a
amjad_cybersec

Amjad K

@amjad_cybersec

Offensive Security Expert

Paquistão
Inglês, Urdu
Algumas informações são exibidas no idioma inglês.
Sobre mim
Offensive Security Professional with 5+ years of experience in penetration testing and application security across web, mobile, API, thick-client, network, cloud, and Active Directory environments. OSCP+ and CRTP certified, experienced in SDLC security, threat modeling, secure code review, SAST/DAST/SCA, CI/CD security gates, MDM, and kiosk hardening. Skilled across reconnaissance, exploitation, privilege escalation, and post-exploitation. Recognized for responsible disclosures by LinkedIn, OKX, Bitget, Nextcloud, and UNESCO.... Saiba mais

Habilidades

a
amjad_cybersec
Amjad K
offline • 
Tempo médio de resposta: 1 hora

Conheça meus serviços

Programação e Tecnologia
I will perform web and API penetration testing and vulnerability assessment

Experiência profissional

Narcotics_Control Division

Offensive Security Expert

Narcotics Control Division • Período integral

Feb 2026 - Present • 8 mos

• Conducted security assessments and penetration tests for web applications, mobile applications, APIs, internal/external networks, cloud infrastructure, and enterprise environments. • Performed application security testing, identifying vulnerabilities such as authentication and authorization flaws, OWASP Top 10 issues, business logic vulnerabilities, insecure configurations, and API security weaknesses. • Conducted internal and external network penetration testing, focusing on network protocols, exposed services, configurations, privilege escalation, and Active Directory access control weaknesses. • Performed source code reviews to identify security vulnerabilities, insecure coding practices, and application logic flaws, and provided remediation recommendations to development teams. • Integrated security practices into the SDLC and DevSecOps processes, supporting secure development, vulnerability management, and remediation workflows. • Conducted cloud security assessments and configuration reviews, identifying misconfigurations and security weaknesses across cloud-based infrastructure and storage services (AWS/Azure). • Performed system and application configuration security reviews against CIS Benchmarks and industry security best practices. • Developed and executed authorized, controlled DDoS resilience and stress-testing simulations within approved assessment environments. • Identified critical and high-risk vulnerabilities and provided detailed technical findings, proof-of-concept evidence, risk ratings, and remediation recommendations. • Conducted post-remediation penetration testing to verify security patches, validate vulnerability fixes, and ensure identified security issues were properly resolved. • Performed access control and privilege reviews to identify excessive permissions, insecure access rights, and potential privilege escalation risks. • Supported security and compliance requirements aligned with ISO 27001, PCI-DSS, SAMA, and other applicable ind

VaporVM

Penetration Tester

VaporVM • Período integral

Aug 2022 - Dec 2024 • 2 yrs 4 mos

• Conducted security assessments and penetration tests for web applications, mobile applications, APIs, internal/external networks, cloud infrastructure, and enterprise environments. • Performed application security testing, identifying vulnerabilities such as authentication and authorization flaws, OWASP Top 10 issues, business logic vulnerabilities, insecure configurations, and API security weaknesses. • Conducted internal and external network penetration testing, focusing on network protocols, exposed services, configurations, privilege escalation, and Active Directory access control weaknesses. • Performed source code reviews to identify security vulnerabilities, insecure coding practices, and application logic flaws, and provided remediation recommendations to development teams. • Integrated security practices into the SDLC and DevSecOps processes, supporting secure development, vulnerability management, and remediation workflows. • Conducted cloud security assessments and configuration reviews, identifying misconfigurations and security weaknesses across cloud-based infrastructure and storage services (AWS/Azure). • Performed system and application configuration security reviews against CIS Benchmarks and industry security best practices. • Developed and executed authorized, controlled DDoS resilience and stress-testing simulations within approved assessment environments. • Identified critical and high-risk vulnerabilities and provided detailed technical findings, proof-of-concept evidence, risk ratings, and remediation recommendations. • Conducted post-remediation penetration testing to verify security patches, validate vulnerability fixes, and ensure identified security issues were properly resolved. • Performed access control and privilege reviews to identify excessive permissions, insecure access rights, and potential privilege escalation risks. • Supported security and compliance requirements aligned with ISO 27001, PCI-DSS, SAMA, and other applicable ind

KloudEdge_Technologies

CyberSecurity Analyst

KloudEdge Technologies • Período integral

Jul 2021 - Jul 2022 • 1 yr

• Conducted security assessments of web and mobile applications, identifying vulnerabilities like SQL injection, XSS, and CSRF. • Collaborated with development teams to provide remediation guidance for identified security issues. • Performed penetration tests on internal and external networks, focusing on network protocols and configurations. • Researched and stayed current with cybersecurity trends and exploit methodologies to enhance testing strategies. • Developed detailed documentation and reports for security assessments, communicating findings to stakeholders.