Ahmed El-Ganainy
Offensive Security | VAPT Consultant · also known as Ahmed M. Ali
In shortOffensive security professional with 5+ years of hands-on experience in penetration testing across Web Applications, APIs, Mobile Applications, Networks, Active Directory, Cloud, and Wireless environments. Certified OSCP, OSWE and OSWP, with strong expertise in manual security testing, vulnerability exploitation, attack-path chaining, and business-logic assessment.
I’ve always been curious about how systems work — and what happens when they don’t. That curiosity led me into cybersecurity, where I spend my time exploring apps, networks and cloud systems to find hidden risks and help make them safer.
What I Do
Every engagement follows the same arc — find it, prove it, make it stick.
🔍 Break things — ethically. Offensive testing across Web, API, Mobile, Network, Active Directory and Cloud.
- Black-box, gray-box and white-box assessments for enterprise and government clients
- Manual exploitation and attack-path chaining, not scanner output
- Authorization, business-logic and injection flaws that automated tooling misses
🔧 Fix things — working with developers, not filing findings into a void.
- Reproduce complex vulnerabilities and walk teams through their real business impact
- Triage and validate SAST/SCA findings to cut false positives
- Verify remediation in UAT and retest until the finding actually closes
⚡ Build things — turning one-off work into repeatable process.
- Methodologies, checklists, reporting templates and retesting workflows
- Custom scripts, tooling and labs that make the next engagement faster
- Knowledge transfer — secure-coding sessions for development teams
Delivered for banking, enterprise and government environments across Saudi Arabia and Egypt — scope and proposals, technical reporting, risk rating, remediation guidance and retesting.
Experience
Penetration Testing Consultant — 2P Perfect Presentation
Feb 2025 – Present
- Delivered 40+ end-to-end penetration testing engagements across internal products and external client environments — assessment, reporting, remediation follow-up, retesting and final validation.
- Conducted comprehensive Web, API and Mobile testing using black-box, gray-box and white-box approaches, identifying complex authorization, business-logic, injection and exploit-chaining vulnerabilities.
- Performed manual source code reviews across Java, .NET/C#, PHP and Node.js, validating exploitability and surfacing issues missed by automated SAST tooling.
- Reviewed and triaged Checkmarx SAST/SCA findings alongside Professional Services and DevOps teams to support automated scanning and vulnerability-management workflows.
- Established and standardized penetration testing methodologies, checklists, reporting templates and retesting workflows aligned with NCA requirements.
- Evaluated third-party penetration testing providers and resident consultants, validating findings, severity ratings, false positives, evidence and report quality.
- Prepared technical proposals covering scope, methodology, effort estimation, timelines and deliverables.
Information Security Consultant — ZINAD IT
Feb 2023 – May 2025
- Conducted penetration testing for banking and enterprise clients across Web, API, Mobile (Android/iOS), network and wireless environments.
- Identified and supported remediation of 200+ Critical and High severity vulnerabilities across client environments.
- Performed manual source code reviews across Java, PHP, Python, Node.js, .NET/C#, Swift, Kotlin and Dart, finding complex business-logic flaws and insecure coding practices.
- Implemented Fortify SAST, DAST and SCA, manually validating findings to reduce false positives and strengthen secure code review.
- Ran security awareness sessions for developers on secure coding, common web vulnerabilities and remediation techniques.
- Organized and competed in CTF competitions across Oman, Qatar, Egypt and Saudi Arabia.
Junior Penetration Tester — Security-Meter
Feb 2022 – Jan 2023
- Performed Web and Mobile application penetration testing for financial-sector clients using black-box, gray-box and white-box approaches.
- Conducted advanced Android and iOS security testing — static and dynamic analysis, runtime manipulation, traffic interception and security-control bypass using MobSF, Frida and custom scripts.
- Identified complex vulnerabilities including race conditions and business-logic flaws, working directly with development teams to reproduce findings and support remediation.
Certifications
| Certification | Issuer |
|---|---|
| OSWE — Offensive Security Web Expert | Offensive Security |
| OSCP — Offensive Security Certified Professional | Offensive Security |
| CRTE — Certified Red Team Expert | Altered Security |
| CRTO — Certified Red Team Operator | ZeroPoint Security |
| HTB BlackSky Cloud Labs — Cyclone (Azure) · Hailstorm (AWS) · Blizzard (GCP) | Hack The Box |
| OSWP — Offensive Security Wireless Professional | Offensive Security |
| eMAPT — Mobile Application Penetration Tester | eLearnSecurity |
Technical Skills
Web & API — Web, REST, SOAP and GraphQL
- Authentication and authorization flaws, session management, JWT weaknesses
- Injection and server-side bugs: SQLi, SSRF, XXE, SSTI, deserialization, file upload
- Client-side: XSS, CSRF — plus rate-limit and WAF bypass
- Business-logic abuse and multi-step exploit chaining
Mobile — Android & iOS
- Static and dynamic analysis, reverse engineering
- Runtime instrumentation, application patching and repackaging
- SSL pinning and root/jailbreak detection bypass, insecure storage
- Mobile backend API testing
Source Code & Application Security
- Manual secure code review across Java, .NET/C#, PHP, Node.js, Python, Swift, Kotlin and Dart
- Exploitability validation, SAST/SCA triage and false-positive reduction
Cloud, Active Directory & Wireless
- Active Directory attack paths and red team techniques
- AWS, Azure and GCP security assessments
- Wireless network security testing
Scripting & PoC Development Python · Bash · PowerShell · JavaScript — for enumeration, exploitation, automation and proof-of-concept development.
Let’s Connect
Whether it’s a penetration testing engagement, a secure code review, or just trading notes on a CTF — I’m happy to talk.