About

About

Mahmoud Adel — Backend Engineer and Offensive Security practitioner based in Cairo, Egypt.

I work at the intersection of building systems and breaking them responsibly. My mindset is analytical: map the attack surface, understand trust boundaries, validate assumptions, and ship fixes that hold up in production—not just in reports.

How I think about security

I approach applications like an attacker would, then engineer mitigations like a builder:

  • System mapping — data flows, auth boundaries, and implicit trust between components
  • Vulnerability analysis — logic flaws, access control gaps, and API abuse paths (not checklist scanning)
  • Evidence-driven testing — reproducible findings with clear impact and remediation
  • Defense by design — secure defaults, least privilege, and fail-closed behavior in code I write

This is offensive security discipline applied professionally: curious, precise, and accountable.

Technical focus

Engineering

  • Languages: Go, PHP, Python, C++
  • Backend: REST APIs, Laravel, clean architecture, JWT/OAuth patterns
  • Infrastructure: Docker, Linux, relational databases

Security

  • Offensive: Web & API penetration testing, IDOR, race conditions, auth bypass
  • Research: Malware triage workflows, OWASP-aligned assessments
  • Tools: Burp Suite, Wireshark, Nmap, custom Python tooling

Experience

Security Researcher (Bug Bounty)

HackerOne · 2026 – Present

Independent research on production web applications and APIs. I report validated issues with PoCs and practical remediation guidance for engineering teams.

Full Stack Web Development Intern

ITI · 2025

Built a movie booking platform with authentication, RBAC, and admin workflows—security considerations embedded in access control design.

Network Security Intern

NTI · 2025

Designed segmented enterprise networks with VPNs, firewalls, VLANs, and AAA (TACACS).

Education & certifications

  • B.Sc. Computer and Systems Engineering, Helwan University (expected 2027)
  • CompTIA Security+ SY0-701, Netriders Academy
  • Additional training: Network+, practical ethical hacking, eJPTv2 coursework

Current objectives

Deepening Go backend engineering and API security—shipping secure services while continuing structured vulnerability research on public programs.

Contact

Open channels for recruiters, engineers, and security researchers.