Offensive security professional with 5+ years of hands-on
experience delivering penetration testing and vulnerability management across financial,
healthcare, oil & gas, manufacturing and e-commerce sectors in the UAE, the wider
Middle East and South Asia.
OSCP+ and CRTP certified, with a track record of identifying critical RCE,
IDOR, business logic and account takeover vulnerabilities by chaining low-risk issues into
high-impact exploit paths. Experienced in vulnerability management at scale, AI-assisted
security tooling, and building internal security tools.
Delivers both technical and executive-grade reports, mentors junior testers, and
contributes to in-house attack methodologies. Active bug bounty researcher.
Confidential · SK / CP-01
Scope of practice
What I am engaged to do
Offensive security
Web, mobile & network penetration testing
Vulnerability assessment & management
Active Directory exploitation
Cloud security testing (AWS)
Source code review (SAST/DAST)
Governance & compliance
NIST CSF, PCI DSS, ISO 27001
UAE IA Standards, NESA, ADHICS
Security policy & procedure development
Threat modeling
MITRE ATT&CK framework
OWASP Top 10 / MASVS / ASVS
Collaboration
Executive & technical reporting
Stakeholder communication
Developer remediation coaching
Cross-functional team leadership
Security awareness training
Mentoring & knowledge transfer
Confidential · SK / CP-01
Selected engagements
Client names withheld under NDA
Core banking mobile application
Financial · PK & ME
MethodGrey boxClientScale2M+ end users
Discovered amount manipulation and authentication bypass
enabling unauthorised fund transfers
CVSS 8.1
Bypassed SSL pinning, root detection and runtime integrity checks using custom Frida scripts
Led the remediation workshop with the client's DevSecOps team
National vaccine portal
Healthcare · PK & ME
MethodOWASP Top 10 & MASVS L2Client
Uncovered 4 high-severity findings, including stored XSS and broken access control
Mobile assessment identified insecure data storage and weak crypto implementations
Energy infrastructure
Oil & Gas · PK & ME
MethodBlack & grey box · web, mobile and core infrastructure
Uncovered critical Remote Code Execution and business logic flaws
Partnered with engineering to deploy compensating controls within 7 days
Distributed manufacturing estate
Industrial · US, CA & ME
MethodInfrastructure, SAST and DAST across globally distributed facilities
Assessed 100+ network devices and servers
Delivered a unified remediation roadmap consumed by globally distributed engineering teams
Tier-1 e-commerce platforms
E-commerce · PK & ME
MethodWeb & APIClient
Identified IDOR and account takeover, bypassing WAF and bot protection
Developer-focused remediation guidance reduced recurrence on subsequent retests
All findings retested · closed
Confidential · SK / CP-01
Engagement model
How an engagement runs
Scoping inputs
TODO(shaheer): what you need from a client before quoting — asset inventory, environment access, test window, rules of engagement.
Typical duration
TODO(shaheer): typical engagement length by type (web / mobile / network / AD).
Deliverable set
TODO(shaheer): what the client receives — executive summary, technical report, evidence pack, remediation guidance.
Retest policy
TODO(shaheer): what is retested, when, and whether it is included in the original fee.
Turnaround
TODO(shaheer): time from test completion to draft report, and from draft to final.
Scope and lead 15+ engagements per quarter across web, mobile, network and Active Directory for enterprise clients in the GCC
Manage vulnerability assessment and remediation tracking for 2,000+ assets; built a prioritisation methodology ranking findings by asset criticality, public exposure and severity
Chain low-severity findings into full attack paths, producing CVSS 8.0+ disclosures across multiple engagements
Build internal tooling automating reconnaissance, reporting and vulnerability correlation
Contribute TTPs to the internal methodology library; authored scripts adopted firm-wide
Participate in Red vs Blue exercises to uplift detection engineering and ATT&CK coverage
Mentor junior consultants and deliver C-suite and engineering briefings
Cyber Security Analyst — Security Engineer
Nov 2022 — Aug 2024
OrganisationB&S World Supply, Dubai, UAE
Conducted 100+ assessments across systems, networks and applications, reducing critical exposure 60% year-over-year
Developed policies aligned to NIST CSF, PCI DSS and ISO 27001; led the organisation through 2 external audits with zero major findings
Reported 200+ vulnerabilities with prioritised guidance, achieving 70% mean-time-to-remediation improvement
Python · Bash · PowerShell — custom internal tools for reconnaissance, reporting and vulnerability correlation. AI models (Hermes, Claude) applied to threat research and tooling development.
Frameworks & standards
OWASP Top 10 · OWASP MASVS · MITRE ATT&CK · NIST CSF · PCI DSS · ISO 27001 · UAE IA Standards · NESA · ADHICS
Confidential · SK / CP-01
Research & tooling
Shipped work, outside client engagements
TODO(shaheer): tool name
Slot 1
TODO(shaheer): one line on the problem it solves.
StackTODO(shaheer)
Screenshot — TODO(shaheer)
TODO(shaheer): tool name
Slot 2
TODO(shaheer): one line on the problem it solves.
StackTODO(shaheer)
Screenshot — TODO(shaheer)
TODO(shaheer): tool name
Slot 3
TODO(shaheer): one line on the problem it solves.
StackTODO(shaheer)
Screenshot — TODO(shaheer)
Active researcher on HackerOne and Bugcrowd, with valid
reports accepted across a range of programmes.
Focus areas: IDOR, SSRF, business logic flaws, authentication and authorisation bypass,
OAuth misconfiguration, and account takeover.
Sample finding (PDF) — not yet published
Confidential · SK / CP-01
Instrumentation
Measured, not asserted
Public activity
GitHub · trailing 52 weeks · refreshed 2026-08-17
Contributions33
Commits32
Pull requests1
Issues0
Public repositories only. Client engagements are performed in
customer-controlled repositories under NDA and are not represented here; this
graph therefore understates delivery by design.
Model usage
Anthropic API · rolling 30 days
Not available at last build — an Admin API key is required.