skip to content
$ cd /about

Senior Application Security & Red Team Engineer

Istanbul, Turkey · Open to Europe / UK / Remote
# Signal

OSCP+ certified Application Security & Red Team Engineer with 8+ years across banking, telecom, aviation, insurance, and e-commerce. Bugcrowd Top 100 (2018) with 400+ reports submitted, 150+ validated. Published CVE (CVE-2026-31974). Hands-on across penetration testing, API security, threat modeling, secure SDLC, DevSecOps automation, and AI/LLM security.

# Trajectory
  1. 2025 – 2026 · Senior AppSec / Red Team Engineer
    Abu Dhabi Commercial Bank (ADCB)

    Led STRIDE threat modeling across 14-microservice architecture; produced 52-finding risk register fed into engineering backlogs. Performed CI/CD pipeline assessments and mobile MASVS assessments (140 test cases, 25 findings).

  2. 2024 – 2025 · AppSec Senior Consultant
    Kafein Technology Solutions

    Security assessments and code reviews across Python/Go/Java/TypeScript stacks. Deployed and tuned SAST/SCA/DAST for 10+ client teams. Trained 100+ developers on OWASP API Top 10.

  3. 2023 – 2024 · Penetration Tester
    Future Technology Systems (Kuwait)

    15+ full-stack pentests for enterprise and financial sector clients; 200+ critical findings; 90% remediation within SLA. Advised three banks on zero-trust network redesign.

  4. 2022 – 2023 · Red Team Senior Specialist
    Barikat Cybersecurity

    Web, mobile, API, network, and physical assessments for aviation sector. AD attack chains mapped to MITRE ATT&CK. Re-tested all findings and certified fixes before systems went live.

  5. 2021 – 2022 · InfoSec Senior Specialist
    Ana Sigorta

    Oversaw risk analysis, control rollout, and PCI-DSS audit; 100% pass on first attempt. Negotiated vendor contracts saving $15K.

  6. 2020 – 2021 · Application Security Engineer
    Intertech

    Built security gates into 700+ Jenkins pipelines (SAST, SCA, DAST, secrets). Led 8-month Security Champion Academy for 500+ developers; 30% fewer OWASP flaws.

# Arsenal
Certifications
  • OSCP+ / OSCP — OffSec
  • eWPTx — INE, 2026
  • eMAPT — INE, 2026
  • Certified API Security Pro (CASP)
  • Certified DevSecOps Pro (CDP)
  • CEH Master
  • ISO27001 Lead Auditor
Stack
  • Python / Bash / PowerShell / Go
  • Burp Suite Pro / Metasploit / BloodHound
  • Fortify / SonarQube / Snyk / Nexus IQ
  • Jenkins / GitLab CI / GitHub Actions
  • AWS / Azure / GCP / Docker / Kubernetes
# Offline

CTF Player (HTB), Shotokan Karate, Analog Photography, Strategy Gaming (EU4, Dota 2).