Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
Rao Afham Shahid, Governance Risk compliance consultant

Rao Afham Shahid

Governance Risk compliance consultant·Inbox business technologies

Pakistan

High school or equivalent, Informatics And Cybernetics

Work experience

Total years of experience: 6 years, 4 months

Governance Risk compliance consultant

December 2025 - Present

Inbox business technologies

Karachi, Pakistan

December 2025 - Present

Company industry:
Cyber & Network Security

GRC Consultant (Governance, Risk & Compliance) Intern

March 2025 - December 2025

Inbox Business Technologies:

Karachi, Pakistan

March 2025 - December 2025

• Assisted in performing risk assessments and maintaining risk registers aligned with regulatory and security
frameworks.
• Conducted gap assessments by comparing organizational policies and controls against industry standards such as
SAMA CSF, NCA ECC, CCC, and CSCC.
• Evaluated inherent and residual risks by analyzing likelihood, impact, existing controls, and treatment plans.
• Reviewed Identity & Access Management (IAM) controls including SSO with MFA, RBAC implementation, PAM
integration, and automated user provisioning/deprovisioning processes.
• Assessed control effectiveness (Preventive & Detective) and provided recommendations for remediation and
compliance improvement.
• Participated in documentation review and compliance validation to ensure alignment with regulatory
requirements.
• Supported risk treatment decisions including risk mitigation, acceptance, and documentation of corrective action
plans.
• Actively expanding knowledge in enterprise risk management, regulatory compliance, and control implementation
practices within GRC domain.

Company industry:
IT Services

Cybersecurity & Networking Intern

August 2025 - October 2025

Sindh Bank of Pakistan (IT Division]:

Karachi, Pakistan

August 2025 - October 2025

+ Gained hands-on experience with network infrastructure, including core switches, routers, firewalls, and DMZ
configurations.
+ Worked with firewall technologies (Perimeter, Data Center, Next-Gen, Palo Alto) for traffic filtering, access
control, and application-level inspection.
+ Assisted in configuring and monitoring proxy servers, Burp Suite, and firewall policies for secure traffic
management.
+ Collaborated with the SOC (Security Operations Center) team
to observe real time threat monitoring, incident
alerts, and response workflows.
+ Learned and practiced with security tools such as SIEM, SNMP, IRIS (incident Response and Investigation System),
Nikto, Wireshark, Nexpose, and SolarWinds for vulnerability assessment and network monitoring.
+ Understood enterprise network design including production & disaster recovery (OR) environments, load
balancing (VIPs), MPLS/VXLAN connectivity, and high-availability setups.
+ strengthened knowledge in web application security (WAF, SQL injection prevention, sniffing. enumeration\] and
email security protocols (SMTP, IMAP, POP3).

Company industry:
Banking

CyberSecurity & Networking Intern

August 2025 - October 2025

Sindh Bank of Pakistan (IT Division):

Karachi, Pakistan

August 2025 - October 2025

• Gained hands-on experience with network infrastructure, including core switches, routers, firewalls, and DMZ
configurations.
• Worked with firewall technologies (Perimeter, Data Center, Next-Gen, Palo Alto) for traffic filtering, access control,
and application-level inspection.
• Assisted in configuring and monitoring proxy servers, Burp Suite, and firewall policies for secure traffic
management.
• Collaborated with the SOC (Security Operations Center) team to observe real-time threat monitoring, incident
alerts, and response workflows.
• Learned and practiced with security tools such as SIEM, SNMP, IRIS (Incident Response and Investigation System),
Nikto, Wireshark, Nexpose, and SolarWinds for vulnerability assessment and network monitoring.
• Understood enterprise network design including production & disaster recovery (DR) environments, load balancing
(VIPs), MPLS/VXLAN connectivity, and high-availability setups.
• Strengthened knowledge in web application security (WAF, SQL injection prevention, sniffing, enumeration) and
email security protocols (SMTP, IMAP, POP3).

Company industry:
Banking

CyberSecurity Intern

October 2024 - August 2025

National Bank of Pakistan (Head Office):

Karachi, Pakistan

October 2024 - August 2025

• Implemented File Integrity Monitoring (FIM) using Wazuh to detect unauthorized file changes.
• Configured malware detection logic to trigger alerts and automatically delete malicious files.
• Performed vulnerability assessments to identify and patch critical exposures.
• Integrated VirusTotal API with Wazuh to enhance malware identification.
• Worked with tools like IBM QRadar and OSSIM for log correlation and event analysis.

Company industry:
Banking
Job role:
Information Technology

Final Year Project (FYP) Leader

October 2024 - August 2025

none

Karachi, Pakistan

October 2024 - August 2025

Overview: project, we built a complete cyber security monitoring system using open-source tools to help small and
medium-sized businesses (SMEs) detect and respond to cyber threats in real-time.
Key Components & What We Did:
• Wazuh Installation & Setup: Deployed Wazuh on Ubuntu to act as the SIEM (Security Information and Event
Management) system.
• Wazuh Agent Integration: Installed Wazuh agents on Windows systems to send logs and detect suspicious activity.
• File Integrity Monitoring (FIM): Set up rules to monitor critical files and folders for unauthorized changes.
• Malware Detection: Configured Wazuh to detect malicious files. Integrated it with VirusTotal API for real-time
scanning of file hashes.
• Automatic Malware Response: Built Python scripts to delete malicious files if detected by Wazuh and flagged by
VirusTotal.
• Log Analysis: Used Kibana dashboards to visualize logs, alerts, and system activities.
• Threat Hunting: Performed manual log analysis and threat investigation using Wazuh alerts.

Company industry:
Cyber & Network Security

Cybersecurity Inter

June 2025 - July 2025

Rednox - Remote:

Delhi, India

June 2025 - July 2025

+ Installed and configured WebGoat, an intentionally wuinerable
web app, to simulate real-world security attacks *
Used OWASP ZAP to intercept and scan traffic, successful identifying:
• SQL injection (SQL): Extracted sensitive data via manipulated queries.
+ Cross-Site Scripting (XSS): Executed malicious JavaScript payloads.
+ Cross-Site Request Forgery (CSRF): Created and tested CSRF PoC attacks.
+ Documented each vulnerability with screenshots, exploitation steps, and mitigation strategies.
+ Configured
Windows Defender Firewall to block high-risk ports
(e g., 23, 4444).
+ Monitored real-time traffic using Wireshark, filtered DNS/HTTP/TLS traffic, and analyzed suspicious IPs via
iplocation.net.
+ Gained practical exposure to both network-level and application-level attack prevention.

Company industry:
Cyber & Network Security

CyberSecurity Intern

June 2025 - July 2025

Rednox – Remote:

Delhi, India Remote

June 2025 - July 2025

• Installed and configured WebGoat, an intentionally vulnerable web app, to simulate real-world security atacks

Used OWASP ZAP to intercept and scan traffic, successfully identifying:
• SQL Injection (SQLi): Extracted sensitive data via manipulated queries.
• Cross-Site Scripting (XSS): Executed malicious JavaScript payloads.
• Cross-Site Request Forgery (CSRF): Created and tested CSRF PoC atacks.
• Documented each vulnerability with screenshots, exploitation steps, and mitigation strategies.
• Configured Windows Defender Firewall to block high-risk ports (e.g., 23, 4444).
• Monitored real-time traffic using Wireshark, filtered DNS/HTTP/TLS traffic, and analyzed suspicious IPs via
iplocation.net.
• Gained practical exposure to both network-level and application-level atack prevention.

Company industry:
Cyber & Network Security
Job role:
Information Technology

Project (FYP) Leader

October 2024 - January 2025

esearch & Project Iqra University:

Karachi, Pakistan

October 2024 - January 2025

tools
(Netdiscover, Spiderfoot).
+ Performed vulnerability scanning with Nikto and other scanners to detect misconfigurations and web
vulnerabiltes.
«Conducted network sniffing and traffic analysis using Wireshark; practiced social engineering to evaluate human
attack surface.
• Built and tested Android payloads (EviDroid) in controlled lab environments to assess mobile threats and improve
defenses.

Company industry:
Cyber & Network Security

Cybersecurity Intern

August 2024 - October 2024

National Bank of Pakistan (Head Office):

Karachi, Pakistan

August 2024 - October 2024

+ implemented File Integrity Monitoring (FIM) using Wazuh to detect unauthorized fle changes.
+ Configured malware detection logic ta trigger alerts and automatically delete malicious files.
+ Performed vulnerability assessments to Identify and patch critical exposures.
+ Integrated VirusTotal AP! with Wazuh to enhance malware identification.
+ Worked with tools ike 18M QRadar and OSSIM for log correlation and event analysis.

Company industry:
Banking

Valuntear / Program Coordinator

August 2020 - August 2024

RETO Foundation:

Karachi, Pakistan

August 2020 - August 2024

Contribute to RETO education and community programs including Smart Study, Self-Learners Intiative, Career
Guidance, and the Health Chapter.
+ Organized awareness campaigns, blood drives and student leadership events such as Shades Olympiad and
Independence Day Celebration.
«Supported career and skill development sessions to guide students in academic and professional planning.
«Assisted in coordination, logistics
and reporting of events across multiple educational institutions.
«Part of outreach initiatives that impacted 30, 000+ individuals across 9 cities in Pakistan.

Company industry:
Non-profit Organization

Volunteer / Program Coordinator

August 2019 - January 2020

RETO Foundation:

Karachi, Pakistan Hybrid

August 2019 - January 2020

• Contribute to RETOs education and community programs including Smart Study, Self-Learners Initiative, Career
Guidance, and the Health Chapter.
• Organized awareness campaigns, blood drives and student leadership events such as Shades Olympiad and
Independence Day Celebration.
• Supported career and skill-development sessions to guide students in academic and professional planning.
• Assisted in coordination, logistics and reporting of events across multiple educational institutions.
• Part of outreach initiatives that impacted 30, 000+ individuals across 9 cities in Pakistan.

Company industry:
Non-profit Organization
Job role:
Administration

Education

Iqra University

December 2026

December 2026

High school or equivalent, Informatics And Cybernetics

Pakistan

Iqra University

December 2026

December 2026

Bachelor's degree, Computer Science

Pakistan

lara University

July 2026

July 2026

High school or equivalent, Computer Science And Computer Networks

Pakistan

Aims College

January 2021

January 2021

High school or equivalent, Computer Science And Computer Networks

Pakistan

Aims College

January 2021

January 2021

High school or equivalent, Applied Science And Engineering

Pakistan

Bangalore Town School

January 2018

January 2018

High school or equivalent, Computer Science And Computer Networks

Pakistan

Bangalore Town School

January 2018

January 2018

High school or equivalent, Computer Science

Pakistan

Skills

ACCESS CONTROLS
Intermediate
ACCESS CONTROLS
Intermediate
COMPUTER SCIENCE
Intermediate
COMPUTER SCIENCE
Intermediate
CYBER SECURITY
Intermediate
CYBER SECURITY
Intermediate
DATA CENTERS
Intermediate
DATA CENTERS
Intermediate
DEMILITARIZED ZONES DMZ
Intermediate
DEMILITARIZED ZONES DMZ
Intermediate
FIREWALL
Intermediate
FIREWALL
Intermediate
NETWORK INFRASTRUCTURE
Intermediate
NETWORK INFRASTRUCTURE
Intermediate
NETWORK TRAFFIC ANALYSIS
Intermediate
NETWORK TRAFFIC ANALYSIS
Intermediate
PERIMETER SECURITY
Intermediate
PERIMETER SECURITY
Intermediate
PROFESSIONAL NETWORKING
Intermediate
PROFESSIONAL NETWORKING
Intermediate
AUTHENTICATIONS
Intermediate
AUTHENTICATIONS
Intermediate
BUSINESS TO BUSINESS
Intermediate
BUSINESS TO BUSINESS
Intermediate
GAP ANALYSIS
Intermediate
GAP ANALYSIS
Intermediate
GOVERNANCE
Intermediate
GOVERNANCE
Intermediate
ORGANISATIONAL POLICIES
Intermediate
ORGANISATIONAL POLICIES
Intermediate
REGULATORY COMPLIANCE
Intermediate
REGULATORY COMPLIANCE
Intermediate
RISK ANALYSIS
Intermediate
RISK ANALYSIS
Intermediate
RISK MANAGEMENT
Intermediate
RISK MANAGEMENT
Intermediate
SINGLE SIGN ON SSO
Intermediate
SINGLE SIGN ON SSO
Intermediate

Training and Certifications

Certifications
Ethical Hacking & CyberSecurity