Shahamat Omim

Penetration Tester @Assurit

Woodbridge, VA, US
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Sep 2023 — Present

Penetration Tester @Assurit

View department →

Fairfax, VA, US

Conducted network and protocol analysis with Wireshark, Zeek, and tcpdump to identify suspicious traffic patterns, protocol misuse, and covert channels.• Carried out vulnerability discovery and validation using Nessus, OpenVAS, Qualys, and Rapid7 InsightVM, and reduced false positives via manual verification and exploitation attempts.• Executed targeted cloud penetration tests and configuration reviews for AWS, Azure, and GCP using tools like ScoutSuite, Prowler, Pacu, CloudSploit, and AWS/Azure/GCP native telemetry (CloudTrail, Config, GuardDuty).• Tested container and orchestration security (Docker, Kubernetes) using Trivy, kube-hunter, Clair, and manual configuration review of RBAC, network policies, and image supply chain.• Performed mobile security assessments using MobSF, Frida, apktool, and dynamic analysis to find insecure storage, improper platform usage, and privileged API access.• Conducted API security testing (Postman, Burp, Insomnia) focusing on authentication, authorization, rate-limiting, input validation, and business logic flaws.• Evaluated and hardened network devices and security controls including firewalls, VPNs, IDS/IPS, proxy configurations, and iptables; tested firewall rulesets and segmentation for bypasses.• Carried out binary and malware analysis with IDA Pro, Ghidra, Cuckoo Sandbox, and dynamic debuggers to reverse engineer payloads, extract IOCs, and produce detection rules.• Performed threat modeling and risk assessments using STRIDE, DREAD, and MITRE ATT & CK to map findings to likely adversary techniques and prioritize remediation.• Conducted physical security and social engineering engagements (phishing simulations, vishing, badge cloning) where permitted and documented human-factor weaknesses.• Integrated application and security testing into CI/CD pipelines (Jenkins, GitLab CI, GitHub Actions) and collaborated with Dev teams to add SAST/DAST checks (SonarQube, Checkmarx, Snyk) and IaC scanning.

EDUCATION

N/A

American International University-Bangladesh

Bachelor of Engineering - BE, Electrical and Electronics Engineering

N/A

Washington University of Science and Technology (WUST)

Master's degree, Information Technology

ABOUT SHAHAMAT OMIM

Cybersecurity professional with 6 years of experience in offensive security, penetration testing, and vulnerability management. Skilled in conducting grey- and black-box tests across web, network, server, and cloud environments (AWS, Azure, GCP), simulating real-world attacks through exploitation, privilege escalation, and lateral movement. Experienced in vulnerability scanning, incident response, and system hardening aligned with NIST 800-53, OWASP Top 10, and CIS benchmarks. Proficient in Python, Bash, and PowerShell for automating reconnaissance, exploitation, and reporting tasks, with strong knowledge of threat modeling (STRIDE, DREAD, MITRE ATT & CK) and cryptographic analysis. Hands-on with Metasploit, Burp Suite Pro, Cobalt Strike, Nessus, Nmap, Wireshark, sqlmap, and OpenVAS to identify, validate, and remediate security weaknesses effectively.

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Shahamat Omim — Penetration Tester at Assurit in Woodbridge, VA, US | Unifers