Book this talent

Book this talent

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Salary
1880
EOR / Payroll from
€299 month
Check availibility
Vusal
Vusal

Penetration Tester

Middle

Azerbaijan

Skills

API Testing
Cybersecurity
mobile tester
red team
web testing
penetration testing

Languages

English B1
Available for hire from
1880

Professional Summary

Candidate brings a robust background in cybersecurity, complemented by a Bachelor's degree in engineering. With a diverse professional journey, they have accumulated valuable experience in several banks, specializing as a penetration tester and vulnerability manager. Currently, they hold the position of a Lead Adversary Simulation Specialist at an MSSP (Managed Security Service Provider) company. In their role, the candidate actively contributes to helping various clients identify vulnerabilities and assess their resilience against cyberattacks. Employing advanced techniques, they play a crucial role in fortifying defenses and ensuring clients are well-prepared to combat evolving cyber threats. The candidate also holds offensive security certifications, underscoring their commitment to excellence and proficiency in offensive security strategies. These certifications further validate their expertise in employing advanced techniques to identify vulnerabilities and enhance cyber resilience. In their tenure at Cyberpoint company, the candidate specialized in red teaming for an impressive 10 months.

Education

Baku Engineering University


Certifications:


  • Zero-Point Security / Red Team Lead

  • Offsec Experienced Penetration Tester (OSEP) 

  • Offensive Security Certified Professional (OSCP) 

  • Cisco Certified Network Associate Routing and Switching (CCNA ROUTING AND

  • SWITCHING) 

Experience

Lead Adversary Simulation Specialist / Cyberpoint

January 2023 – Current

Baku, Azerbaijan


  • Plan, execute, and lead simulated cyberattacks, also known as red teaming exercises, to assess the organization's overall security posture. Simulate sophisticated, real-world attack scenarios to identify vulnerabilities and weaknesses in systems, networks, and applications.

  • Develop and refine TTPs used during adversary simulations to emulate advanced threat actors and their methodologies. Stay updated on the latest threat intelligence, attack vectors, and emerging TTPs to enhance the realism of simulations.

  • Simulate advanced persistent threat scenarios to mimic the techniques used by sophisticated adversaries, including nation-state actors or organized cybercrime groups. Mimic the attack lifecycle, from initial compromise to lateral movement and data exfiltration, to evaluate the organization's ability to detect and respond to such threats.

  • Conduct proactive threat hunting activities to identify potential indicators of compromise and detect malicious activities within the organization's network and systems. Leverage threat intelligence, log analysis, and advanced detection techniques to uncover stealthy threats that may have evaded traditional security measures.

  • Stay abreast of the evolving threat landscape and security technologies by conducting research, attending conferences, and participating in industry forums. Continuously improve methodologies, tools, and techniques used in adversary simulations to stay ahead of emerging threats.

  • I performed thorough web penetration tests using a mix of manual assessments and automated tools to uncover vulnerabilities, including but not limited to SQL injection, cross-site scripting (XSS), and insecure direct object references (IDOR). Concurrently, I took the lead in mobile security assessments, carefully examining iOS and Android applications for potential weaknesses such as insecure data storage, insufficient transport layer protection, and insecure session management. Furthermore, I conducted detailed API penetration testing, addressing concerns such as broken authentication and inadequate data validation to enhance overall system security.




Penetration Tester / Xalq Bank

February 2022 – January 2023 

Baku, Azerbaijan


  • Plan, execute, and document penetration testing activities, including both internal and external assessments. Simulate real-world attacks to identify vulnerabilities and exploit them ethically to gain unauthorized access to systems.

  • Assess the potential impact of identified vulnerabilities and prioritize them based on their severity and the potential risks they pose to the organization's systems, data, and infrastructure.

  • Perform comprehensive vulnerability assessments of computer systems, networks, and applications to identify potential security weaknesses or vulnerabilities.

  • Plan, execute, and document security testing activities specifically focused on mobile applications. Identify vulnerabilities such as insecure data storage, inadequate authentication mechanisms, insecure communication channels, and other mobile-specific risks.

  • I performed thorough web penetration tests using a mix of manual assessments and automated tools to uncover vulnerabilities, including but not limited to SQL injection, cross-site scripting (XSS), and insecure direct object references (IDOR). Concurrently, I took the lead in mobile security assessments, carefully examining iOS and Android applications for potential weaknesses such as insecure data storage, insufficient transport layer protection, and insecure session management. Furthermore, I conducted detailed API penetration testing, addressing concerns such as broken authentication and inadequate data validation to enhance overall system security.




Penetration Tester / Industry Bank

August 2021 – February 2022 

Baku, Azerbaijan


  • Plan, execute, and document penetration testing activities, including both internal and external assessments. Simulate real-world attacks to identify vulnerabilities and exploit them ethically to gain unauthorized access to systems.

  • Assess the potential impact of identified vulnerabilities and prioritize them based on their severity and the potential risks they pose to the organization's systems, data, and infrastructure.

  • Perform comprehensive vulnerability assessments of computer systems, networks, and applications to identify potential security weaknesses or vulnerabilities.

  • I performed thorough web penetration tests using a mix of manual assessments and automated tools to uncover vulnerabilities, including but not limited to SQL injection, cross-site scripting (XSS), and insecure direct object references (IDOR). Concurrently, I took the lead in mobile security assessments, carefully examining iOS and Android applications for potential weaknesses such as insecure data storage, insufficient transport layer protection, and insecure session management. Furthermore, I conducted detailed API penetration testing, addressing concerns such as broken authentication and inadequate data validation to enhance overall system security.




Penetration Tester / Kapital Bank

January 2021 - August 2021

Baku, Azerbaijan


  • Plan, execute, and document penetration testing activities, including both internal and external assessments. Simulate real-world attacks to identify vulnerabilities and exploit them ethically to gain unauthorized access to systems.

  • Assess the potential impact of identified vulnerabilities and prioritize them based on their severity and the potential risks they pose to the organization's systems, data, and infrastructure.

  • Perform comprehensive vulnerability assessments of computer systems, networks, and applications to identify potential security weaknesses or vulnerabilities.

  • I performed thorough web penetration tests using a mix of manual assessments and automated tools to uncover vulnerabilities, including but not limited to SQL injection, cross-site scripting (XSS), and insecure direct object references (IDOR). Concurrently, I took the lead in mobile security assessments, carefully examining iOS and Android applications for potential weaknesses such as insecure data storage, insufficient transport layer protection, and insecure session management. Furthermore, I conducted detailed API penetration testing, addressing concerns such as broken authentication and inadequate data validation to enhance overall system security.

Talent Pool

Available talents

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Abdelsabor
Java Developer
Senior
Egypt
Oracle
MySQL
Spring
Spring Boot
Java
Backend
Egypt
Developers
€ 31 - € 40
€3000 - €5000
English
Nino
Sales Representative
Senior
Georgia
Account Management
OutBound Sales
Inbound Sales
Sales
Sales and Account
Georgia
Sales Experts
€ 21 - € 30
€3000 - €5000
English
Russian
German
Spanish
irine
Marketing Manager
Senior
Georgia
C
Canva
design
Digital marketing
Google Ads
Marketing and Communication
Georgia
Marketers
€ 21 - € 30
€1000 - €3000
English
Lilia
Sales Representative
Senior
Armenia
Interpersonal Communication
Invoice Management
Account Management
Customer Support
OutBound Sales
Sales and Account
Operations
Armenia
Sales Experts
€ 20 and below
€1000 - €3000
English
Russian
French
Solomon
3D Artist
Middle
Georgia
Content Creation
Motion Design
3D Design
Content
Design
Georgia
Designers
€ 20 and below
€1000 - €3000
English
Ana
Content Manager
Senior
Georgia
copywriter
Content
Social media
Marketing and Communication
Georgia
Marketers
€ 21 - € 30
€1000 - €3000
English
French
Russian

Don't see the profile you need right now?

Tell us what you need — we'll find and vet a match within 48 hours.
Request a custom search →