Hi, my name is

Mehedi Hasan

I break systems to protect them.

I’m an Application Security professional, focused on finding high-impact vulnerabilities across Web, API, Mobile, and Infrastructure and helping teams fix them effectively.

0xAbout Me

I am a cybersecurity professional with hands-on experience in Application Security, Vulnerability Assessment & Penetration Testing (VAPT), and Red Team Operations. I combine a strong academic foundation with practical industry expertise to approach security from both engineering and adversarial perspectives.

I hold a BSc in Software Engineering (major in Cyber Security) from Daffodil International University.

Currently at Ernst & Young (EY), I conduct security assessments for banking and telecommunications clients, identifying high-impact vulnerabilities and supporting effective remediation in complex, real-world systems. My work has received recognition from clients for both quality and impact.

Previously, I worked as a Software Security Engineer at City Bank PLC, where I led application security initiatives and conducted assessments across 100+ web, mobile, and APIs, helping to significantly improve the organization's security posture through close collaboration with development teams. Before City Bank, I worked at Trustaira, focusing on applied security research and real-world vulnerability assessments.

I actively conduct independent security research and discovered & reported public CVEs. Alongside this, I am engaged in teaching and mentoring aspiring cybersecurity professionals as a Graduate Teaching Assistant at the University of Dhaka, contributing to applied research initiatives and helping the next generation of security talent.

Mehedi Hasan

0xWhere I've Worked

Associate Consultant, Cybersecurity: Red Team Operations @ Ernst & Young(EY)

July 2025 - Ongoing

  • Received client appreciation twice from one of the largest telecom operators in Bangladesh for exceptional findings and delivery, resulting in an additional engagement for EY.
  • Resolved a critical testing blocker that stopped the team from testing by implementing an alternative method, restoring penetration testing for both web and mobile applications.
  • Conducts penetration testing for web, mobile, and APIs, improving security for major telecom and banking clients.
  • Drives red team operations through attack simulations, vulnerability assessments, and remediation planning.
  • Common and high-severity findings include Privilege Escalation, Remote Code Execution (RCE), SQL Injection, Account Takeover, and mobile-specific issues such as insecure storage, hardcoded secrets, certificate pinning, root detection bypass, and Play Protect bypass.
  • Recognized as a key team member; directly engaged in critical business applications, especially APIs and mobile applications, including those with complex dependency VAPT requirements, in addition to other ongoing engagements.

0xEducation

Formal Education

2018 - 2022

BSc in Software Engineering (Major: Cyber Security)

Daffodil International University

CGPA: 3.80 out of 4.00

  • Earned 151 Credits including 31 Credits in Cyber Security.
  • Major (Cyber Security) course includes – Cyber Security Fundamentals, Ethical Hacking & Countermeasures, Security Analysis & Penetration Testing, Digital Forensic, Cryptography and Secure Application, Cyber Law, Network & Communication Security.
  • Undergraduate Thesis Title: Automated Detection of IDOR Vulnerability in Web Application.

Professional Trainings

Penetration Testing/Red Teaming

@ Internetwork Expert

October 2023

  • Completed 148 hours long training on 'Penetration Testing/ Red Teaming'.
  • Learned topics like Enumeration, Host & Network Based Attacks, Pivoting, Persistence, Web Based Attacks.
  • Completed all the 120 labs of the course.
  • Passed the Practical 48-hour Exam cracking all the boxes.

Penetration Testing/Red Teaming

@ Internetwork Expert

October 2023

  • Completed 148 hours long training on 'Penetration Testing/ Red Teaming'.
  • Learned topics like Enumeration, Host & Network Based Attacks, Pivoting, Persistence, Web Based Attacks.
  • Completed all the 120 labs of the course.
  • Passed the Practical 48-hour Exam cracking all the boxes.

Relevant Courses

YearTitleOrganizationLink
2023Writing Manuscript for High Impact Publications : DOs and DONTsABCD Laboratory
2023Writing in the SciencesStanford University(Coursera)
2023Python for Data Visualization: Matplotlib & SeabornCoursera
2023How to Write and Publish a Scientific Paper (Project-Centered Course)École Polytechnique (Coursera)
2023API Penetration TestingAPISec University
2022ISC2 Certified in Cybersecurity (CC) Cert PrepLinkedin
2020Web Scraping with Beautiful SoupCodecademy
2020Python 3Codecademy
2020Bash ScriptingCodecademy
2020Basics of Regular ExpressionsCodecademy

0xRecognition

Professional Certifications

YearTitleOrganizationCertification IDLink
2020Certified Ethical HackerEc-CouncilECC5894271603
2024Certified Professional Penetration Tester (eCPPT)eLearnSecurity (INE)100172202
2023Junior Penetration Tester (eJPT)eLearnSecurity (INE)84233046
2025Junior Penetration Tester (PT1)TryHackMe3fba18f6-6f9b-4769-b215-10ec8f3f353e
2025API Security Certified Professional(ASCP)APISec University3385f67b-593f-4033-90b6-53d1f1fef71a
2023Certified in CybersecurityISC21466627
2022SWIFT Customer Security ProgrammeSWIFT0001291747
2022Certified AppSec PractitionerThe SecOps Group6886698
2023Certified Network Security PractitionerThe SecOps Group7147022
2023NSE 1 Network Security AssociateFortinetaWHJ5zDA9G
2023NSE 2 Network Security AssociateFortinetUgTxQRv2EO
2022ISO/IEC 27001 Information Security AssociateSKILLFRONT45272227180484

Achievements

YearTitleOrganizationRoleRankLink
2023Inter University CTFBUETTeam Coach2nd Runner-Up
2021National Cyber Drill 2021BGD e-GOV CIRTTeam Captain5th (1st runner-up as per the points)
2021Inter University Cyber Drill 2021BGD e-GOV CIRTTeam Captain2nd Runner-Up
2021Incognito 2.0 (Our 1st International CTF)IIIT LucknowTeam Captain12th Globally
2020National Cyber Drill 2020BGD e-GOV CIRTTeam Captain9th (1st among Educational Institutions)

Honours & Awards

YearTitleOrganizationLink
2018-2022Merit Based Scholarship to Complete UndergraduateDaffodil International University
2022Awareded Fully Funded Erasmus Plus International Credit Mobility scholarshipStaffordshire University

0xGet In Touch

What's Next?

I am currently looking for new opportunities in Red Teaming and Application Security. Whether you have a question or just want to say hi, I'll try my best to get back to you!

Designed & Built by Mehedi Hasan