Mahmoud Adel — Backend Engineer and Offensive Security practitioner based in Cairo, Egypt.
I work at the intersection of building systems and breaking them responsibly. My mindset is analytical: map the attack surface, understand trust boundaries, validate assumptions, and ship fixes that hold up in production—not just in reports.
How I think about security
I approach applications like an attacker would, then engineer mitigations like a builder:
- System mapping — data flows, auth boundaries, and implicit trust between components
- Vulnerability analysis — logic flaws, access control gaps, and API abuse paths (not checklist scanning)
- Evidence-driven testing — reproducible findings with clear impact and remediation
- Defense by design — secure defaults, least privilege, and fail-closed behavior in code I write
This is offensive security discipline applied professionally: curious, precise, and accountable.
Technical focus
Engineering
- Languages: Go, PHP, Python, C++
- Backend: REST APIs, Laravel, clean architecture, JWT/OAuth patterns
- Infrastructure: Docker, Linux, relational databases
Security
- Offensive: Web & API penetration testing, IDOR, race conditions, auth bypass
- Research: Malware triage workflows, OWASP-aligned assessments
- Tools: Burp Suite, Wireshark, Nmap, custom Python tooling
Experience
Security Researcher (Bug Bounty)
HackerOne · 2026 – Present
Independent research on production web applications and APIs. I report validated issues with PoCs and practical remediation guidance for engineering teams.
Full Stack Web Development Intern
ITI · 2025
Built a movie booking platform with authentication, RBAC, and admin workflows—security considerations embedded in access control design.
Network Security Intern
NTI · 2025
Designed segmented enterprise networks with VPNs, firewalls, VLANs, and AAA (TACACS).
Education & certifications
- B.Sc. Computer and Systems Engineering, Helwan University (expected 2027)
- CompTIA Security+ SY0-701, Netriders Academy
- Additional training: Network+, practical ethical hacking, eJPTv2 coursework
Current objectives
Deepening Go backend engineering and API security—shipping secure services while continuing structured vulnerability research on public programs.