/ CV · CURRICULUM
— · — · — v 4.2 · MMXXVI
Curriculum Vitae 5+ Years

// 04 — Credentials

Ashfaqul Haq

Five years across web, mobile, embedded, and adversary-simulation work. Two CVEs, four academic publications, 100+ Hall of Fame credits.

01 / Objective

Red Team specialist, end to end.

A results-driven Red Team specialist with experience identifying vulnerabilities across software, hardware, and network infrastructure. Comprehensive penetration testing of digital platforms (Web, Android) and physical / embedded systems — including IoT devices, access-control hardware, biometric data, and telco assets. Skilled in realistic APT simulations and bypassing modern defenses through sophisticated EDR and Antivirus evasion.

02 / Experience

Three roles, five years.

June 2025 — Present

Off. Sec. Engineer · Shorborno

MSSP of Grameenphone Ltd. · GP House, Dhaka.

June 2022 — May 2025

Cyber Security Analyst

Pentester Space · Agargaon, Dhaka.

2021 — 2024

Security Researcher

Synack Red Team Inc. · Redwood City, California (Remote).

Shorborno — Off. Sec. Engineer

  • 200+ web and Android pentests on enterprise clients and bug-bounty programs.
  • Critical web vulnerabilities — SQLi, SSRF, SSTI, XSS, broken auth and authorization.
  • Embedded-systems assessments — IoT devices, access-control hardware, biometric data.
  • Multi-stage Red Team engagements with APT simulations.
  • Custom payloads — EDR evasion and DLP bypass.
  • Technical reports with reproducible PoCs and strategic remediation.

Pentester Space — Cyber Security Analyst

  • SOC monitoring with SolarWinds, Suricata, Wazuh, Splunk.
  • SOAR-driven incident response across web, Android, network, and Active Directory.
  • Compliance support — GDPR, ISO/IEC 27001, MITRE ATT&CK, NIST.
  • IAM controls and AWS security best practices for new projects and vendors.

Synack Red Team — Security Researcher

  • Vulnerability research on web and Android applications.
  • Critical-to-low findings reported across the program lifecycle.

03 / Toolkit

Tools, languages, frameworks.

04 / Certifications

Eight programs.

Offensive operations, web, mobile, infra, and cloud.

05 / Education & awards

Two degrees, five podium finishes.

2025 — Running

M.Sc. Information Systems Security

Bangladesh University of Professionals (BUP) — Mirpur Cantonment, Dhaka.

2018 — 2022

B.Sc. Electrical & Electronic Engineering

International Islamic University Chittagong — Kumira. CGPA 3.09 / 4.0.

11 Jan 2020

★ Champion · Team SiliconBits

National Cyber Drill 2020 — BGD e-GOV CIRT.

2021 — 2022

4× Runners-up

IIUC T3 (Inter-Univ. Cyber Drill) · SiliconBits (CTF Super League, IEEE CS BUET) · Bitsoverflow (National Cyber Drill 2021) · Secure Hex (IIUC CyberCon 2022).

06 / Hall of Fame

100+ acknowledged.

A partial list — full counter still climbing.

07 / CVEs

Two published.

Both stored XSS — disclosed responsibly through public CVE channels.

08 / Publications

Four academic publications.

[J.1] WINET

Faking Smart Industry — Honeypot Research

Co-author. Wireless Networks (WINET).

[C.1] EAI WICON 2021

★ Same paper · Best Paper Award

14th EAI International Wireless Internet (EAI WICON 2021).

[C.2] ICISET 2022

IoT Air Quality & Weather Monitoring

First-author. International Conference on Innovations in Science, Engineering, and Technology (ICISET-2022).

[C.3] ICSCA 2025

Risk-Based MITRE TTP Scoring

Co-author. 2025 14th International Conference on Software and Computer Applications. pp. 72–76.

[C.4] —

Securing Agentic AI

Co-author. Threats, risks, and mitigation.

// Engagement

Available for security work.

Get in touch →