// 01 — Dossier
Operator profile
Red Team specialist identifying vulnerabilities across software, hardware, and network infrastructure — penetration testing of digital platforms and physical / embedded systems, with realistic APT simulations and EDR / AV evasion.
02 / Trajectory
Three roles, five years.
Offensive engineering, SOC operations, and bug-bounty research — full bullets in the CV.
Off. Sec. Engineer
Shorborno Holdings Ltd. — MSSP of Grameenphone Ltd. · GP House, Dhaka.
Cyber Security Analyst
Pentester Space — Agargaon, Dhaka. SOC monitoring, SOAR-driven response, AD & cloud pentesting.
Security Researcher
Synack Red Team Inc. — Redwood City, CA (Remote). Web and Android vulnerability research.
03 / How I work
Engagement principles.
Four things every engagement gets, regardless of scope or budget.
Narrow first, deep second
A tight scope explored thoroughly beats five surface skims. Surface-level findings serve no one — and they're what gets missed in the report you actually act on.
PoCs over claims
Every finding ships with a reproducible proof — script, screenshot, packet capture, request collection. If the engineer can't trigger it, the fix won't land.
Two audiences, one document
Executive summary your leadership can hand up the chain, and a technical appendix your on-call engineer can act on at 11pm. Same report, both layers.
Diff, not directive
Not "patch the system" — here's the diff, here's the detection rule, here's the regression test. Strategic remediation written for the engineer who'll implement it.
04 / Highlights
Selected proof of work.
CVE-2024-44851
Stored XSS in the File Sharing module of Perfex CRM.
CVE-2024-46638
Stored XSS in HelpDeskZ v2.0.2.
Honeypot Research
Honeypot-driven mapping of the smart-industry threat landscape. Best Paper · EAI WICON 2021.
IoT Air Quality & Weather
First-author paper at ICISET 2022 — IoT sensor system with an Android client.
05 / Off-shift
Languages & current focus.
A short list of where my attention is between engagements.
// Languages
- Native Bangla
- Fluent English
- Conversational Hindi
// Currently exploring
- Multi-cloud red-team
- EDR / AV evasion
- Mobile pentest tooling
- Agentic AI security
- MITRE TTP scoring
- Web vulnerability research
These map to recent certifications (CRTO, eWPTX, MCRTA), recent CVE work, and the directions of my academic publications.
// Full credentials