
M Ibrahim Zafar
Application Security Expert
Skills

See my services


Portfolio
Work experience
Confidentials
Full-time • 3 yrs 9 mos
Assistant Manager Application Security
Jul 2026 - Present • 1 mo
1. Collaborate with development, DevOps, and engineering teams to integrate secure coding practices and security controls throughout the Software Development Life Cycle (SDLC). 2. Perform threat modeling, secure code reviews, penetration testing, and vulnerability validation while providing risk-based remediation recommendations. 3. Manage application security programs by defining security standards, tracking remediation efforts, ensuring compliance with industry frameworks, and reporting security metrics to stakeholders.
Penetration tester
Jun 2024 - Jul 2026 • 2 yrs 1 mo
1. Specialize in Application Security, implementing OWASP ASVS Level 3 controls on web applications to ensure robust security standards. 2. Conduct penetration testing for web applications, mobile applications, and SDKs, identifying and remediating critical vulnerabilities. 3. Experienced with CEN TS 18099 and ETSI TS 119 461, focusing on data injection, presentation attacks, and stream injection threats, and assessing system resilience against such attack vectors. 4. Familiar with ISO/IEC 27001 and SOC 2 standards, contributing to compliance, risk assessment, and security governance processes. 5. Perform endpoint monitoring and threat detection using Wazuh and Google Workspace security tools to identify suspicious activity and security incidents. 6. Collaborate with development teams to secure the SDLC (Secure Software Development Life Cycle) by integrating security best practices, controls, and testing methodologies. 7. Provide actionable security recommendations, detailed vulnerability reports, and hands-on support for implementing effective mitigations and long-term security improvements.
Penetration Tester (ITLAY base company)
Jan 2023 - Aug 2024 • 1 yr 7 mos
1. Conduct Web Application, API, and Mobile Application Penetration Testing. 2. Identify and validate critical vulnerabilities, including Account Takeover (ATO), Broken Access Control, IDOR, Authentication & Authorization flaws, Business Logic vulnerabilities, Session Management issues, and Privilege Escalation. 4. Assess applications against the OWASP Top 10, OWASP API Security Top 10, and OWASP ASVS Level 2 & Level 3 requirements. 5. Perform Secure Code Reviews to identify insecure coding practices and recommend remediation. 6. Integrate SAST, DAST, and SCA tools into CI/CD pipelines to support DevSecOps and Secure SDLC initiatives. 7. Configure and manage security tools such as SonarQube, Checkmarx, Veracode, OpenText Fortify, OWASP ZAP, Burp Suite Professional, Trivy, and Black Duck.