Summary
Overview
Work History
Education
Skills
Websites
Certification
Timeline
Generic

Abdelhak Kherroubi

Security Engineer
Dubai,Dubai

Summary

Results-driven Security Engineer with over 6 years of experience securing enterprise IT environments. Proven expertise in penetration testing, vulnerability assessments, and threat remediation across web, network, and mobile platforms, with a focus on financial and enterprise infrastructures. Skilled in identifying and mitigating security vulnerabilities through manual and automated testing. Experienced in implementing robust security protocols, reverse engineering mobile apps and web, analyzing API security, and utilizing tools like Burp Suite, Metasploit, Nessus, and Wireshark. Proficient in scripting with Python, Bash, and JavaScript to automate security tasks and enhance operational efficiency.

Overview

8
8
years of professional experience
3
3
Certifications
3
3
Languages

Work History

Security Researcher

HackerOne
02.2017 - Current
  • Recognized by Twitter on its Top Security Researchers Acknowledgment Page — ranked 13th globally in 2019.
  • Reported 5+ confirmed vulnerabilities to Twitter’s security team, including critical flaws; also submitted critical vulnerabilities to Google (accepted & in process) and Slack (accepted, awarded bounty).
  • Acknowledged in Hall of Fame pages for notable vendors including Mimecast, TIBCO, SideFX, and Acronis.
  • Discovered vulnerabilities across multiple private programs on HackerOne, including broken access controls, XSS, and authentication flaws.
  • Active Capture the Flag (CTF) participant and ranked hacker on Hack The Box — solved various Easy and Medium-rated machines.
  • Authored public research on banking and financial application vulnerabilities with critical business logic impact.
    Read: Hacking Banks – Broken Access Control [https://medium.com/@protostar0/hacking-banks-broken-access-control-vulnerability-in-banking-application-part-i-c442ed5ae170]

Security Engineer

Arab Leasing Corporation, ALC
10.2021 - 10.2022

- Conducted internal and external penetration tests, including phishing simulations and network assessments, to identify and remediate security vulnerabilities.

- Led the implementation and administration of enterprise security solutions, enhancing the organization’s security posture across systems and endpoints.

- Managed and configured tools such as Nexpose, BeyondTrust PRA, Fortinet security suite (FortiGate, FortiSIEM), Sophos, endpoint detection and response (EDR) platforms, and antivirus solutions.

- Collaborated with IT and infrastructure teams to ensure secure deployment and integration of tools across the enterprise environment.

Cyber Security Specialist

Data Impact
01.2020 - 01.2021
  • Conducted full-scope penetration testing on the organization’s assets, including web applications, internal systems, and mobile platforms.
  • Performed reverse engineering on Android and iOS mobile applications to uncover hidden behaviors, insecure API calls, and cryptographic flaws.
  • Developed custom automation tools using Python and Bash, enhancing the efficiency of repetitive security testing tasks and internal workflows.
  • Worked directly with development and infrastructure teams to analyze root causes and implement secure code fixes, strengthening the organization’s overall security posture.

Security Engineer | Reverse Engineer

KnotAPI
02.2022 - Current
  • Led and executed comprehensive penetration testing across the company’s full asset landscape, including web dashboards, mobile SDKs (iOS & Android), and internal APIs.
  • Identified and remediated 20+ security vulnerabilities, ranging from logic flaws to critical issues, prior to external assessments by Software Secure—which subsequently found no critical or high-risk vulnerabilities, validating the robustness of internal testing.
  • Conducted reverse engineering of heavily obfuscated Android and web applications to uncover hidden APIs and analyze cryptographic implementations for weaknesses.
  • Performed in-depth secure code reviews and implemented or recommended fixes across diverse tech stacks:
    PHP (Laravel framework)
    Java (Android)
    Python
    TypeScript
  • Built and maintained custom security tools to assist developers in secure coding practices, including automated scripts that scan published platforms for hardcoded credentials, tokens, and API keys.
  • Collaborated with engineering teams to integrate security best practices into development workflows and SDLC processes.

Education

Master's Degrees - Computer Networking

UNIVERSITY IBN Khaldoun
09.2018 - 10.2020

Bachelor of Science - Computer And Information Sciences

Ibn Khaldoun
Tiaret,Algeria
04.2001 -

Skills

  • Web Application Penetration Testing

  • Vulnerability Assessment

  • Reverse Engineering (Web & Mobile Apps)

  • Network Security Assessment

  • Security in SDLC

  • OWASP Top 10

  • Banking App API Reverse Engineering

  • API Security Testing

  • Cryptography

Certification

The BeyondTrust Privileged Remote Access

Timeline

Security Engineer | Reverse Engineer

KnotAPI
02.2022 - Current

Security Engineer

Arab Leasing Corporation, ALC
10.2021 - 10.2022

Cyber Security Specialist

Data Impact
01.2020 - 01.2021

Master's Degrees - Computer Networking

UNIVERSITY IBN Khaldoun
09.2018 - 10.2020

Security Researcher

HackerOne
02.2017 - Current

Bachelor of Science - Computer And Information Sciences

Ibn Khaldoun
04.2001 -
Abdelhak KherroubiSecurity Engineer