At Doxso Technologies, I conducted an authorized full-scope security audit of a university platform across its web, infrastructure, API, and server configuration. I confirmed nine vulnerabilities and delivered a prioritized remediation plan.
At Syberno, I developed an LLM-based autonomous web pentesting agent and contributed to a distributed web security scanning platform with OWASP Top 10 detection modules. In independent research, I discovered a critical business logic flaw in a Padel Platform in Tunisia that enabled unlimited token generation without payment.

