n
nizaw1

Ni Zaw

@nizaw1

Web Application Penetration Tester and API Security Specialist

Myanmar [Birma]
Engels, Russisch
Sommige informatie wordt in het Engels weergegeven.
Over mij
Dedicated Cybersecurity Analyst and Web Application Penetration Tester specializing in OWASP Top 10 vulnerabilities, API integrity mapping, and complex business logic flaws. I deeply analyze backend architectures and item quantity validations to uncover structural weaknesses automated scanners miss. I work entirely via secure chat and deliver high-quality, professional Markdown/PDF penetration testing reports with clear remediation guidance. Let's make your web systems robust and secure.... Lees meer

Skills

n
nizaw1
Ni Zaw
offline • 

Bekijk mijn diensten

Bugfixes
I will be your web application penetration tester and security auditor

Werkervaring

Upwork

Independent Application Security Researcher

Upwork • Freelance

Apr 2024 - Present2 yrs 3 mos

Conducted authorized security assessments and logic analysis on enterprise web applications. Specialized in identifying complex Business Logic Flaws, API integrity issues, and item quantity validation flaws. Responsibly disclosed vulnerabilities to help organizations improve their backend structural defense.

Self_Employed

Web Application Penetration Tester and API Security Specialist

Self Employed • Freelance

May 2020 - Present6 yrs 2 mos

Performed comprehensive web application penetration testing and vulnerability assessments within diverse target environments. Focused on mapping and exploiting technical vulnerabilities aligned with the OWASP Top 10 framework, including broken access control, injection flaws, IDOR, and severe security misconfigurations. Investigated complex technical parsing behaviors, input-handling routines, and authentication bypasses across Linux host environments and containerized backend applications. Crafted detailed, structured penetration testing documentation outlining exact exploit vectors, architectural impact assessments, and actionable mitigation blueprints. Provided reliable, zero-noise technical insights to client security teams exclusively through high-quality written reports and structured asynchronous communication channels.