I am a Cyber Security Enthusiast, Bug Bounty Hunter, and CTF player based in Sylhet, Bangladesh. I currently work as a Web Security Researcher on both HackerOne and Intigriti, where I hunt for real-world vulnerabilities across public bug bounty and Vulnerability Disclosure Programs.
My focus is offensive web security: deep reconnaissance, manual testing, and hunting the bug classes that automated scanners miss: broken access control and IDOR, injection flaws, authentication bypasses, SSRF, and business logic errors. I work primarily with Burp Suite, Nmap, and Wireshark alongside custom scripting in Python and Bash, guided by the OWASP Top 10 and MITRE ATT&CK.
I have earned 26+ cybersecurity certifications from EC-Council, Cisco Networking Academy, TryHackMe, Udemy, and Team Matrix, including Ethical Hacking Essentials (EHE), Network Defense Essentials (NDE), Digital Forensics Essentials (DFE), and the Cisco Ethical Hacker badge. I rank in the Top 1% on TryHackMe and have completed five consecutive years of Advent of Cyber.
Alongside security research, I serve as Campus Ambassador for Team Matrix - Elite Hackers at Shahjalal University of Science and Technology, and as IT Secretary of Sonchalon, our voluntary blood donors organization. I believe volunteerism is not a charity but a responsibility.