Senior Application Security & Red Team Engineer
OSCP+ certified Application Security & Red Team Engineer with 8+ years across banking, telecom, aviation, insurance, and e-commerce. Bugcrowd Top 100 (2018) with 400+ reports submitted, 150+ validated. Published CVE (CVE-2026-31974). Hands-on across penetration testing, API security, threat modeling, secure SDLC, DevSecOps automation, and AI/LLM security.
- 2025 – 2026 · Senior AppSec / Red Team EngineerAbu Dhabi Commercial Bank (ADCB)Abu Dhabi Commercial Bank (ADCB)2025 – 2026
Led STRIDE threat modeling across 14-microservice architecture; produced 52-finding risk register fed into engineering backlogs. Performed CI/CD pipeline assessments and mobile MASVS assessments (140 test cases, 25 findings).
- 2024 – 2025 · AppSec Senior ConsultantKafein Technology SolutionsKafein Technology Solutions2024 – 2025
Security assessments and code reviews across Python/Go/Java/TypeScript stacks. Deployed and tuned SAST/SCA/DAST for 10+ client teams. Trained 100+ developers on OWASP API Top 10.
- 2023 – 2024 · Penetration TesterFuture Technology Systems (Kuwait)Future Technology Systems (Kuwait)2023 – 2024
15+ full-stack pentests for enterprise and financial sector clients; 200+ critical findings; 90% remediation within SLA. Advised three banks on zero-trust network redesign.
- 2022 – 2023 · Red Team Senior SpecialistBarikat CybersecurityBarikat Cybersecurity2022 – 2023
Web, mobile, API, network, and physical assessments for aviation sector. AD attack chains mapped to MITRE ATT&CK. Re-tested all findings and certified fixes before systems went live.
- 2021 – 2022 · InfoSec Senior SpecialistAna SigortaAna Sigorta2021 – 2022
Oversaw risk analysis, control rollout, and PCI-DSS audit; 100% pass on first attempt. Negotiated vendor contracts saving $15K.
- 2020 – 2021 · Application Security EngineerIntertechIntertech2020 – 2021
Built security gates into 700+ Jenkins pipelines (SAST, SCA, DAST, secrets). Led 8-month Security Champion Academy for 500+ developers; 30% fewer OWASP flaws.
- OSCP+ / OSCP — OffSec
- eWPTx — INE, 2026
- eMAPT — INE, 2026
- Certified API Security Pro (CASP)
- Certified DevSecOps Pro (CDP)
- CEH Master
- ISO27001 Lead Auditor
- Python / Bash / PowerShell / Go
- Burp Suite Pro / Metasploit / BloodHound
- Fortify / SonarQube / Snyk / Nexus IQ
- Jenkins / GitLab CI / GitHub Actions
- AWS / Azure / GCP / Docker / Kubernetes
CTF Player (HTB), Shotokan Karate, Analog Photography, Strategy Gaming (EU4, Dota 2).