amirulisyraf

MOHAMAD AMIRUL ISYRAF

Security Consultant | Penetration Tester | Cyber Security

Experienced professionally as a Security Consultant for more than a year, with foundation in Ethical Hacking and holding a Certified Ethical Hacker (CEH) certification. Aiming a great opportunity for various hands-on experience to stay updated with the latest industry trends as a dedicated Penetration Tester.

EDUCATION

Bachelor’s Degree in Computer Science (Hons.)

National Defence University of Malaysia (NDUM)
CGPA: 3.38
  • Dean's List - Semester 1 2022/2023 (3.78)
  • Relevant Courses: Digital Forensic, Data & Media Forensic, Ethical Hacking
  • Project: Final-Year Project (Email Spoofing Analysis and Reporting System)

Kuala Lumpur, Malaysia

Oct 2020 - Sept 2023

Foundation in Engineering & Defence Technology

National Defence University of Malaysia (NDUM)
CGPA: 2.98
  • Prospective Cadet Officer (Intake In-Charge)

Kuala Lumpur, Malaysia

Class of 2019

Sijil Pelajaran Malaysia

Mara Junior Science College (MRSM) Terendak
  • Student Representative Council

Kem Terendak, Melaka.

2014 - 2018

PROFESSIONAL EXPERIENCE

ASK Pentest SDN. BHD.

Permanent Staff - Team Lead of Resident Engineer (Bank Negara Malaysia)
  • Recommend and implement security testing methodologies tailored to client-specific environments, enhancing cybersecurity controls and operational goals.
  • Lead weekly large-scale Vulnerability Assessments scheduled alongside patch cycles to ensure rapid detection of critical vulnerabilities and minimize threat exposure.
  • Execute deep-dive analysis and validation of findings, eliminating false positives and prioritizing high-risk vulnerabilities to optimize remediation efforts.
  • Provide expert consultation to application owners, delivering actionable remediation plans and preventive strategies that strengthened overall security posture.
  • Represent the Cyber Security Team in weekly meetings, enforcing remediation accountability to expedite risk reduction based on finding severity.

Kuala Lumpur, Malaysia

Oct 2023 – Present

Industrial Training & Internship
  • Performed comprehensive assessment, uncovering vulnerabilities in both external and internal environments.
  • Executed Wireless and Web Applications Penetration Testing to identify weaknesses in networks and websites.
  • Demonstrated expertise in identifying and exploring vulnerabilities, simulating real-world attack scenarios.
  • Delivered detailed report to clients, enabling them to enhance their security posture effectively.
  • Provided tutoring sessions to familiarized clients with attack scenarios and avoid the vulnerabilities.

Kuala Lumpur, Malaysia

March 2023 – Sept 2023

CERTIFICATIONS AND LICENCES

Certified Ethical Hacker Image

Certified Ethical Hacker (CEH)

EC-COUNCIL

- Issued October 2024 - Expires November 2025

- Credential ID ECC8231547906

...

Computer Hacking Forensic Investigator

EC-COUNCIL

- Issued May 2023 - Expires May 2026

- Credential ID ECC4863150279

SKILLS AND CAPABILITIES

TECHNICAL SKILLS

Tools and Software:

Burp Suite Professional, Nessus Professional, Tenable Security Center Plus, Microsoft Excel VBA, Microsoft PowerBI, NMAP, Frida, Metasploit, SQLMap, Wfuzz, Visual Studio Code, VMWare and XAMPP.

Advanced

Programming Languages:

JavaScript, Java, PHP, CSS, Python, MySQL and VBA.

Advanced

Operating System (OS):

Windows, Kali

Advanced

LANGUAGE PROFICIENCY

Bahasa Melayu:
Fluent/Native Speaker

English Language:
Professional Working Proficiency

Hacker Zone

Certified Ethical Hacker Image

SQL Injection Challenge

...

CSRF Challenge

...

JWT Web Token