Skip to main content
Danish UserDU
Open to opportunities

Danish User

@danishuser7

I uncover exploitable web, mobile, and API vulnerabilities to harden real-world attack surfaces.

Pakistan
Message

What I'm looking for

I'm seeking a Penetration Tester or Application Security role where I can apply proven vulnerability discovery, manual exploitation, and clear remediation reporting to directly harden an organisation's attack surface.

I'm currently delivering vulnerability assessments and SOC operations for the Federal Board of Revenue through Trillium Information Security Systems. I validate scanner findings across infrastructure, web applications, and network services, prioritise risk with CVSS v3.1, and support remediation through retest.

As an independent security researcher, I've found and responsibly disclosed high- and medium-severity IDOR, XSS, SQL injection, and authentication-bypass vulnerabilities through YesWeHack and Bugcrowd. My manual testing with Burp Suite focuses on broken access control, session flaws, business logic abuse, and input validation weaknesses that automated scanners miss.

I've built Python reconnaissance workflows that combine subdomain enumeration, DNS resolution, port scanning, and HTTP probing to improve asset discovery. My hands-on projects also include a black-box mobile banking assessment, SSL-pinning bypass, and a virtualised Active Directory lab covering Kerberoasting, credential dumping, lateral movement, and privilege escalation.

I write reproducible reports with working PoCs, root-cause analysis, business impact, and prioritised remediation guidance mapped to OWASP and MITRE ATT&CK. I bring LPT, CPENT, eCPPT, CEH, CHFI, and eJPT certifications alongside secure development experience with Laravel, MySQL, and JavaScript.

Experience

Work history, roles, and key accomplishments

TS
Current

Cybersecurity Analyst

Trillium Information Security Systems

May 2026 - Present (4 months)

Conducts recurring vulnerability assessments across infrastructure and web applications, manually validating scanner output to eliminate false positives. Monitors and triages SIEM alerts as part of daily SOC operations, supporting incident response and producing vulnerability assessment reports.

Education

Degrees, certifications, and relevant coursework

Capital University of Science and Technology logoCT

Capital University of Science and Technology

Bachelor of Science, Software Engineering

2020 - 2024

Grade: 3.12/4.00

Activities and societies: Relevant coursework included Information Security, Computer Networking, Operating Systems, Database Systems, Data Structures, Object-Oriented Programming, and Artificial Intelligence.

Bachelor of Science in Software Engineering with a focus on information security and computer networking. Achieved a CGPA of 3.12 out of 4.00.

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan