Skip to content
View JawadMahdiBD's full-sized avatar

Highlights

  • Pro

Organizations

@Whispergate

Block or report JawadMahdiBD

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
JawadMahdiBD/README.md

Hi, I'm Jawad Mahdi 👋

Offensive Security Researcher · Penetration Tester · Red Teamer

National team CTF champion · Selected public acknowledgements through authorized security programs

Portfolio · LinkedIn · Message · Medium · Résumé


About Me

I'm an offensive security researcher and penetration tester with 3+ years of hands-on experience across web applications, APIs, mobile applications, networks, Active Directory, vulnerability assessment, and red-team operations.

My work combines offensive-security testing, research, automation, and engineering. I turn validated weaknesses into reproducible evidence, proportionate risk context, and remediation guidance that security leaders and engineering teams can act on.

  • 3+ years in offensive security
  • National team CTF champion with documented international and solo national results
  • Selected public acknowledgements from authorized vulnerability research
  • 11 professional credentials
  • BSc (Hons) Computer Science — CGPA 3.69
  • Based in Bangladesh

Experience

Microsoft 365 & Security Administrator

Confidential maritime company · Malaysia · Jan–Dec 2025 · One-year contract

  • Administered Microsoft 365, Microsoft Entra ID, and Microsoft Defender with tenant-wide privileges.
  • Maintained identity, access, security configuration, and day-to-day platform administration.

Confidential Security Researcher

Confidential security environment · 2021–2023

  • Supported authorized security research under strict confidentiality obligations.
  • The organization, mission, systems, scope, methods, findings, and outcomes remain withheld.

Bug Bounty Researcher

Synack Red Team · HackerOne · Bugcrowd · 2020–2024 · Independent

  • Assessed web applications, APIs, mobile applications, and network infrastructure through authorized programs.
  • Documented reproducible findings and worked with security teams through program validation and remediation.
  • Selected publicly acknowledged outcomes include the U.S. Department of Defense, Apple, the University of Cambridge, The Coca-Cola Company, and Dell Technologies.

Real Projects

A private research workspace that organizes authorized information into evidence people can search, review, visualize, and export safely.

TypeScript React Electron Node.js MCP

A controlled platform for scheduling approved security checks, managing execution, and organizing findings for review.

Nuclei Docker MongoDB JWT RBAC

A platform that turns network-security checks into trackable work, reports, schedules, and follow-up actions.

Django Network Security Scheduling Reporting

Reusable command-line tools that reduce repetitive security-research work and make common workflows easier to repeat.

Python Bash OSINT Workflow Automation

Additional Projects

  • MJZ Autonomous Pentest Agent — An AI-assisted testing workspace that coordinates authorized assessments and preserves clear evidence from discovery through reporting.
    Codex / OpenCode Burp Suite MCP Docker Nuclei

  • Credential Breach Monitoring — A system for monitoring and analyzing exposed account information so security teams can investigate risk.
    Django Elasticsearch

  • Confidential Security Assessments — Selected authorized work remains private under confidentiality obligations.
    NDA Protected

View the complete project showcase →

Skills & Tools

  • Penetration Testing: Web applications, APIs, mobile applications, networks, Active Directory, vulnerability assessment, red teaming
  • Security Services: Web and API testing, network testing, web source-code review, mobile testing, AI red teaming, security-tool development, controlled proof-of-concept development
  • Security Tools: Burp Suite Pro, Nmap, Metasploit, Nuclei, Katana, Wireshark, OpenVAS, Kali Linux
  • Engineering: Python, Bash, C/C++, TypeScript, React, Electron, Node.js, Django, Docker
  • Data Systems: MongoDB, PostgreSQL, Elasticsearch
  • Methods & Frameworks: MCP, OWASP Top 10, MITRE ATT&CK, CVSS, OSINT

Certifications

Achievements

  • Selected public acknowledgements: eligible reports were reviewed and accepted through authorized programs operated by the U.S. Department of Defense, Apple, the University of Cambridge, The Coca-Cola Company, and Dell Technologies.
  • National CTF record: four national team championships and four national runner-up finishes.
  • Cyber Apocalypse CTF 2021: team placed 94th of 4,740 teams, a top-2% international result.
  • Curtin Malaysia CTF 2023: placed 13th nationally among university participants while competing solo.

Recognition records describe authorized vulnerability-disclosure outcomes—not employment, client work, sponsorship, or endorsement.

Review the documented CTF record → · Review public acknowledgements →

Education

BSc (Hons) Computer Science

Taylor's University / University of Bristol · 2023–2026

  • CGPA: 3.69

Writeups & Research

View all six research articles →

Let's Connect

I'm open to conversations about offensive-security roles, authorized assessments, security consultation, research collaboration, and new projects.

Pinned Loading

  1. scripts scripts Public

    Security automation toolkit for repeatable, authorized reconnaissance, OSINT, analysis, and reporting workflows.

    Python 1

  2. Payloads-for-Pentesting Payloads-for-Pentesting Public

    Curated test inputs for authorized Burp Suite and manual web-application security assessments.

    3