About
Cyber Security Consultant with ~2 years of experience in VAPT across Web, API, Network, and Mobile (Android) applications. Identified 100+ vulnerabilities including Critical and High-risk issues, achieving 90%+ remediation across client environments. Skilled in OWASP Top 10, API security testing, and delivering client-ready security reports with CVSS-based risk analysis.
Skills & Expertise (23)
Work Experience
Cyber Security Consultant
PROTECHMANIZE SOLUTIONS PVT LTD
Jun 2025 - Present
Performed VAPT on 50+ web, API, and mobile applications, identifying critical vulnerabilities impacting authentication and access control. Analyzed and validated Critical and High-risk vulnerabilities including authentication bypass, injection, and business logic flaws. Conducted advanced API security testing covering BOLA, BFLA, mass assignment, rate limiting, and token manipulation. Identified security gaps in session management and implemented recommendations that improved access control and session security. Executed network assessments identifying open ports, insecure services, and misconfigurations. Delivered client-ready reports with CVSS scoring, PoCs, and remediation guidance, improving overall application security posture. Reduced security risks by identifying and validating critical vulnerabilities before production deployment. Collaborated with development teams to remediate vulnerabilities and improve application security posture.
Associate Cyber Security Consultant
RIME SOFT LIMITED
Jun 2024 - Jun 2025
Identified 80+ vulnerabilities across web applications using Burp Suite and manual testing techniques. Performed API security testing including endpoint enumeration, parameter tampering, and rate-limit bypass testing. Detected client-side vulnerabilities such as insecure storage, token exposure, and improper validation. Conducted network vulnerability assessments identifying outdated components and misconfigurations. Prepared security reports with CVSS scoring and prioritized remediation recommendations. Assisted in retesting vulnerabilities after remediation, ensuring issues were fully resolved. Participated in internal knowledge sharing sessions on Web & API VAPT techniques and OWASP Top 10 mitigation strategies.
Education
B. Tech in Civil Engineering - ABR College of Engineering & Technology
- 2024 · Afghanistan
Diploma in Civil Engineering - St. Mary’s Group of Institutions
- · Afghanistan
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Need Sponsorship
Relocation
Depends on Offer