Summary
Overview
Work History
Education
Skills
Certification
Languages
Timeline
Generic

Omer Ahmed

Riyadh

Summary

I am a Cyber Security Professional with a robust technical background and a highly analytical mindset, backed by more than three years of professional experience in the field. As a Senior VAPT Consultant Specialist, I bring a wealth of experience in conducting advanced vulnerability assessments and penetration testing within the financial sector. My expertise is in tailoring these assessments to meet the specific security requirements of the industry, ensuring comprehensive protection of financial data and systems. This includes a strong understanding of various regulatory frameworks, ensuring compliance and alignment with industry standards.

Overview

6
6
years of professional experience
1
1
Certification

Work History

Cyber Security Consultant

New Solutions KSA
11.2024 - Current
  • Conducted black box and gray box penetration testing on web and mobile applications (including Flutter-based apps), identifying security vulnerabilities through static and dynamic analysis and API testing.
  • Performed Active Directory security assessments to uncover misconfigurations, privilege escalation paths, and domain trust abuse using tools like Bloodhound.
  • Delivered detailed technical reports with POCs and remediation guidance, and collaborated with internal teams to align findings with business risk and improve overall security posture.

Cyber Security Consultant

Crystal International Technology, KSA
07.2023 - 11.2024
  • Provide cybersecurity consulting services to clients, including penetration testing.
  • Undertaking In-Depth White Box Testing and executing comprehensive Source Code Analysis for Web Applications, utilizing manual techniques and automated tools for thorough examination.
  • Thoroughly reviewing and Assessing Penetration Testing reports to ensure their completeness, accuracy, and quality.
  • Carrying out thorough Configuration Reviews and assessing security controls to measure their effectiveness and ensure compliance with current security standards.
  • Engaged in a project with the AlRajhi Takaful at Crystal, focusing on delivering specialized cybersecurity solutions.

Senior Cyber Security VAPT Consultant

Al Rajhi Takaful – Insurance Services KSA
07.2023 - 11.2024
  • Executing Penetration Tests on web applications, API, Mobile, Thick Client, and Source Code Review to uncover and address security vulnerabilities.
  • Collaborating with Client Application Development Teams to facilitate effective remediation of identified security issues.
  • Performing Active Directory security assessments, ensuring the robustness of the Windows environment.
  • Collaborated in the development of security policies and procedures.

Junior Penetration Tester

FIRST SHIELD
01.2020 - 01.2022
  • Conducted comprehensive penetration testing engagements on various web applications, focusing on identifying and exploiting critical vulnerabilities listed in the OWASP Top 10.
  • Utilized API security testing tools to identify authorization flaws and data leakage issues.
  • Performed network vulnerability assessments (NVA) to identify exploitable weaknesses in network infrastructure.
  • Penetration Testing: Supervising and participating in penetration testing activities to simulate cyberattacks and identify weaknesses in security defenses.
  • Analyzed change requests related to security and provided recommendations to improve the overall security posture.
  • Developed and executed custom payloads to exploit vulnerabilities and assess their impact on the target systems.
  • The importance of clear and concise reporting in cybersecurity.

Education

Information Technology -

University of Science and Technology
01.2018

Skills

  • Mobile Application Penetration Testing
  • API Penetration Testing
  • Programming & Scripting
  • Web Application Penetration Testing
  • Source Code Review
  • Thick Client Penetration Testing
  • Vulnerability Assessment
  • AD Penetration Testing
  • Configuration Review
  • High Quality Reporting

Certification

  • Offensive Security Certified Professional certification (OSCP)
  • ELearn Security Certified Professional Penetration Tester (eCPPTv2)

Languages

Arabic: Native
English: Advanced

Timeline

Cyber Security Consultant

New Solutions KSA
11.2024 - Current

Cyber Security Consultant

Crystal International Technology, KSA
07.2023 - 11.2024

Senior Cyber Security VAPT Consultant

Al Rajhi Takaful – Insurance Services KSA
07.2023 - 11.2024

Junior Penetration Tester

FIRST SHIELD
01.2020 - 01.2022

Information Technology -

University of Science and Technology
Omer Ahmed