// cybersecurity engineer & penetration tester
Moaaz
Afifi
I combine offensive security with a developer's mindset across application security, DevSecOps, and bug bounty — and I report what I find so a developer can act on it.
- CVE-2024-36436
- eCPPT
- eWPTX
- eMAPT
- bug hunter
// brands through client work
whoami
I'm a cybersecurity engineer and penetration tester focused on application security, secure SDLC, and DevSecOps. I came to security from software development, and that background still shapes how I work: I read code, not just responses — an exploit makes sense when you understand what the developer intended.
My experience spans vulnerability assessment, bug bounty hunting, and penetration testing as a service — inside product teams at a technology company, and as a consultant working directly with clients.
What I keep sharpening: offensive security, web and mobile application security, secure development practices, and security research — including the security of AI-powered features.
what i do
-
web & mobile
penetration testingScoped engagements against web applications, APIs, and Android builds. Every finding is verified by hand and documented so it can be fixed without a follow-up call.
-
application
securitySecurity inside product teams: secure code review, threat-informed testing across the SDLC, and working with developers rather than around them.
-
devsecops
Security moved left, where it's cheap: automated checks in the pipeline, clear findings, low friction — so fast and secure stop being competing goals.
-
security research
& bug bountyHunting vulnerabilities in live targets and taking them through coordinated disclosure. One of these reports became CVE-2024-36436.
-
ai security
Testing AI-powered features the way they're attacked: prompt and injection abuse, weak authentication in front of model endpoints, and data exposure across the new surface.
writing
sep 14, 2026
Fuzz the type, not just the value
A one-line habit that keeps finding authorization bugs — swap the type, not just the payload.
dec 20, 2024
From Comments to Command Execution: How an E-Book Platform Gave Me RCE
Stored XSS in a comments feature became unrestricted file upload, and a PHP shell stitched into a PNG became remote code execution.
dec 5, 2024
From Frustration to Exploitation: How a Link Shortener Helped Me Bypass WAF
A 403 wall around a search box — and a built-in link shortener that turned out to be the road around it.
experience
-
2023 — present
Cyber Security Researcher
HackerOne part-time
Vulnerability research and bug bounty hunting across public and private programs — web application testing, vulnerability assessment, and coordinated disclosure.
-
feb 2025 — present
Cyber Security Consultant & Penetration Tester
GCC part-time
Penetration testing and security consulting for client engagements: vulnerability assessment, research, and the technical reports findings stand on.
-
jun 2025 — aug 2025
Application Security Engineer
Robusta Technology Group (RTG) full-time
Application security within product teams — vulnerability assessment, DevSecOps, and secure development practice.
-
oct 2023 — jan 2024
Offensive Security Engineer
Cybrany part-time
Offensive security engineering and vulnerability research.
-
apr 2022 — sep 2022
Software Engineer
كالبنيان المرصوص internship
Full-stack JavaScript development on the MERN stack — where the developer's mindset started.
education
Computer Science & Engineering
Faculty of Electronic Engineering, Menoufia University
volunteering
Cyber Security Core Member — IEEE Menoufia University Student Branch
Arts Committee Member — FEE Student Union
skills
offensive
- web penetration testing
- mobile application testing
- vulnerability assessment
- vulnerability research
- red teaming
- bug bounty
defensive & process
- application security
- DevSecOps
- secure SDLC
- security consulting
- technical reporting
- AI security
engineering
- JavaScript / Node.js
- MongoDB
- databases
- Linux — Red Hat system administration
- secure code review
certifications
eCPPT
Certified Professional Penetration Tester
eLearnSecurity / INE
eWPTX
Web Penetration Tester eXtreme
eLearnSecurity / INE
eMAPT
Mobile Application Penetration Tester
eLearnSecurity / INE
also: red hat system administration I (MaharaTech/ITI) / IBM — delivering quality work with agility / microsoft azure responsible AI / database fundamentals (Almdrasa) / full-stack node.js (Zero To Mastery)
get in touch
Engagements, research collaboration, or a finding on something I run — I read everything.