> INITIALIZING_PROFILE

Faiz Abdul Sukoor

$

Certified cybersecurity professional with 8 years of hands-on experience in penetration testing and vulnerability management. Proven track record in delivering successful projects across web and mobile application security, network security, cloud security, and vulnerability management. Passionate about protecting digital assets in an ever-evolving threat landscape.

Bengaluru, IndiaOSCP+ · CISSP · CRTP
Faiz Abdul Sukoor Muhamed
// about_me

The Operator Behind the Engagements

A certified cybersecurity professional turning adversarial thinking into defensible, enterprise-grade security.

Certified cybersecurity professional with 8 years of hands-on experience in penetration testing and vulnerability management. Proven track record in delivering successful projects across web and mobile application security, network security, cloud security, and vulnerability management. Passionate about protecting digital assets in an ever-evolving threat landscape.

B.Tech in Computer Science & Engineering

SCMS School of Engineering and Technology

0+Years Experience
0Certifications
0+Engagements
0+Vulnerabilities Found
faiz@cyberspace: ~ — bash
faiz@cyberspace:~$whoami
Senior Cybersecurity Consultant — 8 years offensive security
faiz@cyberspace:~$cat focus.txt
pentesting · red team · cloud security · vuln management · automation
faiz@cyberspace:~$cat mission.txt
Protecting digital assets in an ever-evolving threat landscape.
faiz@cyberspace:~$
// skills_and_expertise

Capabilities Across the Stack

Four disciplines, one cohesive offensive-to-defensive security practice.

Offensive Security

Adversarial testing across the full application and network stack.

Web Application Penetration Testing95%
Network Penetration Testing92%
Mobile Application Security Testing85%
Red Teaming88%
API Security Testing87%
// certifications

Industry-Recognized Credentials

Eight certifications spanning offensive security, red teaming, and cloud.

Elite

OSCP+

Offensive Security Certified Professional

OffSecverified
Elite

CISSP

Certified Information Systems Security Professional

ISC²verified

CRTP

Certified Red Team Professional

Altered Securityverified

eWPTX

Web Application Penetration Testing Extreme

INE / eLearnSecurityverified

MCRTA

Multi-Cloud Red Team Analyst

CyberWarFare Labsverified

CEH

Certified Ethical Hacker

EC-Councilverified

AZ-900

Microsoft Certified: Azure Fundamentals

Microsoftverified

AI-900

Microsoft Certified: Azure AI Fundamentals

Microsoftverified
// work_experience

Career Journey

Eight years of progressive offensive security roles at global consulting firms.

// featured_work

Engagements & Case Studies

Representative projects across penetration testing, red team, cloud, and automation.

Web Security

Enterprise Web App Penetration Test

Full black-box and grey-box penetration test of a Fortune-500 financial services portal. Chained an SQL injection into authenticated data exfiltration and uncovered multiple IDOR flaws, delivering a prioritized remediation roadmap.

Burp SuiteOWASP Top 10SQLiIDOR
3 critical · 8 high findings
EASM

External Attack Surface Management

Mapped and continuously monitored the external digital footprint of a global enterprise. Surfaced shadow IT, expired certificates, and exposed services across thousands of assets using Bitsight, Xpanse, and Qualys.

BitsightXpanseQualysDNS Recon
47 shadow assets discovered
Red Team

Red Team Engagement

Simulated an advanced threat-actor intrusion against a banking client. Achieved domain compromise through spear-phishing, lateral movement, and credential harvesting while mapping every step to MITRE ATT&CK.

Cobalt StrikeMITRE ATT&CKActive DirectoryPhishing
Domain Admin in 72 hours
Cloud Security

Azure & AWS Cloud Security Review

CIS-benchmark configuration review across a multi-subscription Azure tenant and AWS estate. Identified over-privileged identities, misconfigured IAM, weak logging, and publicly exposed storage.

AzureAWSCIS BenchmarkIAMNIST
68 misconfigurations remediated
Automation

Security Automation Framework

Built a Python and Power Automate pipeline integrating Nessus, Qualys, and Burp Suite APIs to auto-triage findings, deduplicate CVEs, and generate client-ready CVSS-scored reports.

PythonPower AutomateAPIsDocker
60% reduction in report time
Mobile Security

Mobile Application Security Audit

OWASP MASVS assessment of an iOS and Android banking application. Reverse-engineered the build to expose hardcoded secrets, insecure storage, and bypassed certificate pinning at runtime.

OWASP MASVSFridaMobSFBurp Suite
2 critical · 5 high findings
// by_the_numbers

Impact at a Glance

0+Years Experience
0Certifications
0+Engagements
0+Vulnerabilities Found
// get_in_touch

Let's Secure Something Together

Available for penetration testing engagements, security consulting, and red team exercises.