About
My name is Amir, and I am a penetration tester and security researcher specializing in web application and mobile security. Over the past few years, I have conducted approximately nine professional penetration tests, spent two years in bug bounty programs, and worked on security research ranging from HP iLO firmware to AI adversarial robustness.
Capabilities
Manual code review, blackbox web testing, mobile application security, Android reverse engineering, and API abuse testing. Experienced with PHP, Python, JavaScript, Bash, and typical security tooling.
On the response side I have handled incident triage, breach containment, disaster management exercises, and post-mortem root cause analysis.
Research
HP iLO firmware security research — identifying vulnerabilities in server management firmware that could lead to full host compromise. AI security research focusing on adversarial inputs and failure modes in deployed machine learning systems.
Client Work
Web application penetration tests for private clients across multiple sectors. Deliverables include evidence-backed findings reports, remediation guidance, and retesting. I also conduct security reviews of in-house applications and APIs before production deployment.
Focus Areas
- Web application security testing (blackbox & greybox)
- Android application security & reverse engineering
- Bug bounty hunting across private & public programs
- Incident response & disaster management
- Red Team operations and adversary simulation
- Security research (firmware, AI, protocol)
Contact
If you need a security review, penetration test, or just want to discuss something security-related — reach out.