HACTRON.SEC
SYSTEM ONLINE · DUBAI, UAE

IDENTITY / 001 · SECURITY CONSULTANT

Think like an
attacker.
Build like a defender.

Application & API Security professional focused on offensive testing, product security and practical risk reduction across modern enterprise environments.

● ● ●hactron@secops:~ENCRYPTED

$ whoami

Cybersecurity Consultant

$ specialize --in

API Security, AppSec, Product Security

$ status READY_

HS
APIAPPCLOUD
4+YEARS
SECURITY
APISECURITY
FOCUS
<3%AVG ROLLOUT
DEFECTS
20%REPEAT INCIDENT
REDUCTION

Security beyond
the scanner.

I'm a Cybersecurity Consultant with 4+ years of experience across application, API and product security.

My work spans end-to-end API assessments, source code review, cloud and container security, CI/CD security, vulnerability management, and security controls around API gateways, WAFs, firewalls and enterprise platforms.

I turn technical findings into actionable remediation and help engineering teams move security closer to design and development.

Attack surface
mapped.

SELECT A DOMAIN →

LIVE INTELLIGENCEAPI SECURITY

End-to-end API security assessments covering authentication, authorization, business logic, rate limiting, input validation and API gateway controls.

Field experience.

01
CURRENT

Security Consultant

Enterprise Banking Client · Dubai, UAE

  • Conduct end-to-end product API security assessments across multiple squads and products.
  • Perform source code reviews and assess application architecture and security controls.
  • Work across container security, CI/CD pipeline security and AWS, Azure and GCP practices.
  • Review Kafka topics, API Gateway, WAF, firewall and network security controls.
  • Use Burp Suite, Checkmarx, Sysdig and Kibana for testing and security monitoring.
  • Promote Shift Left security and collaborate with engineering/product teams on remediation.
02
PREVIOUS

Cybersecurity / Application Security

ICICI Bank Client

  • Coordinated VAPT activities and security testing for critical business applications.
  • Successfully delivered security assessments for LAMS and InstaServe.
  • Identified critical security vulnerabilities and worked with stakeholders toward remediation.
  • Performed web, mobile and network security assessments using industry-standard methodologies.

Always
curious.

// Sanitized public-facing work only

01 / API

API Security Notes

Authentication, authorization, business logic and defensive API design.

VIEW →
02 / WEB

VAPT Methodology

Practical testing workflows mapped to common application risks.

VIEW →
03 / MOBILE

Android Security

APK analysis, local storage, session and transport security.

VIEW →
04 / LAB

Security Experiments

Personal labs, tooling and controlled security experiments.

VIEW →

Measured by impact.

2 WKS

Early delivery on selected FY modules

0

Critical-to-medium defects at go-live on reported rollouts

5

Knowledge-sharing sessions in FY26

95%+

Target billable utilization across squads/products

AWARDBest Team AwardENBD Client
AWARDBravo AwardICICI Client
CONTRIBUTIONSecurity Knowledge SharingAPI · Wi-Fi · Security Engineering
CRT-ID

Certified Red Team Infra Developer

Offensive security & red-team infrastructure

CASA

Certified API Security Analyst

API security assessment & defense

TRAINING

AI Security Engineering

Professional security engineering training

TRAINING

Linux Thick Client Testing

Professional security testing training

Let's secure
something.

Security discussions · professional opportunities · collaborations