Asim.
Kanvis
Asim Shakeel

Asim Shakeel

Offensive Security Specialist | Penetration Testing & AppSec | FAST-NUCES '26
Hire Me

Overview

Offensive security specialist with a background in government-level vulnerability assessments and financial sector SOC operations. Experienced in full-lifecycle VAPT, NIST CSF-aligned hardening, and securing production Node.js environments. Proven ability to identify and remediate high-criticality vulnerabilities across complex network infrastructures.
Islamabad, Pakistan

Experience

Mar 2026 – Apr 2026

INTERNSHIP

Penetration Testing Intern

Tech Hierarchy
Remote
Executed full-lifecycle VAPT across 3+ isolated VM sandbox targets - OSINT, host discovery (Nmap, Netdiscover), service enumeration, and exploitation of OWASP A03 (SQLi) and A07 (XSS) - producing structured PoC reports with CVSS v3.1-scored findings, payloads, screenshots, and executive-ready remediation recommendations. Designed enterprise-grade segmented VLAN topology in Cisco Packet Tracer; deployed DVWA and OWASP Juice Shop as live attack surfaces in isolated sandbox environments for repeated pentest cycles.
Executed full-lifecycle VAPT across 3+ isolated VM sandbox targets - OSINT, host discovery (Nmap, Netdiscover), service enumeration, and exploitation of OWASP A03 (SQLi) and A07 (XSS) - producing structured PoC reports with CVSS v3.1-scored findings, payloads, screenshots, and executive-ready remediation recommendations.
Designed enterprise-grade segmented VLAN topology in Cisco Packet Tracer; deployed DVWA and OWASP Juice Shop as live attack surfaces in isolated sandbox environments for repeated pentest cycles.
OSINTNmapNetdiscoverOWASP A03 (SQLi)OWASP A07 (XSS)CVSS v3.1Cisco Packet TracerDVWAOWASP Juice ShopVLAN

Mar 2026 – Apr 2026

INTERNSHIP

Application Security Intern

Developers Hub
Remote
Identified and validated 6+ critical/high vulnerabilities (OWASP A02, A03, A07) in a production Node.js application using Burp Suite, OWASP ZAP, SQLMap, and Nikto; performed false-positive triage and confirmed exploitability before escalating with CVSS v3.1 scores. Owned complete remediation cycle - bcrypt, JWT hardening, CSP, HTTPS, CSRF tokens, Helmet.js, rate limiting, CORS - then conducted remediation verification via Lynis audit confirming zero open OWASP Top 10 findings across the stack.
Identified and validated 6+ critical/high vulnerabilities (OWASP A02, A03, A07) in a production Node.js application using Burp Suite, OWASP ZAP, SQLMap, and Nikto; performed false-positive triage and confirmed exploitability before escalating with CVSS v3.1 scores.
Owned complete remediation cycle - bcrypt, JWT hardening, CSP, HTTPS, CSRF tokens, Helmet.js, rate limiting, CORS - then conducted remediation verification via Lynis audit confirming zero open OWASP Top 10 findings across the stack.

Key Achievements

Identified and validated 6+ critical/high vulnerabilities (OWASP A02, A03, A07) in a production Node.js application.
Confirmed zero open OWASP Top 10 findings across the stack after remediation cycle.
Node.jsBurp SuiteOWASP ZAPSQLMapNiktoCVSS v3.1bcryptJWTCSPHTTPSCSRF tokensHelmet.jsRate limitingCORSLynis

Jun 2025 – Aug 2025

WORK

Cybersecurity Intern

Pakistan Telecommunication Authority - Cybersecurity Directorate
Islamabad (On-site)
Observational internship focused on government-scale cybersecurity operations, SOC/NOC workflows, and NIST CSF frameworks.
Observed national-level SOC and NOC operations, gaining insight into real-time network traffic monitoring and threat mitigation strategies.
Gained exposure to how large-scale networks are monitored and how malicious traffic is identified and blocked in a government environment.

Key Achievements

Gained exposure to national-level SOC/NOC workflows and NIST CSF application.
NIST CSFWiresharkWindows ServerLog Analysis

Aug 2023 – Sep 2023

INTERNSHIP

SOC Intern

U Microfinance Bank - Risk & Security, Head Office
Islamabad (On-site)
Triaged 50+ live security events daily in IBM QRadar SIEM; correlated logs, identified 3 confirmed anomalies, and escalated high-priority alerts for Tier-2 investigation in a regulated financial environment.
Triaged 50+ live security events daily in IBM QRadar SIEM; correlated logs, identified 3 confirmed anomalies, and escalated high-priority alerts for Tier-2 investigation in a regulated financial environment.

Key Achievements

Triaged 50+ live security events daily.
Identified 3 confirmed anomalies.
IBM QRadar SIEMLog Correlation

Project Portfolio

ACADEMIC

Present

Network IDS Lab & Post-Exploitation Simulation

Security Architect / Pentester

Architected 4-VM attack/defend sandbox (Kali Linux attacker, Windows Server, Ubuntu targets, pfSense firewall); authored 12+ custom Suricata IDS rules, validated detection against live Meterpreter sessions achieving 0 false negatives on tested payload set. Documented privilege escalation chains with MITRE ATT&CK-mapped defensive controls; produced structured post-exploitation playbook for remediation verification.
Kali LinuxSuricataMetasploitMeterpreterpfSenseWindows ServerUbuntuMITRE ATT&CK
PERSONAL

Present

Context-Aware Web & API Misconfiguration Analyzer

Developer

Automated misconfiguration scanner targeting OWASP Top 10; successfully validated against test environments to detect SQLi, XSS, and CORS misconfigurations. Currently extending detection to Broken Access Control and Cryptographic Failures.
PythonFlaskOWASP ZAP APIOWASP Top 10

Education

2026

B.Sc. Computer Science

FAST-NUCES, IslamabadSpecialization in Computer Science
GPA: 2.26 / 4

Relevant Coursework

Offensive SecurityNetwork SecurityOS Internals

Impact & Recognition

Awards

PTA & Huawei · 2025

Telecom Cyber Security Awards 2025

Attendee/Speaker recognition

Professional Certifications

Hack The Box · 2026

Junior Penetration Tester Path

Credential In Progress
Google · 2024

Google Cybersecurity Professional Certificate

Social Impact & Activities

2025

Next Gen Cyber Resilience Workshop & Telecom Cyber Security Awards 2025WORKSHOP

Speaker/Attendee - Next Gen Cyber Resilience Workshop

Jointly organized by PTA & Huawei

Internet Governance & ICANN sessionsOTHER

Internet Governance & ICANN sessions

Participation in governance sessions

Skills & Interests

Burp Suite

Nmap

OWASP Top 10

Kali Linux

Metasploit

OWASP ZAP

Wireshark

Meterpreter

XSS

SQLi

SQLMap

JWT

API Security Testing

Nessus

Netdiscover

Nikto

MSFVenom

OSINT

Broken Auth

CSRF

Suricata IDS

IBM QRadar SIEM

Python

SQL

NIST CSF

MITRE ATT&CK

Node.js

C/C++

Bash

Lynis

PowerShell

Let's Connect

I'd love to hear from you. Feel free to reach out.

These unlock once you finish onboarding and publish your profile.