Skip to main content
zakaria haiouaniZH
Open to opportunities

zakaria haiouani

@zack999

I uncover critical web and API vulnerabilities through authorized offensive security research.

Indonesia
Message

What I'm looking for

I'm seeking a remote Application Security Engineer or Web Penetration Tester role, ideally full-time or long-term contract, where I can perform authorized offensive security work and help teams validate and remediate critical web and API risks.

I've delivered 150+ rewarded vulnerability findings across 30+ authorized programs, including Remote Code Execution in production at ByteDance, email-spoofing misconfiguration reported to Google VRP, and zero-click account takeover at OpenTable.

Since 2024, I've led web application and infrastructure penetration tests at ITR Connect B.V., finding RCE, API misconfigurations exposing company data, Plesk zero-authentication access, stored XSS, and server misconfigurations in production systems. I validate remediation through structured retest cycles and focus on account takeover, broken access control, payment and KYC bypasses, OAuth, CSRF, and API security.

I also maintain open-source security tools and vulnerable labs through hackerz.space and zack0x01, with 750+ GitHub stars, and share bug bounty methodology and web-security walkthroughs through my YouTube channel.

Experience

Work history, roles, and key accomplishments

IB
Current

Penetration Tester

ITR Connect B.V.

Jan 2024 - Present (2 years 7 months)

Lead web application and infrastructure penetration tests on bespoke CRM, ERP, and business platforms (Laravel/PHP) across the agency client pipeline. Discovered remote code execution, API misconfiguration exposing full company data, and Plesk zero-authentication access in production systems.

zack0x01 logoZA
Current

Security Educator & Open-Source Maintainer

zack0x01

Jan 2020 - Present (6 years 7 months)

Maintains hackerz.space, a full vulnerable-lab environment and cybersecurity penetration-testing platform with hands-on labs, academy, and research blog. Developed open-source tools including Recox, JS-Analyser, and CVE-2025-55182 Advanced Scanner, and runs a YouTube channel for security education.

HackerOne logoHA
Current

Application Security Researcher

Apr 2019 - Present (7 years 4 months)

150+ rewarded submissions across 30+ authorized programs with 80+ public disclosures (40+ Critical, 60+ High). Found Remote Code Execution (RCE) in production on ByteDance; reported SMTP-misconfiguration email spoofing to Google VRP; zero-click account takeover on OpenTable; critical BAC on Hostinger.

Education

Degrees, certifications, and relevant coursework

UA

University of Algeria

Bachelor's Degree, Languages

Pursued a Bachelor's Degree in Languages for two years before leaving to focus on offensive security full-time.

Tech stack

Software and tools used professionally

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan