Offensive Security Researcher · Penetration Tester · Red Teamer
National team CTF champion · Selected public acknowledgements through authorized security programs
Portfolio · LinkedIn · Message · Medium · Résumé
I'm an offensive security researcher and penetration tester with 3+ years of hands-on experience across web applications, APIs, mobile applications, networks, Active Directory, vulnerability assessment, and red-team operations.
My work combines offensive-security testing, research, automation, and engineering. I turn validated weaknesses into reproducible evidence, proportionate risk context, and remediation guidance that security leaders and engineering teams can act on.
- 3+ years in offensive security
- National team CTF champion with documented international and solo national results
- Selected public acknowledgements from authorized vulnerability research
- 11 professional credentials
- BSc (Hons) Computer Science — CGPA 3.69
- Based in Bangladesh
Confidential maritime company · Malaysia · Jan–Dec 2025 · One-year contract
- Administered Microsoft 365, Microsoft Entra ID, and Microsoft Defender with tenant-wide privileges.
- Maintained identity, access, security configuration, and day-to-day platform administration.
Confidential security environment · 2021–2023
- Supported authorized security research under strict confidentiality obligations.
- The organization, mission, systems, scope, methods, findings, and outcomes remain withheld.
Synack Red Team · HackerOne · Bugcrowd · 2020–2024 · Independent
- Assessed web applications, APIs, mobile applications, and network infrastructure through authorized programs.
- Documented reproducible findings and worked with security teams through program validation and remediation.
- Selected publicly acknowledged outcomes include the U.S. Department of Defense, Apple, the University of Cambridge, The Coca-Cola Company, and Dell Technologies.
A private research workspace that organizes authorized information into evidence people can search, review, visualize, and export safely.
TypeScript React Electron Node.js MCP
A controlled platform for scheduling approved security checks, managing execution, and organizing findings for review.
Nuclei Docker MongoDB JWT RBAC
A platform that turns network-security checks into trackable work, reports, schedules, and follow-up actions.
Django Network Security Scheduling Reporting
Reusable command-line tools that reduce repetitive security-research work and make common workflows easier to repeat.
Python Bash OSINT Workflow Automation
-
MJZ Autonomous Pentest Agent — An AI-assisted testing workspace that coordinates authorized assessments and preserves clear evidence from discovery through reporting.
Codex / OpenCodeBurp Suite MCPDockerNuclei -
Credential Breach Monitoring — A system for monitoring and analyzing exposed account information so security teams can investigate risk.
DjangoElasticsearch -
Confidential Security Assessments — Selected authorized work remains private under confidentiality obligations.
NDA Protected
View the complete project showcase →
- Penetration Testing: Web applications, APIs, mobile applications, networks, Active Directory, vulnerability assessment, red teaming
- Security Services: Web and API testing, network testing, web source-code review, mobile testing, AI red teaming, security-tool development, controlled proof-of-concept development
- Security Tools: Burp Suite Pro, Nmap, Metasploit, Nuclei, Katana, Wireshark, OpenVAS, Kali Linux
- Engineering: Python, Bash, C/C++, TypeScript, React, Electron, Node.js, Django, Docker
- Data Systems: MongoDB, PostgreSQL, Elasticsearch
- Methods & Frameworks: MCP, OWASP Top 10, MITRE ATT&CK, CVSS, OSINT
- Certified Red Team Professional · CRTP · Altered Security
- Sliver C2: Pentesting and Evasion · Hack Smarter · Kairos Sec
- Web Application Penetration Tester eXtreme · eWPTX · INE Security
- Certified Professional Penetration Tester · eCPPT · INE Security
- Certified AppSec Pentester · CAPen · The SecOps Group
- Certified API Security Analyst · CASA · APIsec University
- Certified Security Code Review Beginners · CSCRB · Red Team Leaders
- Google Cybersecurity Professional Certificate · Google · Coursera
- Certified Cybersecurity Educator Professional · CCEP · Red Team Leaders
- Basic Python for Analytics Professional · CADS · 2025
- Java Foundations · Oracle Academy · 2023
- Selected public acknowledgements: eligible reports were reviewed and accepted through authorized programs operated by the U.S. Department of Defense, Apple, the University of Cambridge, The Coca-Cola Company, and Dell Technologies.
- National CTF record: four national team championships and four national runner-up finishes.
- Cyber Apocalypse CTF 2021: team placed 94th of 4,740 teams, a top-2% international result.
- Curtin Malaysia CTF 2023: placed 13th nationally among university participants while competing solo.
Recognition records describe authorized vulnerability-disclosure outcomes—not employment, client work, sponsorship, or endorsement.
Review the documented CTF record → · Review public acknowledgements →
Taylor's University / University of Bristol · 2023–2026
- CGPA: 3.69
- Using Burp Suite MCP with AI to Assess a Supabase Application — AI-assisted application testing, controlled validation, and repeatable documentation.
- Chaining OSINT, IDOR, and RCE — How multiple weaknesses combined into a complete exploit chain.
- A Weird Bug That Leaked PII — Reproducing and explaining an unusual personal-data exposure.
View all six research articles →
I'm open to conversations about offensive-security roles, authorized assessments, security consultation, research collaboration, and new projects.