Engineer, Offensive Security Research
CurrentAs an Engineer on the Offensive Security Research team, I specialize in identifying and mitigating security vulnerabilities across Android, Web & APIs. In this role, I've,⦿ Conducted penetration testing on 10 mobile and 20+ web applications, identifying critical vulnerabilities in 22% of systems tested, with findings that contributed to enhanced security measures and reduced threat exposure.⦿ Discovered and documented over 100 security vulnerabilities (8 critical, 42 high-severity) across mobile and web applications, actively mitigating risks of data breaches and financial fraud through targeted remediation plans.⦿ Executed penetration testing initiatives aligned with PCI-DSS, ISO 27001, and Bangladesh Bank Cloud Computing Guidelines, contributing to organizational compliance and enhancing overall security posture.⦿ Performed in-depth Web and API penetration testing using Burp Suite Professional, Ffuf, Kiterunner, Nmap, alongside custom scripts and personal methodologies, with a focus on OWASP Top 10 and critical business logic vulnerabilities.⦿ Leveraged Android pentesting tools, including AVD, ADB, Frida, Objection, JADX, Apktool, Burp Suite, and MobSF, to perform comprehensive static and dynamic analysis.⦿ Managed Burp Suite Enterprise for routine, automated scans of internal and external web portals, achieving early detection of vulnerabilities and reducing response times for critical findings.