Ayesha Aziz

Senior Penetration Tester & Security Engineer

Avatar placeholder
Lahore, Pakistan

Experience

Feb 2022 - Present
4 years
Islamabad, Pakistan

Senior Penetration Tester & Security Engineer

SecurityWall

  • ShopSecure - Vulnerability assessment and penetration testing for a European e-commerce platform serving millions of users.

  • Engaged as part of a 6-member red team to design and execute a full-scale application security program aligned with ISO 27001 and ISO 27034 standards.

  • Integrated security best practices across the SDLC, including threat modeling, secure code review, penetration testing, and continuous monitoring.

  • Scoped multiple domains within the client’s IT infrastructure and identified critical vulnerabilities across web, mobile, API, and cloud assets.

  • Delivered comprehensive security reports detailing severity levels, business impact, and prioritized remediation recommendations.

  • Collaborated with development teams to implement fixes, resulting in a 60% reduction in externally reported issues year-over-year.

  • InfraLock - Red team activity and security assessment for an online real estate marketplace based in Pakistan with 5m+ users.

  • Conducted internal network penetration testing and lateral movement assessment as part of a 5-member red team.

  • Gained initial access via exposed services, bypassed AV, escalated privileges, and compromised the Domain Controller using Mimikatz.

  • Delivered remediation guidance and supported patching efforts to strengthen internal defenses and reduce risk exposure.

  • Technologies used: Python & Bash Scripting, Metasploit Framework, Nmap, Burp Suite Professional, Wireshark, SQLMap, John the Ripper, Hydra, Aircrack-ng, Nessus, Nexpose, Acunetix, Shodan, Censys, OWASP Amass, Dirsearch, Httprobe, Postman, Cobalt Strike.

Mar 2020 - Jan 2022
1 year 11 months
Canada

Security Analyst

Proto Global Ltd

  • Led end-to-end security assessments across applications, networks, and cloud environments, remediating 95% of high-risk vulnerabilities within three months.

  • Designed and implemented an ISO 27001-compliant ISMS and led audits to achieve SOC2, ISO 27001, and GDPR certifications.

  • Strengthened infrastructure and cloud security using WAF, IDS/IPS, FIM, and AWS/GCP best practices.

  • Conducted regular risk assessments, access reviews, and background checks to ensure policy compliance, minimize insider threats, and protect sensitive data.

  • Technologies used: Vanta, AWS Inspector, AWS CloudTrail, AWS GuardDuty, GCP Security Command Center, CrowdStrike, Slack, Notion, Grafana, Jira, Git.

Mar 2019 - Present
6 years 11 months

Independent Security Researcher

Freelance

  • Conducted vulnerability assessments and penetration testing for platforms such as Synack, Bugcrowd, HackerOne, Intigriti, and YesWeHack.

  • Analyzed Android/iOS and web applications to uncover critical vulnerabilities, including hardcoded secret keys, zero click account takeovers, and logical flaws.

  • Scoped and evaluated infrastructure, web apps, APIs, and cloud services, resolving over 100 high-severity vulnerabilities.

  • Delivered detailed security reports and remediation strategies to clients, reducing security incidents by 35% within six months.

  • Discovered and reported highly critical vulnerabilities to renowned security teams, contributing to the mitigation of significant threats and safeguarding millions of users globally.

  • Technologies used: Python, Metasploit, Nessus, Burp Suite, MobSF, AWS, Wireshark, Objection, Frida, APKTool, Ghidra, Azure Security Center, Amazon Inspector, Postman.

Skills

  • Cyber Security (5+ Years Of Experience)
  • Python & Bash Scripting (3)
  • Javascript (3)
  • Penetration Testing (4+) In Web App/mobile App/api/network/active Directory/cloud/thin & Thick Client
  • Vulnerability Assessment (4+)
  • Red Teaming (3)
  • Owasp Top 10 (4+)
  • Sast (1.5)
  • Dast (1.5)
  • Exploit Development & Modification (4)
  • Incident Response (2)
  • Threat Modeling (1.5)
  • Iso 27001 (1.5)
  • Iso 27034 (1.5)
  • Linux (4+)
  • Windows (4+)
  • Cobalt Strike (2)
  • Metasploit (3)
  • Infrastructure Security (2)
  • Cryptography (1.5)
  • Reverse Engineering (1)
  • Security Awareness Training (2)
  • Cloud Security (Azure/aws/ibm Cloud) (4)
  • Container Security (Docker/kubernetes) (1.5)
  • Ci/cd Security (Jenkins/gitlab) (1.5)
  • Secure Devops Practices (1.5)
  • Cloud Compliance (3)

Languages

Urdu
Native
English
Advanced

Certifications & licenses

Certified Information Security Manager (CISM)

Offensive Security Certified Professional (OSCP)

Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions

Similar Freelancers

Discover other experts with similar qualifications and experience

Muhammad Daniyal
Muhammad Daniyal

Senior Penetration Tester

View Profile
Syed ghazanfar Abbas
Syed ghazanfar Abbas

Information Security Consultant

View Profile
Niels Aerts
Niels Aerts

Azure Architect

View Profile
Stefan Radushev
Stefan Radushev

ISO27001 Certification

View Profile
Alexander Nagy
Alexander Nagy

Security Expert

View Profile
Mohit Dabas
Mohit Dabas

Senior Security Technologist

View Profile
Rick Grassmann
Rick Grassmann

Interim IT Security Analyst

View Profile
Obad Zafar
Obad Zafar

Cybersecurity Trainer

View Profile
Seyed farhad Miri
Seyed farhad Miri

Senior Product Security Engineer

View Profile
Maryam Mouzarani
Maryam Mouzarani

AI Red Team Engineer

View Profile
Erlijn Van genuchten
Erlijn Van genuchten

Science communicator and change manager

View Profile
Ali Yazdani
Ali Yazdani

Principal Product Security Engineer

View Profile
Sokol Çavdarbasha
Sokol Çavdarbasha

Cybersecurity Engineer

View Profile
Valeri Milke
Valeri Milke

Associate Partner - Information Security Consulting

View Profile
Kazim Rizvi
Kazim Rizvi

Principal Security Architect - Contract Hands on

View Profile
Pierre Gronau
Pierre Gronau

Ansible Automation, Windows Third Level Support

View Profile
Sascha Leitner
Sascha Leitner

CEO

View Profile
Benedek Galácz
Benedek Galácz

CTO/CISO

View Profile
Ahmad Moaaz
Ahmad Moaaz

Senior Security Consultant

View Profile
Udayan Sarkar
Udayan Sarkar

Head – IT Infrastructure & Cyber Security

View Profile
Markus Willems
Markus Willems

KRITIS Consultant

View Profile
Mallikharjun Swamy
Mallikharjun Swamy

Bug Bounty Hunter | Cybersecurity Researcher | Pentester

View Profile
Matthias Steinmann
Matthias Steinmann

Senior Consultant Security (freelance)

View Profile
Patrick Beck
Patrick Beck

AML Officer

View Profile
Christian Decker
Christian Decker

Managing Director and Senior Consultant

View Profile
Zeeshan Adil
Zeeshan Adil

Sanad Chat-Based Application for Search & Rescue Ops

View Profile
Daniel Kaguongo
Daniel Kaguongo

ISMS Risk Tracker & Compliance Portal (Streamlit + PostgreSQL)

View Profile
Bernhard Bowitz
Bernhard Bowitz

Senior Security Architect

View Profile
Uzair Anwar
Uzair Anwar

Senior Software Engineer

View Profile
Henryk Orantek
Henryk Orantek

Security Consultant

View Profile