Muhammad Shamshair, Project Manager Penetration Testing

Muhammad Shamshair

Project Manager Penetration Testing

Gulf International Bank

Location
Bahrain - Manama
Education
Bachelor's degree, Bachelor of Science in Electronics
Experience
8 years, 11 Months

Share My Profile

Block User


Work Experience

Total years of experience :8 years, 11 Months

Project Manager Penetration Testing at Gulf International Bank
  • Bahrain - Manama
  • My current job since January 2024

Working in GiB as a Project Manager Penetration Testing.
Looking all PT related activities.

Cybersecurity Technical Specialist at TAQA
  • Pakistan - Islamabad
  • September 2021 to September 2023

Worked in TAQA group as a Cybersecurity Technical Specialist and independently looked after the following activities:
o Managing application security and VA/PT related activities.
o Reviewing SOC and Threat Hunting reports periodically.
o Handling NCA & Saudi-Aramco releases.
o Vendor compliance assessment as per TAQA standards.
o Worked on NCA-ECC and SAC-021 Framework.
o Top Projects:
• Implementation of NCA controls and security solutions (MDM, EDR etc.)
• Blackbox PT and Threat Hunting.
• Compromise assessment with Loki & YARA rules.

Application Security Analyst at Telenor Microfinance Bank
  • Pakistan - Islamabad
  • September 2019 to September 2021

Worked in TMFB as a Manager Application Security in Information Security Department (Risk Division) and independently looked after the following activities:
o Security of financial app EasyPaisa.
o VAPT of Network Devices, Infrastructure, Applications (Branchless and Core Banking).
o Worked as DevSecOps, to ensure the security of architecture design and mitigate code flaws.
o Awareness and Training for the implementation of Secure-SDLC process.
o Worked in CTI (Cyber Threat Intelligence) Unit with State Bank of Pakistan (SBP) team, to mitigate the risk of security threats from outside the organization.
o VAPT of in house Private Cloud including IaaS, PaaS, SaaS and DaaS. Provided by “Ant Financial Services”.
o Support SOC (Security Operation Control) team to improve SIEM maturity.
o Delivering a range of CR assessment types including Desktop/Web/Mobile Application, APIs, Databases, 3rd party Integrations and Servers.
o Worked closely with other teams such as Infra, Network, IT Dev., Operations, Solution Architect, PD & PMO for the mitigation of organizational risk.
o Top Projects:
• VAPT of T24 Temenos (Found 3 Zero Days, which were reported to Temenos global).
• VAPT of Alibaba cloud system (Implemented by Ant Financial group, China).
• Annually PT and Compromise assessment
• Network Assessment Exercise.
• Recommended permanent solution for prevent app cloning incident for reduce the Fraud/Risk.
• Application Audits.

Information Security Manager at Government of Pakistan
  • Pakistan - Islamabad
  • February 2015 to June 2019

For a long term project worked in a semi government organization as an Information Security Manager. Lead the Security team and independently looked after the following activities:
o Bug Hunting for Mobile, OS and Web Based Applications.
o Hardware, Software, Network and Web based penetration testing for Local/Remote Area.
o Supervised R&D Team.
o Virus/Malware/Backdoor Analysis and reverse engineering
o Suggestion/Decision & Implementation for Secure Networks.
o Python scripting for automation process.
o Supervise Red Team for in-house CTF Events.

Education

Bachelor's degree, Bachelor of Science in Electronics
  • at COMSATS Institute of Information And Technology
  • January 2011

Done my Graduation in 2011. Worked on Industrial Automation Project, Wireless Security System, RF Control, Information Security, Python Programming, MCU's Programming with Robotics Development and Control, Linux based Embedded System.

Specialties & Skills

Web Application Security
Vulnerability Management
Penetration Testing
Vulnerability Assessment
Cyber Security
Web Application Penetration
Network Security
IOT Devices Penetration
Vulnerability management
INFORMATION SECURITY
Microsoft ATP (Advance Threat Protection)
Exploit Research
Embedded System
Network Penetration
Threat Hunting
Red Team
Static and Dynamic testing
Vulnerability Assessment
Penetration testing
Microsoft Azure
Applicaiton security
OT Security
Cloud security
Manual and automated testing
Vulnerability scanning
Mobile app security testing

Social Profiles

Personal Website
Personal Website

URL removed due to policy violation. Please contact support for further information.



Languages

English
Expert
French
Beginner
Urdu
Native Speaker

Memberships

ISACA
  • CISM
  • December 2023

Training and Certifications

Cisco Certified Introduction to Cybersecurity (Certificate)
Date Attended:
November 2020
Certified Network Security Specialist (CNSS) (Certificate)
Date Attended:
December 2020
Microsoft Azure Security & CISSP Modules (Learning) (Certificate)
Date Attended:
November 2022
Certified Information Security Manager (CISM) (Certificate)
Date Attended:
November 2023
Valid Until:
November 2025
Certified Appsec Practitioner (CAP) (Certificate)
Date Attended:
December 2023
Certified Ethical Hacker - CEH v10 (Certificate)
Date Attended:
December 2018

Hobbies

  • Youtube Education Videos
  • Internet Surfing
  • Book Reading
  • Chess