About
Cybersecurity Analyst and Penetration Tester with 2.5+ years of experience in vulnerability assessment and penetration testing across web applications, APIs, networks, and cloud environments. Skilled in identifying and validating OWASP Top 10 vulnerabilities such as SQL injection, XSS, IDOR, SSRF, authentication issues, and security misconfigurations. Hands-on experience with tools like Burp Suite, Nmap, Nessus, Metasploit, and Kali Linux, along with exposure to SIEM monitoring and incident analysis using Wazuh and Elastic Stack. Also experienced in supporting compliance and security audits aligned with frameworks such as NIST, CIS, SOC 2, and HIPAA, including basic risk assessment and gap analysis. Familiar with Python and Bash scripting for automating repetitive security tasks and improving efficiency.
Skills & Expertise (34)
Work Experience
Cyber Security Analyst
Dinoct Solutions
Jun 2023 - Oct 2025
Conducted vulnerability assessment and penetration testing on 30+ web applications, APIs, networks, and cloud environments, identifying and prioritizing security risks. Discovered and validated 50+ vulnerabilities including OWASP Top 10 issues. Performed manual validation of automated scan results, reducing false positives and improving reporting accuracy by 30%. Utilized tools including Burp Suite, Nmap, Nessus, Metasploit, Nikto, and Kali Linux for comprehensive security testing. Supported compliance assessments aligned with frameworks such as NIST, CIS, SOC 2, and HIPAA, including audit evidence collection, control validation, and gap analysis. Assisted in security audits and contributed to documentation of policies, procedures, and risk findings for compliance requirements. Monitored security alerts using Wazuh and Elastic, assisting in threat detection, investigation, and incident response activities.
VAPT, Cyber Security - Intern & Trainee
Brototype
Jul 2022 - Apr 2023
Gained foundational knowledge in cybersecurity through practical exposure to vulnerability assessments and penetration testing on systems, networks, and web applications. Learned and applied tools and techniques to identify security weaknesses and potential threats. Assisted in documenting vulnerabilities and preparing reports, contributing to a deeper understanding of security operations and processes.
Education
Bachelor of Business Administration - University Of Calicut
2017 - 2020 · Afghanistan
Plus two - Science - GVHSS Kalpetta, Wayanad
2015 - 2017 · Afghanistan
Certifications
ISO/IEC 27001:2022 Lead Auditor
Master Minds · 2026
Google Cloud Certified Professional Cloud Security Engineer
Google cloud · 2024
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Relocation
Open to Relocation
Skills (34)
Click a skill to find developers with the same skill