) analysis and filter-bypass techniques
  • Professional technical reports with reproduction steps, CVSS scoring, and remediation guidance
  • Built custom Python and Bash tooling to automate recon, vulnerability triage, and data analysis
  • Used LLM-assisted workflows (ChatGPT, Claude) for recon automation, payload generation, and source-code analysis
  • Early hands-on mobile pentesting (Android, OWASP)
  • Advised development teams on identified issues and secure-coding recommendations

Skills & Tools

  • Web & API Security: Burp Suite, OWASP ZAP, Metasploit, Postman
  • Vulnerability Scanning: Nessus, Metasploit, Nmap
  • Exploitation & Recon: SQLmap, FFUF, Subfinder, Amass, Nuclei
  • Mobile Pentesting: Android (Frida basics, APK analysis), OWASP MASVS
  • Methodologies: OWASP Top 10, OWASP API Security Top 10, OWASP MASVS, SANS Top 25
  • Automation / AI: LLM-assisted recon, payload generation & code analysis; custom scripts
  • Scripting: Bash, Python, PHP, JavaScript (basics)
  • Operating Systems: Linux (Kali, Ubuntu), Windows

Areas of Focus

IDOR · XSS · SSRF · SQLi · authentication & OTP/2FA bypass · business-logic flaws · sensitive information disclosure · OWASP Top 10 & API Top 10

Education

  • M.Sc. Information Systems — Julius-Maximilians-Universität (JMU) Würzburg
  • B.Sc. Information Technology Engineering — University of Aleppo (2024)

Community & Mentoring

  • Mentor — Rushd Cybersecurity Cohort — deliver live offensive-security sessions (web exploitation, network penetration testing, and a hands-on CTF) to students at Aleppo and Homs universities; the first cohort drew 600+ students and 1,000+ live attendees.
  • Member — HAK-MZ — a security research collective working across web application, AI, and infrastructure security, focused on reproducible findings and honest severity.

Volunteering

Technical Lead — ICPC, Aleppo University (Jan–Feb 2023) — led technical teams organizing an international programming contest.

Languages

Arabic (Native) · English (Fluent) · German (B2, telc)

Contact

LinkedIn · HackerOne · Telegram · [email protected]