Jawad Mahdi

Offensive Security Researcher · Penetration Tester · Red Teamer

I’m an offensive security researcher and penetration tester with 3+ years of hands-on experience across web applications, APIs, mobile applications, networks, Active Directory, vulnerability assessment, and red-team operations.

My work combines offensive-security testing, research, automation, and engineering. I turn validated weaknesses into reproducible evidence, proportionate risk context, and remediation guidance that security leaders and engineering teams can act on.

Reading mode

Experience

Security administration, penetration testing, authorized research, and evidence-led communication across commercial and confidential environments.

One-year contract

Microsoft 365 & Security Administrator

Confidential maritime company · Malaysia

Administered Microsoft 365, Microsoft Entra ID, and Microsoft Defender with tenant-wide privileges, maintaining identity, access, security configuration, and day-to-day platform administration.

Confidential engagement

Confidential Security Researcher

Confidential security environment · Organization withheld

Supported authorized security research under strict confidentiality obligations. Organization, mission, systems, scope, methods, findings, and outcomes remain withheld.

Independent

Bug Bounty Researcher

Synack Red Team · HackerOne · Bugcrowd

Assessed web applications, APIs, mobile applications, and network infrastructure for authorized programs, working with security teams through validation and remediation.

Review CTF competition record and evidence

Services

Authorized offensive-security services supported by hands-on testing, engineering capability, and evidence-led reporting. Every engagement requires written permission and a defined scope.

01

Web Application Penetration Testing

Assess authentication, authorization, session management, input handling, business logic, and common OWASP Top 10 risks across modern web applications.

02

API Penetration Testing

Assess application APIs for broken object-level authorization, authentication flaws, excessive data exposure, injection, rate-limit weaknesses, and workflow abuse.

03

Network Penetration Testing

Assess exposed services, configuration weaknesses, segmentation, credential paths, and controlled privilege-escalation opportunities across internal or external networks.

04

Red Teaming

Conduct objective-led attack simulations across people, applications, identity systems, and infrastructure under documented rules of engagement.

05

Web Source Code Review

Review web application source for unsafe data flows, access-control gaps, injection paths, exposed secrets, insecure dependencies, and implementation flaws.

06

Mobile Application Penetration Testing

Assess mobile applications and supporting APIs for insecure storage, transport, authentication, authorization, and application-logic weaknesses.

07

Security Tool & Exploit Development

Build security automation, research tooling, and controlled proof-of-concept exploits that make validation and reporting repeatable in authorized environments.

08

AI Red Teaming & AI Application Testing

Assess AI-enabled applications for prompt and data-boundary failures, unsafe tool use, access-control gaps, sensitive-data exposure, and abuse-resistant workflow design.

All testing is permission-based and scoped in writing. Sensitive targets, client evidence, and exploit details are never published without authorization.

Skills

Hands-on capability across offensive testing, security tooling, software engineering, data systems, and established security methods.

Penetration Testing

Web applications · APIs · Mobile applications · Networks · Active Directory · Vulnerability assessment · Red teaming

Security Tools

Burp Suite Pro · Nmap · Metasploit · Nuclei · Katana · Wireshark · OpenVAS · Kali Linux

Engineering & Methods

Python · Bash · C/C++ · TypeScript · React · Electron · Node.js · Django · Docker · MongoDB · PostgreSQL · Elasticsearch · MCP · OWASP Top 10 · MITRE ATT&CK · CVSS · OSINT

About

Computer-science foundations, practical security research, and evidence-led communication.

My background combines computer-science study with independent security research, coordinated disclosure, application engineering, and security-tool engineering.

I separate observation from inference, validate before claiming impact, and document findings so both security leaders and engineering teams can act.

Education

BSc (Hons) Computer Science
Taylor’s University / University of Bristol
CGPA 3.69 · 2023—2026

Real Projects

Selected product engineering, offensive-security tooling, and controlled assessment evidence.

01

EntityLens

Offensive-security research workspace for controlled evidence analysis and permission-aware OSINT.

EntityLens research workspace showing an authorized synthetic demo datasetOpen full-size evidence

What it is

A local-first workspace that turns authorized research data into structured evidence, high-volume analysis, interactive visualization, and read-only AI access through the Model Context Protocol (MCP).

What I built

Case-oriented persistence, structured search and filtering, resumable background operations, controlled exports, and defensive desktop integration.

What it proves

Application engineering, responsible OSINT design, resilient workflows, evidence quality, and permission-aware AI integration.

TypeScript · React · Electron · Node.js · MCP

Read architecture case study

Additional Projects

Supporting evidence across autonomous assessment, monitoring, and confidentiality-bound work.

Sanitized MJZ autonomous pentest agent terminal demonstrating evidence validation with synthetic data
05

MJZ Autonomous Pentest Agent

A local-first, AI-assisted platform for authorized web and API testing, source analysis, deterministic scope control, isolated specialist workflows, evidence retention, and reproducible reporting.

Codex / OpenCode · Burp Suite MCP · Docker · Nuclei
Credential breach monitoring project interface
06

Credential Breach Monitoring

Monitoring and analysis work built with Django and Elasticsearch.

Django · Elasticsearch
Confidential security assessment placeholder with no client information
07

Confidential Security Assessments

Selected authorized work remains private under confidentiality obligations.

NDA Protected

Security Recognition

Selected outcomes from a broader body of in-scope vulnerability research, supported by reproducible evidence, program validation, and responsible disclosure.

Disclosure record

Selected highlights

The organizations shown here represent selected outcomes from a wider record of authorized reports and research activity.

What the recognition means

For the selected public examples below, eligible in-scope reports passed program triage, received bounty awards, and were formally acknowledged. They do not represent every submission.

  1. Authorized scope

    Testing followed the program’s published scope, authorization, and disclosure rules.

  2. Reproducible report

    Each submission included reproducible evidence, impact analysis, attack context, and remediation guidance.

  3. Validated outcome

    Program triage confirmed eligible disclosures before bounty awards and acknowledgements were issued.

Selected public examples

Bounty acknowledgements

These organizations publicly identify selected validated outcomes—not the total volume of reports submitted.

  • U.S. Department of DefenseBounty awarded · Acknowledged
  • AppleBounty awarded · Acknowledged
  • University of CambridgeBounty awarded · Acknowledged
  • The Coca-Cola CompanyBounty awarded · Acknowledged
  • Dell TechnologiesBounty awarded · Acknowledged
Research channels

Authorized platforms

Scoped testing and coordinated-disclosure channels used under their published program rules.

  • Synack Red Team

    Assigned, authorized testing scope.

  • HackerOne

    Coordinated-disclosure programs.

  • Bugcrowd

    Coordinated-disclosure programs.

Recognition records describe authorized vulnerability-disclosure outcomes—not client work, employment, sponsorship, or endorsement. Organization and platform marks identify the receiving program or authorized research channel only.

Credentials

All ten professional credentials are shown together, with the most role-relevant certifications presented first.

eWPTX advanced web application penetration testing certificate issued to Jawad Mahdi
Web Application Security

Web Application Penetration Tester eXtreme

eWPTX · INE Security

Verify credential ↗
Google Cybersecurity Professional Certificate issued to Jawad Mahdi
Cybersecurity Foundations

Google Cybersecurity Professional Certificate

Google · Coursera

Verify credential ↗
Certified Cybersecurity Educator Professional certificate issued to Jawad Mahdi
Security Education

Certified Cybersecurity Educator Professional

CCEP · Red Team Leaders

Verify credential ↗

Writeups & Research

Practical security writing that shows how I investigate, validate, connect, and communicate application-security findings.

Using Burp Suite MCP with AI to Assess a Supabase Application

Shows how an AI-assisted web assessment moved from initial signals to validated security findings through controlled testing, tool orchestration, and repeatable documentation.

Read writeup ↗

Chaining OSINT, IDOR, and RCE

Explains how open-source intelligence, broken access control, and remote code execution combined into one exploit chain—and how to reason about the complete risk.

Read writeup ↗

A Weird Bug That Leaked PII

Breaks down an unusual application behavior that exposed personally identifiable information, how the issue was reproduced, and why ordinary user flows still require careful validation.

Read writeup ↗
View all six research articles

Contact Me

For offensive-security roles, authorized assessments, and selected technical collaborations.

Send a message

Use this private form to begin a professional conversation. Your reply address is sent securely to the contact endpoint and is not published on the website.

Please do not include credentials, client data, or confidential evidence. We can establish a safer channel if the conversation needs one.

Open one-page résumé

Your details are used only to deliver and reply to this message. No public email address is exposed.

Evidence preview