Mohd Haji
Offensive Security Engineer - 3 @Fanatics | AI & LLM Security + Creating Agents Skills / MCP Servers | OSCP+ , OSWA | Bug hunter @Apple, @Paypal,etc.
- Role
- Offensive Security Engineer - 3 at Fanatics
- Location
- Hyderabad, TG, IN
- LinkedIn followers
- 500 followers
About Mohd Haji
I’m a passionate and honest cybersecurity professional who believes that everything happens for a reason—and often, for the better. With a strong growth mindset, I thrive in roles that challenge me and allow room to grow—if a position matches even 70% of my skillset, I see it as the perfect opportunity to learn and contribute.What I Do:I specialize in offensive security, with hands-on experience across-> Web, Mobile & API Pentesting -> LLM & Agentic AI Security(Red teaming LLMs & Implemented various MCP Servers )-> Cloud Security (AWS, Azure)-> Network & Infrastructure Security -> Payment Gateway Security -> CI/CD & DevSecOps, SAST & DAST -> Secure Code Review -> Red Teaming Exercises -> Vulnerability Research & Exploitation (Consulting & Bug bounties)Global Experience:Worked in Riyadh, Saudi Arabia for 1.5+ years as an InfoSec Specialist. Executed pentesting engagements for private and government clients. Collaborated on team training, CTFs, and internal tooling. I have 9+ years of experience in penetration testing /bug hunting, with 5+ years of experience as Application Security/Product Security Engineer/Offensive Security Engineer in (Copart/Vmware/Fanatics). Recognitions & Achievements-> Facebook Hall of Fame – 6 consecutive years (2014–2019)-> Ranked #1 Facebook Whitehat Researcher from Hyderabad (2015, 2016)-> PayPal Top 10 Security Researcher (Q4 2015, Q3 2016)-> Listed in 150+ companies’ Hall of Fame for responsible disclosures (public & private programs) & got rewards as well-> CVE Contributor: CVE-20•••••66 – Nextcloud Server -> Bug hunting on Platforms: Bugcrowd, HackerOne & Private programs including Apple, Microsoft, Facebook, PayPal, and more
Experience
Offensive Security Engineer - 3
Apr 2024 — Present · Hyderabad, IN
Pentesting Fanatics Cloud Enviroment (Azure & AWS)-> Pentesting internal AI chatbots and applications-> Handling Fanatics bug bounty program on Synack-> Participated in Fanhack Event (Creating AI based solution to detect PII using Amazon AI technologies such as Amazon Comprehend)-> DRI On call rotation for any security incident-> Learned about Akamai WAF configuration-> Working with relevant stakeholders on closing down external ports to public assets-> Using AI agents for day to day activities-> Completed two trainings on (Advance Cloud Hacking and DEVSECOPS) delivered by Notsosecure (Blackhat Trainers)-> Completed Offsec\'s PEN 200 training and obtained OSCP+ certification-> Implemented MCP Servers for different cybersecurity use cases-> Evaluated Tld\'s of fanatics via zone file for sub domain takeovers-> Created and lead many security related SEV incidents collaborating with SRE/SRO teams.
Education
Newton High School
Secondary School Certificate
2010 — 2011
Chaitanya Bharathi Institute Of Technology
Bachelor's degree, Computer Science
2013 — 2017
MS Junior College
Intermediate, MPC
2011 — 2013
Skills
- C++
- Microsoft Office
- Html
- Leadership
- Oauth
- Api Security
- Java
- Python
- Powerpoint
- Penetration Testing
- Burp Suite
- Security Analysis
- Tamper Data
- C
- Programming
- Windows
- Prezi
- Vulnerability Research
- Business Logic Flaws
- Sql
- Idor
- Microsoft Word
- Owasp
- Csrf
- Xss
- Pega Prpc
- Information Security
- Php
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.