Web Application Security Testing
Self-directed — OWASP WebGoat + Burp Suite
Worked through the OWASP WebGoat labs with Burp Suite in the loop, then wrote the results up the way a client would actually receive them.
Scope
A local OWASP WebGoat instance — a deliberately vulnerable application published for exactly this purpose — proxied through Burp Suite. Entirely self-hosted and self-authorised.
Findings
Completed lab exercises covering Broken Access Control, session hijacking, cookie spoofing and a range of client-side flaws, using Burp to intercept, modify and replay requests.
Reporting
Documented each finding in penetration-test report format — the vulnerability, how it was reached, the impact if exploited, and the remediation. The exercise was as much about writing a finding a developer will actually act on as about finding it.
Let's talk about the hard part.
Open to SOC Analyst, Security Analyst and Blue Team roles. Based in Dhaka, Bangladesh, and comfortable with distributed teams across time zones — I have spent three years working daily with a head office in Japan.
Open to IT Engineer, Network Engineer and Systems Infrastructure roles. Based in Dhaka, Bangladesh, and comfortable with distributed teams across time zones — I have spent three years working daily with a head office in Japan.