Architected a custom Python-based automation tool to streamline the security assessment lifecycle, integrating subdomain enumeration with automated vulnerability discovery.
Engineered modules to detect common web-based vulnerabilities (SQLI, SSRF, XSS) across large attack surfaces, significantly reducing manual reconnaissance time by up to 40% across target domains.
Implemented efficient data parsing to generate actionable vulnerability reports, facilitating rapid triage and remediation for bug bounty engagements.
Conducted hands-on vulnerability assessments on simulated enterprise network environments, identifying misconfigurations and weaknesses across routers, switches, and endpoint systems.
Configured and tested firewall rule sets and access control policies to enforce network segmentation and restrict unauthorized traffic in alignment with security best practices.
Performed network traffic analysis using Wireshark and Nmap to detect anomalies, map attack surfaces, and support penetration testing exercises on internal infrastructure.
Web App Penetration Tester Trainee
Arab Open University (AOU)
Dec 2024 - May 2025
Performed security assessments on web applications to identify vulnerabilities including SQL Injection, XSS, and Broken Authentication.
Utilized Burp Suite and manual testing techniques to bypass security controls and document findings.
Collaborated with the development team to provide remediation strategies based on the OWASP framework.
Drafted comprehensive technical remediation reports addressing OWASP Top 10 vulnerabilities (including SQLI, XSS, and IDOR) for development teams.