Resume

Rana Uzair Ahmad

Security Engineer · Penetration Tester · DevSecOps Practitioner

Profile

Professional Summary

Security Engineer, Penetration Tester, DevSecOps Practitioner, and Software Developer with 3+ years of hands-on experience spanning offensive security, CI/CD pipeline security, infrastructure automation, and full-stack security tool development. Author of 34+ open-source tools covering SIEM engineering, remote infrastructure management, SSH security, and network analysis. Ranked Top 3% TryHackMe globally and Top 800 HackTheBox (Professional Rank, Level 54). CompTIA PenTest+ Preparation Course Certified via Coursera with 17 total certifications.

Capabilities

Technical Skills

$

TOOLS & FRAMEWORKS

Burp Suite
Web VAPT
Metasploit
Exploit
Nmap
Recon
Wireshark
Network
Hashcat
Crack
SQLMap
Database
Nessus
Scan
Nikto
Web
$

PLATFORMS & INFRASTRUCTURE

Kali Linux
Offensive
Parrot OS
Offensive
Docker
Containers
Kubernetes
Cluster
Terraform
IaC Cloud
Ansible
Automation
AWS Cloud
IAM & VPC
Ubuntu / Debian
Server
$

DEFENSIVE & SIEM ENGINEERING

Wazuh SIEM
Detection
Splunk
Analytics
Elastic / Kibana
Log Pipelines
CyberGuard Agent
C Daemon
Sysmon / DFIR
Telemetry
Trivy / Semgrep
SAST / SCA
$

LANGUAGES & SYSTEMS PROGRAMMING

Python
Scapy & Paramiko
C / C++
POSIX & Sockets
Rust
Systems & Memory
Assembly (x86)
Low-Level Registers
Ghidra / x64dbg
Reverse Eng
Bash / Shell
Linux Automation
Career

Professional Experience

Security Engineer

Apr 2025 - Present
Zerox Innovation (Pvt.) Ltd. · Rawalpindi, Pakistan
  • Integrate security controls into CI/CD pipelines using GitHub Actions and Jenkins; automate SAST/DAST scanning, dependency analysis, and vulnerability reporting as part of DevSecOps workflows.
  • Deploy and manage containerized security environments using Docker and Docker Compose; maintain system configuration automation using Ansible for local labs and client environments.
  • Lead end-to-end vulnerability lifecycle management; triage findings using CVSS, prioritize by exploitability and business impact, and coordinate remediation with engineering teams.
  • Conduct adversarial gap analysis between offensive findings and defensive controls; design and maintain incident response playbooks covering detection, containment, eradication, and recovery.
  • Develop Python and Bash automation scripts for continuous security monitoring, threat intelligence integration, and exposure tracking across client infrastructure.
GitHub ActionsJenkinsDockerDocker ComposeAnsiblePythonWazuhSemgrepBash

Penetration Tester

Apr 2024 - Present
Zerox Innovation (Pvt.) Ltd. · Rawalpindi, Pakistan
  • Conducted full-scope red team engagements across web applications, APIs, internal networks, and external perimeters; delivered CVSS-rated reports with actionable remediation guidance.
  • Performed API security testing using Postman and REST Assured; identified authentication bypasses, IDOR vulnerabilities, broken object-level authorization, and injection flaws.
  • Integrated custom scanning and exploitation scripts into GitLab CI pipelines for repeatable, automated security assessment workflows.
  • Collaborated with development teams on OWASP Top 10 and secure SDLC assessments to embed security upstream in engineering workflows.
  • Researched and replicated emerging CVEs; developed proof-of-concept exploits and documented findings for both technical and non-technical stakeholders.
Burp SuitePostmanREST AssuredMetasploitNmapGitLab CIPythonOWASP Top 10

Freelance Penetration Tester

Apr 2023 - Present
Independent · Remote
  • Conducted independent web application and network penetration testing engagements for clients; delivered risk-rated security assessment reports with prioritized remediation steps.
  • Built and maintained custom offensive security tooling in Python and C to support reconnaissance, exploitation, and post-engagement reporting workflows.
  • Competed actively in CTF competitions and HackTheBox/TryHackMe challenges, applying findings directly to client engagement techniques.
PythonCBurp SuiteMetasploitNmapLinux

Digital Forensics & Security Engineer

Jun 2024 - Sep 2024
National Center of Cyber Security (NCCS) · Islamabad, Pakistan
  • Engineered a high-performance C-based SIEM daemon for real-time file integrity monitoring (inotify), network scanning, event correlation, and anomaly detection; deployed into live government infrastructure.
  • Operated Wazuh, Splunk Enterprise, and Kibana for real-time threat detection, forensic packet investigation, and incident triage in active production environments.
CWazuh SIEMSplunkKibanaInotifyLinuxPOSIX
Selected work

Key Projects

All projects
Academics

Education

B.Sc. Cyber Security (GPA: 3.33 / 4.0)

2023 - 2027
Air University, Islamabad
  • Advanced specialization in Network Security, Applied Cryptography, Reverse Engineering, Malware Analysis, DFIR, Kernel Internals, and Secure Systems Design.
  • Lead operative and captain in university CTF & Red Team competitions.
Credentials

Certifications & Achievements

All 8 certifications, verified against the original documents. Click any card to view the certificate.

Oct 2025

CompTIA PenTest+ Preparation Course Certificate

CompTIA · Coursera

Dec 2025

Certified Cybersecurity Educator Professional (CCEP)

Red Team Leaders

Oct 2025

Cyber Threat Intelligence 101 (Foundation TIA)

arcX

Oct 2025

CSI Linux Certified Investigator (CSIL-CI)

CSI Linux

Oct 2025

Introduction to Cyber Investigations

CSI Linux

Oct 2024

Mastering Reverse Engineering & Malware Analysis (REMASM+)

OCSALY Academy · Udemy

Sep 2024

Digital Forensics Internship Certificate

National Center of Cyber Security (NCCS)

2024

Web Application Security

Udemy

Get the full resume

Download the complete PDF resume, or grab the plain text version.