Skip to content
View mamgad's full-sized avatar

Block or report mamgad

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mamgad/README.md

Mohamed Amgad Khater

LinkedIn Twitter GitHub

πŸ‘¨β€πŸ’» About Me

Senior Security Engineer with expertise in Application Security, DevSecOps, and Cloud Security. Currently working at Unifonic, focusing on enterprise-wide security solutions and cloud-native security architecture.

πŸ”­ Current Role

Senior Security Engineer @ Unifonic

  • Contributing to DevSecOps pipeline implementation with focus on security automation
  • Working on security solutions for AWS and Kubernetes environments
  • Participating in architecture reviews and threat modeling activities

πŸ›‘οΈ Security Research

HackerOne Bugcrowd

  • Discovered and responsibly disclosed critical vulnerabilities in Fortune 500 companies
  • Notable companies: Twitter, Sony, Adobe, TripAdvisor, Ford Motors, Pinterest, Dell
  • Published CVEs: CVE-2017-1000058 (Stored XSS at Chevereto CMS), CVE-2018-5222

πŸŽ“ Certifications

Advanced Security

  • Offensive Security Web Expert (OSWE)
  • Certified Cloud Native Security Expert (CCNSE)
  • Certified Container Security Expert (CCSE)
  • Certified DevSecOps Professional (CDP)

Penetration Testing

  • Web Application Penetration Tester Extreme v2 (eWPTXv2)
  • Certified Professional Penetration Tester v2 (eCPPTv2)
  • Mobile Application Penetration Tester (eMAPT)

πŸ’» Technical Skills

Software Development

  • Primary Languages: Python, Java, JavaScript
  • Additional: Ruby on Rails, MySQL, Bash

Application Security

  • Security Testing: SAST, DAST, Penetration Testing
  • Security Tools: BurpSuite Pro, OWASP ZAP, Nuclei, Subfinder, httpx, Nmap, Metasploit, Wireshark, SonarQube, Semgrep, Trivy

Cloud & Infrastructure

  • Cloud Security: AWS, Kubernetes, Docker
  • DevSecOps: CI/CD Pipeline Security, IaC, Security Automation

πŸš€ Featured Project

A comprehensive training project demonstrating common security vulnerabilities in banking applications.

  • Built with Python, Flask, SQLAlchemy, React, JWT Authentication
  • Includes modules on secure code review, authentication vulnerabilities, and API security
  • Implements real-world security scenarios and industry security standards

Pinned Loading

  1. DVBLab DVBLab Public

    This course uses a deliberately vulnerable banking application to demonstrate common security vulnerabilities, their impact, and how to fix them. The application is built with Flask (backend) and R…

    JavaScript 43 3

  2. Magdz/Pipeline-MIPS-Processor Magdz/Pipeline-MIPS-Processor Public

    VHDL

  3. RUDPy RUDPy Public

    A reliable UDP implementation in Python.

    Python 32 15

  4. WServer WServer Public

    Forked from SubNader/WServer

    An HTTP over TCP web server, written in C.

    C

  5. BlackJack-Cards-Game BlackJack-Cards-Game Public

    simple cards game

    Java

  6. Genetic-Algorithm-solving-Travelling-Salesman Genetic-Algorithm-solving-Travelling-Salesman Public

    Solving travelling salesman problem using artificial intelligence with real time plotting for visualization of paths and performance

    Python