Security Engineering / Offensive Security / Dubai

Validate the attack path. Strengthen the system.

I am a Penetration Tester, Red Team Operator (CRTO), and Security Engineer focused on practical attack-path validation across web applications, APIs, Active Directory, internal networks, and cloud environments. My career started in vulnerability research and bug bounty hunting and evolved into enterprise VAPT, adversary simulation, and remediation-focused security engineering.

5+ years offensive securityCRTOHTB Top 10 · #6Yahoo Hall of FameAWS Summit Dubai 2026 · Team #3UAE NESA / ISR
01

Professional Overview security engineering profile

My work sits at the intersection of offensive security, engineering, and risk reduction: discover realistic attack paths, validate exploitability, communicate business impact, and support practical remediation.

I have worked across enterprise web applications, Active Directory environments, internal networks, cloud platforms, private bug-bounty programmes, and adversary-simulation exercises. In current and recent roles, I have translated technical findings into actionable remediation for engineering and infrastructure teams.

5+ yrsOffensive security
#6HTB All-Time Rank
CRTOCertified Operator
2017Research Journey
02

Evidence of Hands-On Depth

Competitive Security#6

Hack The Box — Global Rank #6

Reached Top 10 (#6) in Hack The Box's All-Time Hall of Fame among 100K+ hackers worldwide during the 2018–2019 period.

AWS Hackathon#3

AWS Summit Dubai 2026 — Agentic AI Hackathon

Our team achieved 3rd rank at the AWS Summit Dubai 2026 Agentic AI Hackathon, held at Dubai World Trade Centre.

Red TeamingCR

Certified Red Team Operator

CRTO credential from Zero-Point Security, complementing practical work in Active Directory, adversary simulation, lateral movement, and evasion.

Responsible DisclosureY!

Yahoo Security Recognition

Recognized in Yahoo's Hall of Fame following responsible disclosure of Stored XSS, Reflected XSS, and logic vulnerabilities.

Enterprise TestingSR

Synack Red Team Member

Freelance Red Team Member from March 2021 to March 2023, performing black-box penetration testing and adversary emulation on enterprise targets.

Web3 ResearchBF

BitForex Vulnerability Disclosure

Identified and responsibly disclosed a critical BitForex Exchange vulnerability through HackenProof with proof-of-concept details.

Research & CommunityOS

Researcher + Lecturer

Publishes practical security write-ups and has delivered web-application-security teaching with hands-on labs and OWASP-focused material.

03

Security Engineering Expertise

Offensive Security

Red Team OperationsAdversary SimulationVAPTWeb SecurityAPI SecurityBusiness LogicPrivilege EscalationLateral Movement

Identity & Internal Security

Active DirectoryAttack PathsPost-ExploitationInternal NetworkWindowsLinux

Cloud & Infrastructure

AzureAWSAzure Landing ZonesOffice 365Endpoint Protection

Tools & Frameworks

Burp Suite ProCobalt StrikeBloodHoundMetasploitNmapNessusQualysWiresharkMITRE ATT&CK

Security Standards

UAE IA (NESA)ISRNIST 800-53ISO 27001PCI DSSOWASP Top 10

Scripting & Delivery

PythonBashPowerShellJavaScriptPoC DevelopmentTechnical ReportingRemediation Guidance
04

Professional Experience

IT Security Engineer (Hybrid Contract)
Aug 2025 – Present
Middle East Technology L.L.C — Dubai, UAE

Conduct internal network and web-application VAPT; execute adversary simulations and Active Directory assessments; identify lateral-movement and privilege-escalation paths; and translate findings into actionable remediation aligned with UAE IA (NESA/ISR).

Guest Cyber Security Lecturer
Mar 2025 – Jul 2025
Cranfield University — Remote

Designed and delivered web-application-security curriculum focused on OWASP Top 10 and secure coding, supported by hands-on labs that simulated practical VAPT scenarios.

Security Consultant — Offensive Security
Mar 2023 – Feb 2025
Self-Employed — Bangladesh

Performed advanced offensive-security work across private bug-bounty programmes and enterprise web applications, including business-logic testing, high-severity vulnerability research, reporting, and red-team simulations.

Red Team Member
Mar 2021 – Mar 2023
Synack — Remote

Executed black-box penetration testing and adversary emulation against global enterprise targets, with proof-of-concept reporting and remediation guidance for engineering teams.

Bug Bounty Hunter / Vulnerability Researcher
Apr 2017 – Apr 2018
HackerOne & HackenProof — Global

Started with independent vulnerability research, including Yahoo findings that led to Hall of Fame recognition and a critical BitForex Exchange disclosure through HackenProof.

05

Credentials & Continuous Learning

Certified Red Team Operator (CRTO)Zero-Point Security
HTB Red Team Operator L3 — CyberneticsHack The Box
ProLab Offshore — Penetration Tester Level IIHack The Box
Google Cybersecurity Professional CertificateGoogle
Certified Ethical Hacker SpecializationPearson
CompTIA PenTest+ PathwayTryHackMe
PentesterLab BadgesRecon · Serialize · Essential · PCAP · Unix · White · Introduction
TryHackMe RecognitionTop 1% ranking recorded in 2022
06

Research, Writing & Security Community

My research background is rooted in hands-on exploitation. I document practical techniques and lessons from security testing, with published work covering Yahoo XSS, Python Pickle Deserialization, CouchDB exploitation, and Windows/Linux privilege escalation.

Professional contact

Building security that stands up to real attack paths.

For security-engineering roles, offensive-security engagements, red-team collaboration, technical security projects, or cybersecurity education, connect through the channels below.