
Shahzaib Ahmed
Reverse Engineer
Compétences

Voir mes services


Portfolio
Expérience professionnelle
Mobile Application Security Consultant
Systems Limited • Temps plein
Aug 2021 - Present • 5 yrs 1 mo
Providing authorized security assessments for Android applications and backend APIs, with a focus on identifying confirmed vulnerabilities and delivering practical remediation guidance. Key responsibilities: • Conduct static and dynamic security analysis of authorized Android applications. • Assess REST, GraphQL and mobile-backend APIs for authentication, authorization, access-control, input-validation and sensitive-data risks. • Analyze APK structure, Java and Kotlin components, native ARM or ARM64 libraries and runtime application behavior. • Review network communication, local data storage, cryptographic implementation and application security configurations. • Evaluate protections including obfuscation, root detection, anti-debugging and anti-tampering controls. • Apply OWASP MASVS, OWASP Mobile Top 10 and OWASP API Security Top 10 principles during assessments. • Use Frida, Burp Suite, Ghidra, JADX, MobSF, Postman, ADB and custom scripts within approved testing scopes. • Produce professional reports containing severity ratings, evidence, affected components, business impact and actionable remediation recommendations. All assessments are conducted only on systems owned by the client or explicitly authorized for testing.
Android Reverse Engineer
ZZ Group Company CCS
Mar 2021 - Feb 2026 • 4 yrs 11 mos
Worked as an Android Reverse Engineer specializing in mobile application security testing, reverse engineering, and vulnerability assessment. Conducted in-depth static and dynamic analysis of Android applications to identify security flaws, logic vulnerabilities, and data exposure risks. Key Responsibilities & Achievements: Performed APK reverse engineering using Smali, JADX, Ghidra, and Apktool Conducted dynamic analysis and runtime instrumentation using Frida and Objection Identified and bypassed SSL pinning implementations for security testing purposes Analyzed API endpoints, authentication flows, and token security Executed mobile penetration tests using Burp Suite and MITM proxy tools Discovered critical vulnerabilities including insecure data storage, hardcoded secrets, and improper authentication Delivered detailed security assessment reports with CVSS scoring and remediation guidance Assisted development teams in implementing secure coding practices