Yurii
Penetration Tester
- Місто проживання:
- Львів
- Готовий працювати:
- Дистанційно
Контактна інформація
Шукач вказав телефон .
Прізвище, контакти та світлина доступні тільки для зареєстрованих роботодавців. Щоб отримати доступ до особистих даних кандидатів, увійдіть як роботодавець або зареєструйтеся.
Отримати контакти цього кандидата можна на сторінці https://www.work.ua/resumes/19681660/
Завантажений файл
Це резюме розміщено у вигляді файлу. Ця версія для швидкого перегляду може бути гіршою за оригінал резюме.
Penetration Tester
PROFILE
Web application and cloud penetration tester with hands-on commercial experience across a direct fintech engagement and an active
bug bounty program. Owns the full assessment lifecycle independently — scoping, manual exploitation, CVSS-based risk scoring, and
client-facing reporting — aligned with ISO 27001 and DORA compliance requirements. Complements web/cloud specialization with
CRTP-certified Active Directory attack experience, backed by a structured, continuous self-training program across offensive security
disciplines.
EXPERIENCE
Baltum — Penetration Tester (Subcontractor) | 05/2026 – Present | Fintech platform | Remote
• Operate as an independent subcontractor, owning the full engagement lifecycle solo — scoping, testing, reporting, and client
communication
• Conducted manual web application and cloud security assessments, documenting 15+ vulnerabilities across broken access control, IDOR,
cloud IAM misconfigurations — including 1–3 rated Critical/High severity
• Scored all findings using CVSS and prioritized remediation by business risk and exploitability
• Authored full assessment reports with reproduction steps, severity ratings, and remediation guidance
• Aligned testing scope and reporting with ISO 27001 and DORA regulatory requirements
H-X Technologies — Bug Bounty Hunter (Subcontractor) | 06/2026 – Present | Remote
• Actively perform bug bounty testing on web application and cloud assets within program scope, applying the same manual, attacker-driven
methodology used in commercial engagement work
• Focus on broken access control, IDOR, and cloud misconfiguration classes, building and adapting reconnaissance and exploitation tooling to
program-specific attack surface
SKILLS
Web Application Security
Manual, attacker-driven testing methodology using Burp Suite — intercepting and modifying requests, probing authentication and
session logic, and validating access control boundaries beyond what automated scanners surface. Practical exploitation experience
across broken access control, IDOR, XSS (including session hijacking), SSTI-to-RCE, SSRF (including internal resource access and
metadata abuse), LFI-to-RCE chains, and business logic flaws that require understanding application flow rather than pattern matching.
Attack surface expansion through content discovery and parameter fuzzing with ffuf, Gobuster, dirsearch, Subfinder, and httpx —
consistently uncovering hidden endpoints and unlinked functionality that scanners miss.
Cloud & Container Penetration Testing
AWS — IAM privilege escalation paths, S3/storage exposure, Lambda and EC2 misconfigurations, VPC network review, and CloudWatch
log/config enumeration. Azure — App Service and Key Vault access flaws, RBAC misconfigurations, and network rule bypass. GCP — IAM
and service account abuse, instance metadata service exploitation, and Google Workspace attack vectors. Kubernetes — RBAC
misconfiguration, service account token abuse, and pod-level privilege escalation. Comfortable moving across all three major cloud
providers rather than specializing in a single one, reflecting hands-on practice through both structured labs (PwnedLabs, CloudGoat) and
applied engagement work.
Exploitation Tooling & Automation
Build custom Python PoC scripts and exploitation utilities to validate findings and demonstrate concrete attacker impact — not just flag a
vulnerability, but show what an attacker can actually do with it. Scripts span JWT verification bypass, LDAP/NoSQL injection, and
chained exploitation scenarios. C++ (Boost.Asio) for lower-level, asynchronous network reconnaissance tooling where Python-based
alternatives are too slow or too high-level. Bash for recon and enumeration workflow automation, reducing repetitive manual steps
across engagements.
Active Directory / Internal Security
Full-lifecycle AD compromise methodology: protocol-level enumeration across SMB, LDAP, and Kerberos to map domain structure and
surface misconfigurations invisible to surface-level scans; privilege escalation via Kerberoasting, ACL abuse, and delegated permission
exploitation; lateral movement and post-exploitation with Impacket and native Windows techniques, staying close to legitimate traffic
patterns to simulate real adversary behavior. Operate Sliver C2 for post-exploitation and command-and-control, leveraging
SharpCollection for in-memory .NET tool execution. Tooling anchored around BloodHound for attack path visualization, Impacket,
NetExec, and Certipy for AD CS abuse.
TOOLS
• Recon & Scanning — Nmap, Whois, Nessus, Subfinder, httpx
• Web Testing — Burp Suite, ffuf, Gobuster, dirsearch, sqlmap, WPScan
• Active Directory — BloodHound, Impacket, NetExec, Certipy, Responder, Evil-WinRM, Mimikatz, SharpCollection
• C2 & Post-Exploitation — Sliver C2, Metasploit, proxychains, socat
• Password Attacks — Hashcat, John the Ripper, Hydra
• Cloud & Containers — AWS CLI, Azure CLI, gcloud, kubectl, AzureHound
• Custom Tooling — PenrecBoost (C++/Boost.Asio), ADExplorer/Penrec, Python PoC scripts
LEARNING & RESEARCH
Structured, self-directed training program across web, cloud, and Active Directory offensive security — translated into reusable methodology
and tooling rather than isolated lab completions.
• - Maintain personal playbooks for AD/Red Team and Cloud Penetration Testing (AWS/Azure/GCP/Kubernetes), consolidating tooling,
technique notes, and engagement checklists into reusable reference material
• - Solved 100+ HackTheBox machines across difficulty levels, with hands-on practice across six HTB Pro Labs (Dante, Offshore,
RastaLabs, Cybernetics, Shinra, Zephyr) — enterprise-scale Active Directory environments simulating full corporate network
compromise
• - Completed HTB Academy modules on IDOR, SSRF, SSTI, SSI, XML/XSLT injection, XSS, and pivoting — building structured theory
behind the exploitation techniques used in hands-on labs
• - Completed PortSwigger Web Security Academy labs on advanced exploitation — server-side parameter pollution, HTTP request
smuggling, business logic flaws, authentication bypass
• - Completed cloud-focused offensive labs across AWS, Azure, and GCP (PwnedLabs, CloudGoat) — covering IAM privilege escalation,
metadata service abuse, misconfigured service accounts, and credential exposure through instance metadata
• - Designed and built VulnShop, an original HackTheBox machine chaining IDOR → Stored SSRF → race condition → group
misconfiguration privilege escalation — currently under HTB review
• - Develop a Python poc-scripts collection targeting specific vulnerability classes — JWT verification bypass, LDAP/NoSQL injection,
XSS-to-NoSQL exploitation chains — used to validate impact beyond proof-of-concept
• - Maintain a public write-up repository documenting exploitation methodology across solved HTB machines
CERTIFICATIONS
• Certified Red Team Professional (CRTP)
LANGUAGES
• English — C1
• Polish — B1
• Russian — native
• Ukrainian — native
EDUCATION
Bachelor in Computer Science, Rzeszow University of Technology | 10/2023 – Present | Rzeszow, Poland
In progress
Схожі кандидати
-
Аудитор безопасности веб-сайтов, penetration tester
20000 грн, Дистанційно, Київ -
Trainee Penetration Tester
Дистанційно, Одеса -
Penetration Tester
Дистанційно, Дніпро , ще 2 міста -
Junior Penetration Tester
Дистанційно, Київ -
Penetration Tester
Дистанційно, Київ