
Mehedi Hasan
Level 2
Security Consultant at Big Four, Penetration Tester, 6 CVEs
Skills

See my services


Want to work on an hourly basis?
Tell Mehedi Hasan what you need.
$35
/
hourPortfolio
Work experience
Private
Full-time • 3 yrs 7 mos
Consultant, Cyber Security (Red Team Operations) at a Big Four consulting firm
Jul 2025 - Present • 1 yr 2 mos
Security consultant on the cyber security team of a Big Four consulting firm, delivering penetration testing and red-team operations for banks and telecom operators. What I do: • Web application, API, mobile (Android and iOS) and network penetration tests, performed by hand against OWASP WSTG, OWASP MASVS, the OWASP API Security Top 10 and PTES, with every finding verified before it is reported • Red-team operations: adversary-style campaigns across internet-facing systems and internal networks, reported as attack paths with business impact rather than isolated issues • Regulated environments: engagements scoped and documented to PCI DSS and central-bank requirements, producing evidence that auditors accept • Reporting for two audiences: executive summaries that set priorities for management, and technical findings with CVSS severity, reproduction steps, screenshots and a specific fix for each issue • Retesting and remediation support with client engineering teams until findings are closed Recognized multiple times by clients for the quality of findings and delivery.
Senior Cybersecurity Consultant at a U.S. Based Cybersecurity Firm
Apr 2024 - Present • 2 yrs 5 mos
• Conduct web, API, mobile, and cloud penetration testing to identify and validate security vulnerabilities across client environments. • Perform manual vulnerability assessment and exploitation, including authentication, authorization, business logic, injection, and API security testing. • Conduct Active Directory and internal network security assessments, identifying privilege escalation and lateral movement opportunities. • Develop detailed penetration testing reports, documenting technical findings, business impact, proof-of-concept evidence, and actionable remediation recommendations. • Collaborate directly with clients and technical teams to communicate security risks, validate remediation, and strengthen overall security posture.
Graduate Teaching Assistant, Software Security
University of Dhaka • Part-time
Dec 2023 - Jan 2026 • 2 yrs 1 mo
Teaching assistant for CSE 803 Software Security in a professional master's program in information and cyber security. • Run hands-on lab sessions on secure coding and application security testing • Guide students through practical exercises based on the industry standards used in professional engagements • Grade practical assignments and give feedback on students' testing and reporting
12 Reviews
| (12) | ||
| (0) | ||
| (0) | ||
| (0) | ||
| (0) |
Rating Breakdown
- Seller communication level
- Quality of delivery
- Value of delivery
Sort By
sakaabi

United Arab Emirates
Very humble and cooperative person… the best work, this guy is a gem.highly recommend and professional work.
garyrafferty863

United Kingdom
Mehedi Hasan EXCELS in his QA & Review work, showcasing remarkable professionalism throughout. Collaborating with him is a breeze due to his deep understanding and proactive communication, always coupled with quick responsiveness. Truly a TOP-NOTCH experience working with him! 👍
garyrafferty863

United Kingdom
Mehedi Hasan truly IMPRESSED with his work in QA & Review! His attention to details and deep understanding made the project flow smoothly, and his professionalism exceeded our expectations. Working with someone who's quick to respond and consistently goes above and beyond was a genuine pleasure. 👏
matthew_comb

New Zealand
Mehedi is very professional, good to work with. We needed a pen test turned around quickly, he was able to accommodate and also conducted retests on issues found. Would happily work with Mehedi again.
rexweston

Spain

