Mohamed sayed, Security Researcher

Mohamed sayed

Security Researcher

Synack Red Team

البلد
مصر - القاهرة
التعليم
دبلوم عالي, Information Security Diploma
الخبرات
13 years, 10 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :13 years, 10 أشهر

Security Researcher في Synack Red Team
  • مصر - القاهرة
  • أشغل هذه الوظيفة منذ أكتوبر 2016

Freelancer Security researcher and bug bounty hunter for Synack Clients
• Research in the areas of Mobile, Web applications and Host security assessments
• Provide solid reports and exploits to prove the existence of the vulnerabilities, steps for reproduction and possible ways of exploitations.

Senior Information Security consultant في SecureMisr
  • مصر - القاهرة
  • أشغل هذه الوظيفة منذ أكتوبر 2017

Hold responsibility for managing a variety of information security projects for a diverse range of corporations.Utilize strong business and technology acumen to effectively do penetration testing for complex systems and troubleshoot complex problems.
• Client Services:
1. Conduct continuous penetration testing, targeting technology vulnerabilities utilizing web, mobile, desktop applications, source code, architecture review and Network penetration testing to achieve successful problem resolution. Providing recommended methods for vulnerability remediation and best practise controls.

2. Hold Secure Coding trainings.
3. Hold Web and mobile application penetrating testing trainings.
• Project Management: Research and review high profile client security needs, assisting with e-banking, mobile banking, e-trade applications, electronic payments applications, and online banking needs for commercial banks, telecom corporations and international services.
• Security Assessment: Achieved cost savings for commercial banking locations, and multi-national telecom companies, reducing data breaches and preventing fraud, resulting in operational growth.

Senior Information Security analyst في EG-Bank
  • مصر - القاهرة
  • أغسطس 2016 إلى أكتوبر 2017

-Penetration testing and Application Security Consultation for In-house SW Development -Integrate Security during SDLC (Threat modelling - Security goals -Risk assessment -Security requirements - Secure Design review - Secure coding based on best practice implementation - Penetration testing - Secure deployment) for Core banking applications and next generation of mobile payment and invisible payment solutions (mobile banking, E-Wallet, Soft token.etc)
-Network/Infrastructure vulnerability assessment and penetration testing
-Providing recommended methods for vulnerability remediation and best practice controls.
-Incident handling
-Forensic investigation
-SIEM administration/configuration and fine tuning
-Security Awareness/Training for information security and potential threats
-evaluate third party solutions
-Implement ISMS based on ISO 27001(gab analysis - SOA -Threads/vulnerabilities definition - Risk assessment-Mitigation plan)

Mobile Team leader & Application Security Consultant في International Turnkey Systems (ITS)
  • مصر - القاهرة
  • مارس 2016 إلى يوليو 2016

-Working in R&D department -Mobile banking unit
-integrating information security into The SDLC
-implement applications requirements -perform code auditing and security penetration testing
-Penetration testing for the core banking applications/Mobile banking solutions

Mobility team leader & Info. Security Consultant - Act as defense unit head في Wind Technologies
  • مصر - القاهرة
  • يونيو 2013 إلى مارس 2016

I’m leading the Mobile development team to deliver secure Mobile based systems, participating in R&D activates related to defense technologies and payments, Design and implement new projects and requirements.
-Integrate Security in SDLC
-Implement /deliver sensitive and high profile solutions
for Banking, Military and crisis management, government sectors
like (mPOS, E-Voucher, C4i, Boarder control ...and many more)

Senior Android Sw Engineer - freelancer في Smaris
  • مصر - القاهرة
  • ديسمبر 2012 إلى يوليو 2013

I worked with a team to generate a new concepts in smaris, and also I was responsible for designing and implementing the Software arch. And help junior developers in technical issues, analysis application requirements, divide it into tasks and determined deadlines for each

Security SW Engineer في Reserved Officer
  • مصر - القاهرة
  • أبريل 2011 إلى يوليو 2013

-Focus on securing information and systems.
-Work with a team to implement very sophisticated solutions for the military field.
-Addressing information security during SDLC .
-Perform Vulnerability assessments and penetration testing for web applications.

Software engineer في Parfield
  • مصر - القاهرة
  • أغسطس 2010 إلى أبريل 2011

Participating in Android framework customization and custom ROMs for a well-known vendors like HTC and Samsung, By Framework mirroring and Arabic keyboards development

الخلفية التعليمية

دبلوم عالي, Information Security Diploma
  • في AAST
  • مايو 2017

Studying Info. sec diploma (CCSU-ECSS-CEH-ENSA-ECSA-CHFI)

بكالوريوس, Telecommunication and Electronics department
  • في faculty of engineering helwan uni
  • مايو 2010

Specialties & Skills

Application Security
Secured Transactions
Vulnerability Assessment
Penetration Testing
Software Development
Security Implementation
Mobile applications Penetration tester
C4I Military systems
Voip systems
Banking applications
Vulnerabilities assessment
Android development
Mobile Payment applications
Ethical hacking
Web application Penetration Testing (OWASP)

اللغات

الانجليزية
متوسط
العربية
متمرّس

التدريب و الشهادات

OSCP (تدريب)
معهد التدريب:
Offensive Security
تاريخ الدورة:
July 2018
Application Security specialist (تدريب)
معهد التدريب:
IBM
C|SCU (تدريب)
معهد التدريب:
ECCouncil
E|NSA (تدريب)
معهد التدريب:
ECCouncil
C|EH (تدريب)
معهد التدريب:
ECCouncil
ISO 27032 Lead cyber security manager (تدريب)
معهد التدريب:
PECB
ISO 27001 Lead implementer (تدريب)
معهد التدريب:
PECB
ECSS ( Certified Security Specialist) (تدريب)
معهد التدريب:
ECCouncil
Offensive Security (تدريب)
معهد التدريب:
self
Golden Codility Award (الشهادة)
تاريخ الدورة:
November 2015
صالحة لغاية:
November 2017
Secure Coding (تدريب)
معهد التدريب:
Secure Misr
تاريخ الدورة:
June 2015
Usable Security (تدريب)
معهد التدريب:
Coursera
CEH9 (تدريب)
معهد التدريب:
EC-Council
Cryptography (تدريب)
معهد التدريب:
Coursera
Software Security (تدريب)
معهد التدريب:
Coursera

الهوايات

  • sport
  • Gym