// cybersecurity engineer & penetration tester

Moaaz
Afifi

I combine offensive security with a developer's mindset across application security, DevSecOps, and bug bounty — and I report what I find so a developer can act on it.

  • CVE-2024-36436
  • eCPPT
  • eWPTX
  • eMAPT
  • bug hunter
get in touch see experience

open for pentest & research work

// brands through client work

Dubai Islamic Bank Oracle

whoami

I'm a cybersecurity engineer and penetration tester focused on application security, secure SDLC, and DevSecOps. I came to security from software development, and that background still shapes how I work: I read code, not just responses — an exploit makes sense when you understand what the developer intended.

My experience spans vulnerability assessment, bug bounty hunting, and penetration testing as a service — inside product teams at a technology company, and as a consultant working directly with clients.

What I keep sharpening: offensive security, web and mobile application security, secure development practices, and security research — including the security of AI-powered features.

what i do

  1. web & mobile
    penetration testing

    Scoped engagements against web applications, APIs, and Android builds. Every finding is verified by hand and documented so it can be fixed without a follow-up call.

    web / mobile / api / reporting

  2. application
    security

    Security inside product teams: secure code review, threat-informed testing across the SDLC, and working with developers rather than around them.

    appsec / ssdlc / code review

  3. devsecops

    Security moved left, where it's cheap: automated checks in the pipeline, clear findings, low friction — so fast and secure stop being competing goals.

    automation / ci / secure defaults

  4. security research
    & bug bounty

    Hunting vulnerabilities in live targets and taking them through coordinated disclosure. One of these reports became CVE-2024-36436.

    recon / vulnerability research / disclosure

  5. ai security

    Testing AI-powered features the way they're attacked: prompt and injection abuse, weak authentication in front of model endpoints, and data exposure across the new surface.

    llm applications / authentication / abuse cases

experience

  1. 2023 — present

    Cyber Security Researcher

    HackerOne part-time

    Vulnerability research and bug bounty hunting across public and private programs — web application testing, vulnerability assessment, and coordinated disclosure.

  2. feb 2025 — present

    Cyber Security Consultant & Penetration Tester

    GCC part-time

    Penetration testing and security consulting for client engagements: vulnerability assessment, research, and the technical reports findings stand on.

  3. jun 2025 — aug 2025

    Application Security Engineer

    Robusta Technology Group (RTG) full-time

    Application security within product teams — vulnerability assessment, DevSecOps, and secure development practice.

  4. oct 2023 — jan 2024

    Offensive Security Engineer

    Cybrany part-time

    Offensive security engineering and vulnerability research.

education

Computer Science & Engineering
Faculty of Electronic Engineering, Menoufia University

volunteering

Cyber Security Core Member — IEEE Menoufia University Student Branch
Arts Committee Member — FEE Student Union

skills

offensive

  • web penetration testing
  • mobile application testing
  • vulnerability assessment
  • vulnerability research
  • red teaming
  • bug bounty

defensive & process

  • application security
  • DevSecOps
  • secure SDLC
  • security consulting
  • technical reporting
  • AI security

engineering

  • JavaScript / Node.js
  • MongoDB
  • databases
  • Linux — Red Hat system administration
  • secure code review

certifications

eCPPT

Certified Professional Penetration Tester

eLearnSecurity / INE

eWPTX

Web Penetration Tester eXtreme

eLearnSecurity / INE

eMAPT

Mobile Application Penetration Tester

eLearnSecurity / INE

eAIS

AI Systems Security Specialist

eLearnSecurity / INE

get in touch

Engagements, research collaboration, or a finding on something I run — I read everything.