At Information Network Security Agency (INSA), I conduct web and Android application penetration testing, identifying issues such as insecure authentication, API misconfigurations, and data exposure. I also assist with security assessment reports and remediation recommendations.
As a security researcher at INSA, I assessed web applications and networks for organizations including Ahadu Bank, Customs Commission, Amhara Bank, and Wegagen Bank. I reported findings such as privilege escalation, database access issues, and XSS, with recommendations to improve permissions and access control.
I developed the backend for a Vulnerability Scanner API that automates web security testing using OWASP Top 10 and CVE records, and added caching to improve scanning speed. I also developed a Spring Boot backend for a maintenance mobile application and a MITM attack simulation tool for security research and testing.

