Muhammad Khan

Senior Penetration Tester @Motion Recruitment

Toronto, CA
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Apr 2025 — Present

Senior Penetration Tester @Motion Recruitment

View department →

NJ, US

Penetration Testing & Bug Bounty• Conducted penetration testing on web applications (OWASP WSTG) and mobile applications (OWASP MSTG).• Performed security assessments on Docker, AWS, and Kubernetes environments.• Implemented and validated bug bounty findings, reproducing exploits to confirm impact and remediation.Red Team Operations & Adversary Emulation• Executed red team engagements on Active Directory, aligned with MITRE ATT & CK tactics (Reconnaissance → Initial Access → Execution → Persistence → Privilege Escalation → Credential Access → Lateral Movement → Exfiltration).• Simulated adversary techniques against AWS services (IAM, EC2, S3, ROSA, EKS, Lambda) to identify misconfigurations and gaps.Application Security• Reviewed and validated developer-implemented mitigations, ensuring secure SDLC practices.• Defined security verification requirements for production releases.• Implemented SAST tools (SonarQube, Snyk, Semgrep, MobSF) to identify vulnerabilities in CI/CD pipelines.• Performed DAST scanning on new product releases to uncover runtime security flaws.

EDUCATION

N/A

Toronto Metropolitan University

Bachelor of Engineering - BE, Electrical and Electronics Engineering

ABOUT MUHAMMAD KHAN

I am a Penetration Tester and Senior Security Engineer with over 6 years of experience delivering offensive security assessments across web applications, APIs, Active Directory, enterprise networks, and cloud platforms (AWS, Azure, GCP). My work has consistently followed industry frameworks including PTES, NIST 800-115, MITRE ATT & CK, and OWASP, ensuring assessments are structured, repeatable, and directly aligned to business impact.Over the course of more than 50 penetration tests and red team engagements, I have identified and exploited high-impact vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), broken access control, and misconfigurations. Beyond discovery, I work closely with IT and engineering teams to validate remediation and implement durable defenses—closing lateral movement paths, improving identity security, and strengthening network and cloud perimeters.My technical expertise spans penetration testing and red teaming (scoping, threat modeling, exploitation, reporting, and re-testing), and a strong toolkit including Kali Linux, Burp Suite, Nmap, Metasploit, SQLmap, Wireshark, Dirbuster, and Nikto. I am also experienced in infrastructure and cloud security, including network segmentation, Active Directory hardening, firewall policy optimization, and cloud perimeter controls. In addition, I leverage Python and Bash scripting to automate reconnaissance, evidence collection, and reporting, enabling more efficient and scalable testing operations.

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Muhammad Khan — Senior Penetration Tester at Motion Recruitment in Toronto, CA | Unifers