Ayesha Aziz
Senior Penetration Tester & Security Engineer
Experience
Senior Penetration Tester & Security Engineer
SecurityWall
ShopSecure - Vulnerability assessment and penetration testing for a European e-commerce platform serving millions of users.
Engaged as part of a 6-member red team to design and execute a full-scale application security program aligned with ISO 27001 and ISO 27034 standards.
Integrated security best practices across the SDLC, including threat modeling, secure code review, penetration testing, and continuous monitoring.
Scoped multiple domains within the client’s IT infrastructure and identified critical vulnerabilities across web, mobile, API, and cloud assets.
Delivered comprehensive security reports detailing severity levels, business impact, and prioritized remediation recommendations.
Collaborated with development teams to implement fixes, resulting in a 60% reduction in externally reported issues year-over-year.
InfraLock - Red team activity and security assessment for an online real estate marketplace based in Pakistan with 5m+ users.
Conducted internal network penetration testing and lateral movement assessment as part of a 5-member red team.
Gained initial access via exposed services, bypassed AV, escalated privileges, and compromised the Domain Controller using Mimikatz.
Delivered remediation guidance and supported patching efforts to strengthen internal defenses and reduce risk exposure.
Technologies used: Python & Bash Scripting, Metasploit Framework, Nmap, Burp Suite Professional, Wireshark, SQLMap, John the Ripper, Hydra, Aircrack-ng, Nessus, Nexpose, Acunetix, Shodan, Censys, OWASP Amass, Dirsearch, Httprobe, Postman, Cobalt Strike.
Security Analyst
Proto Global Ltd
Led end-to-end security assessments across applications, networks, and cloud environments, remediating 95% of high-risk vulnerabilities within three months.
Designed and implemented an ISO 27001-compliant ISMS and led audits to achieve SOC2, ISO 27001, and GDPR certifications.
Strengthened infrastructure and cloud security using WAF, IDS/IPS, FIM, and AWS/GCP best practices.
Conducted regular risk assessments, access reviews, and background checks to ensure policy compliance, minimize insider threats, and protect sensitive data.
Technologies used: Vanta, AWS Inspector, AWS CloudTrail, AWS GuardDuty, GCP Security Command Center, CrowdStrike, Slack, Notion, Grafana, Jira, Git.
Independent Security Researcher
Freelance
Conducted vulnerability assessments and penetration testing for platforms such as Synack, Bugcrowd, HackerOne, Intigriti, and YesWeHack.
Analyzed Android/iOS and web applications to uncover critical vulnerabilities, including hardcoded secret keys, zero click account takeovers, and logical flaws.
Scoped and evaluated infrastructure, web apps, APIs, and cloud services, resolving over 100 high-severity vulnerabilities.
Delivered detailed security reports and remediation strategies to clients, reducing security incidents by 35% within six months.
Discovered and reported highly critical vulnerabilities to renowned security teams, contributing to the mitigation of significant threats and safeguarding millions of users globally.
Technologies used: Python, Metasploit, Nessus, Burp Suite, MobSF, AWS, Wireshark, Objection, Frida, APKTool, Ghidra, Azure Security Center, Amazon Inspector, Postman.
Skills
- Cyber Security (5+ Years Of Experience)
- Python & Bash Scripting (3)
- Javascript (3)
- Penetration Testing (4+) In Web App/mobile App/api/network/active Directory/cloud/thin & Thick Client
- Vulnerability Assessment (4+)
- Red Teaming (3)
- Owasp Top 10 (4+)
- Sast (1.5)
- Dast (1.5)
- Exploit Development & Modification (4)
- Incident Response (2)
- Threat Modeling (1.5)
- Iso 27001 (1.5)
- Iso 27034 (1.5)
- Linux (4+)
- Windows (4+)
- Cobalt Strike (2)
- Metasploit (3)
- Infrastructure Security (2)
- Cryptography (1.5)
- Reverse Engineering (1)
- Security Awareness Training (2)
- Cloud Security (Azure/aws/ibm Cloud) (4)
- Container Security (Docker/kubernetes) (1.5)
- Ci/cd Security (Jenkins/gitlab) (1.5)
- Secure Devops Practices (1.5)
- Cloud Compliance (3)
Languages
Certifications & licenses
Certified Information Security Manager (CISM)
Offensive Security Certified Professional (OSCP)
Similar Freelancers
Discover other experts with similar qualifications and experience