
Sohaib
Information Security Expert, VAPT, CISM, IS Auditor, Incident Response
Skills

Bekijk mijn diensten

Portfolio
Werkervaring
Cyber Security Architect
Confidentials
Apr 2018 - Present • 8 yrs 5 mos
Professional Experience Information Security Architect | May 2018 – Present * Design and assess enterprise information security architecture, controls, and security processes. * Conduct VAPT for web applications, APIs, networks, and infrastructure. * Perform manual and automated security testing covering authentication, authorization, session management, APIs, input validation, business logic, access control, and security configuration. * Identify and validate vulnerabilities using controlled PoC techniques while minimizing false positives. * Prepare professional security reports with technical evidence, severity, business impact, OWASP/CWE mapping, and remediation guidance. * Design and improve SOC workflows for security monitoring, incident detection, investigation, and response. * Work with SIEM and security technologies including IBM QRadar, Wazuh, Splunk, firewalls, and endpoint security solutions. * Apply MITRE ATT&CK and Cyber Kill Chain methodologies for threat analysis and incident investigation. * Conduct security architecture reviews and threat modeling using STRIDE, PASTA, NIST CSF, and ISO 27001. * Develop risk-based vulnerability scoring and prioritization approaches. Selected Projects Web Application & API Penetration Testing: * Assessed modern web applications and APIs for authentication weaknesses, authorization flaws, business-logic vulnerabilities, injection risks, API security issues, rate-limit weaknesses, and payment-flow vulnerabilities. * Delivered detailed penetration-testing reports with reproducible PoCs and actionable remediation. Automated Vulnerability Assessment Platform: * Designed an agentless security assessment platform covering reconnaissance, crawling, endpoint discovery, parameter analysis, vulnerability testing, validation, and automated reporting. Developed multiple testing strategies aligned with OWASP, SANS, penetration testing, vulnerability assessment, SSL/TLS, CMS, and deep-scan requirements.