Application Security | Web Security | Secure Code Review
Syed Muhammad Asees Shah
I work as an Application Security engineer across web security, API security, and secure code review. I use real software projects, labs, and write-ups to find issues, fix them properly, and explain the work clearly while continuously developing my security engineering depth.
About
Building security depth on top of real software projects
I am an Application Security engineer with a software development background and a BS Computer Science education at the University of Peshawar. My work focuses on Application Security, Web Security, API Security, and Secure Code Review.
My software development background helps me understand how applications are built, where security issues emerge, and how to remediate them. I document that work through labs, reports, secure code reviews, and GitHub projects.
I have completed focused AppSec training and hands-on security labs across authentication, access control, API security, and web vulnerabilities. I also review real application code, identify security risks, and implement practical fixes such as input validation and prepared statements.
Snapshot
Experience
Security internships and hands-on security work
Offensive Security Intern
- Completed an offensive security internship focused on reconnaissance, web application testing, and vulnerability analysis.
- Worked with Burp Suite, Nmap, Metasploit, recon workflows, and practical red-team methodology in authorized lab environments.
- Produced testing and reporting work aligned with real security assessment processes.
Education
Skills
Security areas and engineering tools
Projects
Security-focused work and software projects
Blogs
Writing
Short, practical AppSec notes from security engineering and secure code review work.
My Progress
Key milestones and public proof
My recent work is focused on secure code review, security engineering, and clear public documentation.
Week 2 done
TaskVault project and the planned Week 2 AppSec work were completed and documented.
Week 3 done
Completed IBM Application Security for Developers and DevOps Professionals and seven related labs.
Portfolio updates
Keeping GitHub, roadmap, and project proof aligned with real completed work.
Certifications
Training and credentials
Contact
Open to AppSec and Product Security opportunities
I am open to AppSec internships, junior security opportunities, project collaboration, and discussions around secure code review, web security, and practical security work.