a
aisha9690

Ayesha Rahman

@aisha9690

Senior Cyber Security Analyst

Verenigd Koninkrijk
Engels, Urdu
Sommige informatie wordt in het Engels weergegeven.
Over mij
CEH and CySA+ certified Ethical Hacker & Penetration Tester (6+ yrs) helping businesses discover vulnerabilities before attackers do. I specialize in webApp pentesting, network security assessments, API testing, WordPress security, and manual vulnerability analysis using industry-standard methodologies (OWASP, NIST, PTES). I provide clear reports, reproducible PoC, risk ratings, and prioritized remediation steps. I deliver actionable findings, not auto‑scanner noise. • Black‑box / Grey‑box testing • Manual testing (no dependency on automated tools) • Secure Code Review (optional add‑on)... Lees meer

Skills

a
aisha9690
Ayesha Rahman
offline • 
Gemiddelde reactietijd: 1 uur

Bekijk mijn diensten

Bugfixes
I will perform manual and automatic penetration testing for your website with report

Werkervaring

Confidentials

Penetration Tester (6+ yrs experience)

Confidentials • Fulltime

Nov 2019 - Jan 20266 yrs 2 mos

Performed full‑scope penetration testing across web apps, APIs, internal/external networks, and enterprise infrastructure. Completed 100+ engagements identifying critical vulnerabilities, including authentication bypasses, privilege escalation paths, and full Active Directory compromises. Delivered clear reports, PoC evidence, and prioritized fixes to technical teams and senior leadership. Managed continuous security assessments for 1000+ assets using Nessus/OpenVAS. Validated 50+ new vulnerabilities monthly and prepared executive‑level security reports. Contributed to security policy development and provided cross‑team training in basic penetration testing and hardening. Key highlights: 70+ web app pentests following OWASP/NIST standards 50+ network pentests across 900+ node environments Identified high‑risk API flaws preventing major PII exposure Built Python automation to reduce testing time by 60% Led a 3‑member pentest team, ensuring 100% on‑time delivery Supported incident response, malware analysis, & threat monitoring