Abbas Al-Maliky

AI Researcher

Bratislava, Slovakia6 yrs 10 mos experience

Key Highlights

  • Expert in Penetration Testing and Cyber Security.
  • Proven track record in identifying critical vulnerabilities.
  • Strong leadership in security testing methodologies.
Stackforce AI infers this person is a Cyber Security Expert with extensive experience in penetration testing and network security.

Contact

Skills

Core Skills

Penetration TestingNetwork SecurityCloud SecurityWeb Application SecurityIot SecuritySystem AdministrationNetwork ManagementTechnical Support

Other Skills

Kali LinuxVulnerability AssessmentSecurity Testing MethodologiesAWSAzureSecurity AuditsOWASPSQL InjectionXSSRisk MitigationVirtualizationDisaster RecoveryNetwork ConfigurationElectrical TroubleshootingDigital Forensics

About

Hands on Computers since Windows 95 - Senior System Administrator with a demonstrated history of working in the IT industry. Skilled in Network Administration, Penetration Testing, Troubleshooting, Network Security and Computer Forensics. Strong information technology professional with a Bachelor's degree focused in Computer Systems Networking and Cyber Security. Computer Networks Hack The Box Open Bug Bounty

Experience

6 yrs 10 mos
Total Experience
1 yr 1 mo
Average Tenure
--
Current Experience

Swiss re

Senior Penetration Tester / Ethical Hacker

Aug 2022Jul 2023 · 11 mos · Bratislava, Slovakia · Hybrid

  • Penetration Testing using Kali Linux, including the creation of vulnerability reports, manual post
  • exploitations, and the execution of Black, White, and Grey Box penetration testing for Web
  • Applications, Network Infrastructure, Windows and Linux Machines, Cloud Environments of AWS and
  • Azure etc.
  • Providing technical leadership and training on security testing methodologies and best practices to
  • ensure high-quality, effective security testing.
  • Maintaining open and transparent communication with application owners throughout the
  • penetration testing process, including regular status updates, progress reports, and follow-up
  • meetings.
  • Established vulnerability assessment practice, proactively ensuring safety of client-facing applications and minimizing client audit findings.
  • Actively searched for potential security issues and security gaps that are beyond the ability of detection by any security scanner tool.
  • Performed security assessments and audits of Cloud environments (AWS and Azure), recommending and implementing security improvements.
  • Worked with application developers to validate, assess, understand root cause and mitigate vulnerabilities including DevSecOps.
  • Developing and executing custom exploit code to achieve advanced penetration testing objectives, such as bypassing security controls, escalating privileges, and exfiltration sensitive data.
  • Strong communication and reporting skills, with the ability to present technical information to non-technical stakeholders for improvements for security services, including the continuous training enhancement of existing methodology material and supporting assets.
  • Identified previously unknown 0days in severe infrastructure-level vulnerabilities in publicly and internal accessible websites and software’s (PDFTron, Adobe Acrobat Reader etc.)
  • (Please feel free to ask if you have more questions.)
Penetration TestingKali LinuxVulnerability AssessmentCloud SecurityNetwork Security

Integrity360

Cyber Security Test Consultant

Nov 2021Jul 2022 · 8 mos · Manchester, England, United Kingdom

  • Penetration Testing - Kali Linux – Creating vulnerability reports, manual post
  • exploitations, conducting Black, White and Grey Box penetration testing.
  • Performed penetration testing on Security infrastructure and vulnerability
  • assessment, across public and private networks, performing audit on Windows / Linux
  • systems.
  • Perform in-depth Web application, Network Infrastructure, Internal Red Team
  • assessment, Citrix Breakouts and AWS / Azure Cloud penetration test for clients in
  • global retail, finance, banks and aeroplane industries and created detailed written
  • reports on the assessment findings and recommendations.
  • Worked on improvements for provided security services, including the continuous
  • enhancement of existing methodology material and supporting assets.
  • Performed assessments of security awareness training using social engineering.
  • Analyze security test results, draw conclusions from results and develop targeted
  • testing as deemed necessary and social engineering tests for global clients.
  • OWASP Vulnerabilities like XSS, SQL Injection, CSRF, Privilege Escalation and all
  • the test-case of a web application security testing.
  • Follow up and ensure the closure of the raised vulnerabilities by revalidating and
  • ensuring 100% Closure.
  • Produced and report 0-day exploits to vendors such as Oracle, CISCO VPN
  • endpoints and WordPress etc.
Penetration TestingKali LinuxVulnerability AssessmentWeb Application SecurityNetwork Security

Siemens healthineers

Information Security Professional - Penetration Tester / Ethical Hacker

Nov 2019Nov 2021 · 2 yrs · Bratislava, Bratislava Region, Slovak Republic

  • Lead of Infrastructure Pentest department and hold workshops illustrating the state of the art of various technologies and assessment strategies.
  • Hands-on penetration testing on Security infrastructure and vulnerability assessment, across public and private networks, performing audit on Windows / Linux systems including Privilege escalations.
  • Creating vulnerability reports for clients, manual post exploitations, conducting Black, White and Grey Box penetration testing.
  • Microsoft Server 2008-2019, Windows OS, Bloodhound, Active Directory, Domain Controllers, Group Policies, Audit of Infrastructure, DMZ, Firewalls, subnets, Azure, AWS etc.
  • Manual exploiting CVEs to Security Incident Response team(s) such as Blue Team to further investigate and remediate findings.
  • Perform penetration tests on IoT Hospital Medical Devices such as Blood Analyzers etc. for Siemens Healthineers.
  • Developing threat models, security controls, threat analysis and creation of risk control matrices and risk mitigation strategies.
  • Analyze security test results, draw conclusions from results and ensure corporate compliance.
  • Work on improvements for provided security services, including the continuous enhancement of existing methodology material and supporting assets.
  • Web Penetration Testing - Burp Suite Pro, Wireless Penetration Testing - WPA, WPA2, WEP.
  • Advanced with password hash cracking, MD5, SHA1 WPA2, with tools such as Hashcat, John the Ripper, Cobalt Strike, PowerShell Empire, Nessus, NMap, SQLMap etc.
  • (Please feel free to ask if you have more questions.)
Penetration TestingVulnerability AssessmentIoT SecurityCloud SecurityNetwork Security

K3 business technologies

Senior System Administrator

Jan 2019Sep 2019 · 8 mos · Manchester, United Kingdom

  • Managing and achieving projects for Servers, workstations, laptops, printers, routers, switches and existing network applications - Covering first, second and third line of support of contact for all IT & technical for all users and incident response on Server 2008-2019.
  • Responsible for supporting from Windows 7-10, Office 365 - Active Directory, Anti-Virus products, DNS/DHCP, TCP/IP, Ethernet, Group Policy and Firewall Audit, including securing the network with Sonicwall Firewall, setting up VPN users etc.
  • Performed daily audit on all systems, frameworks, hardware and server resources.
  • Server Virtualization using Hyper-V and VMware vSphere vCenter – Managing virtual machines, snapshots etc. – Scale Network hardware - Server Migrations to cloud infrastructure.
  • Troubleshooting and repairing PC’s, laptops (hardware and software) replacing hardware and NAS drives - Skype for Business.
  • Penetration Testing - Kali Linux – Creating vulnerability reports, manual post exploitations, Web Application Pentesting etc. – DarkTrace – Monitor Traffic etc.- deploying patches, manual patching, patch servers etc.
  • Solarwinds MSP Cloud Backups - Initiates backup process, data recoveries and other disaster recovery contingencies.
  • (Please feel free to ask if you have more questions.)
System AdministrationNetwork ManagementVirtualization

Spectrum brands, inc

System Administrator

Nov 2016Dec 2018 · 2 yrs 1 mo · Manchester, United Kingdom

  • Acting as the first, second and third line of support of contact for all IT & technical queries including administering the IT department’s policies and procedures, including securing the network, Websense Forcepoint Security Portal proxy and filtering firewalls. Responsible for supporting from Windows 7-10, Office 2007-2016, Windows Server 2008-2016, Active Directory, Anti-Virus products, DNS/DHCP, TCP/IP, Ethernet, wireless router and Firewall Configurations including configuring and cabling, switches and Exchange 2013.
  • VMware vSphere vCenter – Managing virtual machines, snapshots etc.
  • Sophos Enterprise Console - deploying antivirus remotely, filtering group policies and protecting against Ransomware.
  • Troubleshooting and repairing PC’s, laptops (hardware and software) replacing hardware and mobile devices including managing company iPhones with Cisco Meraki Mobile Management, Mitel phone servers and support of telecommunication equipment and supporting a multi-site IT infrastructure of at least 100 employee per off site visit.
  • Helpdesk tickets - receiving inbound and outbound technical calls from different departments supporting remotely, face to face support.
  • Qualys Vulnerability Scanner – Vulnerability Scanning, deploying patch, manual patching, creating report, patch servers etc.
  • Veeam Disaster Recovery – Setting up, securing, NAS drives up to 21TB, disaster backing up servers, deploying backups to end users remotely.
System AdministrationNetwork SecurityDisaster Recovery

Business data and mobile solutions limited

Senior Information Technology Administrator - Connector

Feb 2016Sep 2016 · 7 mos · Manchester, United Kingdom

  • Responsible for supporting: Windows XP/Vista/Windows 7-10 Office 2007-2013, Windows Server 2003/2008 Active Directory Anti-Virus products, DNS/DHCP, TCP/IP, Ethernet, wireless router and Firewall Configurations including configuring and cabling network Avaya servers and switches and SQL server.
  • Managing VMware, Windows 2003-2008, Active Directory Group Policies, TCP/IP.
  • Troubleshooting and repairing PC’s, laptops (hardware and software) and mobile devices.
  • Acting as the first point of contact for all IT & technical queries including administering the IT department’s policies and procedures.
  • Installation software and support of telecommunication equipment.
Technical SupportSystem AdministrationNetwork Configuration

Education

The University of Salford

Bachelor's degree — Computer Systems Networking and Telecommunications

Jan 2013Jan 2016

Stackforce found 100+ more professionals with Penetration Testing & Network Security

Explore similar profiles based on matching skills and experience