Security & Offensive (authorized)
- Penetration Testing, Vulnerability Scanning
- Exploit/Recon Automation, WAF evasion testing (authorized)
- Threat Modeling, Security Awareness/Phishing Simulation
- System Hardening
Fars, Iran • (+98) 902 055 0525 • [email protected]
Open to relocation • Hybrid/Remote
Security-focused Software & Cybersecurity Engineer with an analytical mind and 4+ years of experience in authorized penetration testing, exploit automation, and infrastructure hardening. Certified LPIC-1/2/303 with expertise in Linux systems, bug bounty workflows, and Python/Go-based security tools. Proven at driving measurable risk reduction across enterprise apps and cloud/Kubernetes platforms. Bridges dev and security to build robust, scalable, attack-resilient systems.
Shiraz, Iran • Jan 2024 – Present
Tehran, Iran • Sep 2022 – Dec 2023
Tehran, Iran • Nov 2021 – Aug 2022
Tehran, Iran • Mar 2019 – Apr 2020
Apr 2020 – Nov 2021
Stack: Python, Playwright, PostgreSQL
Automated crawling and CVE testing for enterprise systems, integrated with alerting.
Built toolset to evaluate WAF protections across internal systems, reducing bypass testing effort by 50%.
Stack: Go & Python
Automated subdomain enumeration, path discovery, and exploit testing.
Linux Professional Institute
ActiveLinux Professional Institute
ActiveLinux Professional Institute
ActiveSecurity Certification
ActiveAmazon Web Services
ActiveWeb Application Vulnerabilities
ActivePersian (Native) • English (Professional/Fluent) • German (A1) • Japanese (Basic) • Spanish (Basic)
B.Sc., Computer Science / IT — in progress • Elmi-Karbordi, Qaemshahr, Iran
Expected graduation: 2027