Ahmad M.-Senior Security Consultant

Check rate
Experience
Senior Security Consultant
Deloitte
- Experienced cybersecurity engineer and penetration tester leading a pentest team (9+ members) across different countries of Deloitte's biggest financial clients.
- Planning and assigning pentest tasks every month.
- Ensuring client’s pentest projects for all 14 countries are finished on time for their monthly releases.
- Conducting kick-off meetings for new projects and performing performance reviews of team members.
- Pen-testing web applications, APIs, network, mobile applications, source code, thick-client, VoIP, and wireless technologies.
- Providing consulting for all products, projects, and services.
- Presenting and documenting findings and recommending fixes.
- Writing comprehensive reports including assessment-based findings, outcomes, and propositions for further system security enhancements.
Security Consultant
Pentester Academy Firmus
- Pen-testing web applications, APIs, network, mobile applications, source code, thick-client, VoIP, and wireless technologies.
- Providing consulting for all products, projects, and services.
- Presenting and documenting findings and recommending fixes.
- Performing vulnerability assessments and penetration tests, including on-demand pentests.
- Conducting meetings with clients to explain and reproduce vulnerabilities.
- Leading a team of pentesters.
- Writing comprehensive reports including assessment-based findings, outcomes, and propositions for further system security enhancements.
Application Security Engineer
Digitify
- Leading a team of 3 pentesters and performing pentests of in-house products before production.
- Pen-testing web applications, APIs, network, and mobile applications; providing consulting for all products, projects, and services.
- Conducting source code reviews.
- Presenting and documenting findings and recommending fixes.
- Dealing with third-party companies for security assessments; managing scoping, triaging, and assessing identified vulnerabilities.
- Writing comprehensive reports including assessment-based findings, outcomes, and propositions for further system security enhancements.
- Managing AWS cloud security and applying the MITRE ATT&CK framework to enhance threat detection.
- Reported a SQL injection on a university site, dumping a database of 70,000+ users and other databases.
- Reported a vulnerability on a tech giant in Pakistan, gaining access to a database of 10,000+ lines.
- Reported a vulnerability on a US-based blockchain company, accessing their complete database and SMTP account.
Security Engineer
Ebryx
- Performing penetration tests on multiple international organizations' infrastructure and on-site pentests.
- Pen-testing web applications, network, and mobile applications; providing consulting for all products, projects, and services.
- Conducting source code reviews and on-demand feature pentests for clients.
- Performing on-site WiFi pentests and internal company pentests.
- Collaborating with team leads to divide work and create execution plans for upcoming pentests.
- Holding meetings with clients to reproduce findings.
- Supervising internees, monitoring pentest progress, and assisting with report writing.
- Discovered a misconfiguration at a software development company (Arbisoft) granting access to their whole database.
- Reported SQL injection and broken access control on an ISP, accessing an authenticated endpoint without authentication.
Information Security Consultant
BPCPetroleum
- Conducting black box, white box, and grey box web pentests, network pentests, mobile pentests, API pentests, source code reviews, VAPT, and cloud pentests.
- Working with developers to fix vulnerabilities.
- Training employees to protect against phishing attacks.
- Analyzing network traffic for malicious activities.
- Suggesting efficient methods to protect systems and data.
- Delivering technical and pentest reports to the IT department.
Industry experience
See where this freelancer has spent most of their professional time.
Experienced in Professional Services, Banking and Finance, Information Technology, and Energy.
Business area experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology and Project Management.
Summary
Experienced Cybersecurity Engineer and Penetration Tester, leading a penetration testing team responsible for securing Deloitte’s most critical clients. Recognized with the "Best Pentester of the Year 2021" award for excellence in the field.
Passionate about knowledge sharing, I write Medium blogs covering cybersecurity concepts and interesting vulnerabilities I have discovered.
Skills
- Blackbox, Whitebox & Greybox Web Pentest
- Mobile Pentest
- Vapt
- Api Pentest
- Source Code Review
- Leadership
- Red Teaminig
- Cloud Pentest
- Leadership
Languages
Education
Asia Pacific University
Bachelors in Cybersecurity · Cybersecurity · Kuala Lumpur, Malaysia
Asia Pacific University
Diploma in Software Engineering · Software Engineering · Kuala Lumpur, Malaysia
Certifications & licenses
Certified Red Team Professional (CRTP)
Pentester Academy Firmus
EWPT
OSCP+
Statistics
Experience
Global experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Ahmad speaks the following languages: English (Advanced), Malay (Advanced), Arabic (Elementary).
Ahmad has at least 7 years of experience. During this time, Ahmad has worked in at least 5 different roles and for 5 different companies. The average length of individual experience is 2 years and 6 months. Note that Ahmad may not have shared all experience and actually has more experience.
Based on recent experience, Ahmad would be well-suited for roles such as: Senior Security Consultant, Security Consultant, Application Security Engineer.
Ahmad's most recent position is Senior Security Consultant at Deloitte.
In recent years, Ahmad has worked for Deloitte, Pentester Academy Firmus, and Digitify.
Ahmad is most experienced in industries like Professional Services, Banking and Finance, and Information Technology. Ahmad also has some experience in Energy.
Ahmad is most experienced in business areas like Information Technology and Project Management.
Ahmad has recently worked in industries like Banking and Finance, Professional Services, and Information Technology.
Ahmad has recently worked in business areas like Information Technology and Project Management.
Ahmad holds a Bachelor in Cybersecurity from Asia Pacific University and a Bachelor in Software Engineering from Asia Pacific University.
Ahmad has 3 certificates. These include: Certified Red Team Professional (CRTP), EWPT, and OSCP+.
The availability of Ahmad needs to be confirmed.
Similar freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Senior Security Consultant
