Hello, It's Me

Md Mahfuzur Rahman

And I'm a

I am currently working as an Associate Cloud Security Engineer at SELISE Group, with prior experience as a Cybersecurity Engineer at EIC Limited. I completed my B.Sc. in Software Engineering (Major in Cybersecurity) from DIU. I work on cloud security, VAPT for web and mobile applications, secure code review, and compliance-focused assessments. I actively participate in CTF competitions and continuously improve my offensive security skills. If you need any security help, you can hire me.

Download CV

About Me

Cybersecurity Engineer !

Hi, myself Mahfuz. I am currently working as an Associate Cloud Security Engineer at SELISE Group, where I focus on Azure security controls, cloud monitoring, incident response, and DevSecOps integration in CI/CD pipelines. Previously, I worked as a Cybersecurity Engineer at EIC Limited, contributing to VAPT and PCI DSS compliance projects for leading financial institutions. I also build Bash/Python automation tools, stay active in CTF competitions, and continue hands-on cybersecurity research and lab-based learning.

Read More

My Skills

Advanced security engineering, automation, and modern cloud defense

VAPT & Pentesting

0%

Web & Android App Security

0%

Cloud Security (Azure, IAM, WAF)

0%

API Security Testing

0%

PCI DSS Compliance Assessment

0%

Python & Bash Automation

0%

DevSecOps & CI/CD Security

0%

SIEM & Incident Response

0%

AI-Assisted Security Workflows

0%

CTF & Offensive Security

0%

My Qualification

Experience, Education & Activities

Work & Experience

Associate Cloud Security Engineer (Hybrid)

SELISE Group
Head Office: Zürich, Switzerland
Bangladesh Office: Dhanmondi 27, Dhaka
Nov 2025 - Present

Cybersecurity Engineer (Onsite)

EIC Limited
Gulshan-1, Dhaka
Apr 2024 - Oct 2025

Cybersecurity Internship (Remote)

Senselearner Technologies Pvt Ltd
India
Sep 2023 - Nov 2023

Education

Bachelor in Software Engineering (Major in Cybersecurity)

Daffodil International University, Bangladesh 2020 - 2024

Higher Secondary School Certificate (HSC)

University Laboratory College, Bangladesh 2016 - 2018

Secondary School Certificate (SSC)

Madartek Abdul Aziz High School, Bangladesh 2014 - 2016

Extra Curricular Activities

Cyber Raid CTF

Placed 10th in the top 30 finalist teams (Bangladesh Army) 2025

Flag Hunt: Battle of Hackers

Ranked 5th in the national CTF Competition. 2023

BUET CTF Competition Final

Ranked 8th in BUET CTF competition Final. 2023

Google Hacking Competition at DIU

2nd Runners Up in Cyber Security Awareness Day 2023

Google Hacking Competition at DIU

Ranked 10th in Cyber Security Awareness Day. 2022

Mujib 100 Idea Competition

Winner in Mujib 100 Idea National Competition and lead the team from front. 2021

Volunteer Activities

MIST LeetCon 2023 and DIU Cybersecurity Awareness Day 2022-2023

My Services

Application Security Testing

End-to-end security testing for web and Android applications, including vulnerability assessment, exploitation validation, and practical remediation guidance.

Read More

Software Development

I develop security-focused tools and scripts using Bash and Python to automate testing workflows, improve efficiency, and support practical cybersecurity operations.

Read More

Cloud Security

Cloud security hardening and monitoring for modern infrastructure, with focus on secure configurations, threat detection, and compliance-driven controls.

Read More

Latest Projects

Bus Fare Payment project screenshot by Mahfuz

Bus Fair Payment

You can pay public transport fare online by scanning a QR code.

Web design and portfolio project screenshot by Mahfuz

Web Design

This full website is designed and maintained by me.

DIU Delivery project screenshot by Mahfuz

DIU Delivery

Documentation of a food delivery app for my university.

API-Key-Checker cybersecurity project visual

API-Key-Checker

A free, open-source Python tool for quickly validating API keys during pentests to detect exposed or misconfigured credentials.

Card Data Discovery PCI DSS security project visual

Card Data Discovery

Automates the detection of unencrypted and unmasked cardholder data to support PCI DSS compliance with detailed Excel-based reporting and secure scanning capabilities.

RegEx-for-Wazuh security log analysis project visual

RegEx-for-Wazuh

For Wazuh log analysis by converting logs using Wazuh recommended regex.

TruffleHTML-Extractor secret scanning project visual

TruffleHTML-Extractor

Parses TruffleHog HTML reports, extracts findings, and outputs unique raw secrets with related repository context.

Auto-Install-tools scripting and automation project visual

Auto-Install-tools

Shell-based automation toolkit to speed up installation and setup of common security and development tools.

Punycode Generator security testing utility visual

Punycode Generator

Utility to encode and decode domain names with punycode for domain analysis and security testing workflows.

Github SIEM project dashboard and alert management visual

Github SIEM

Collects logs from GitHub and visualizes them in a SIEM dashboard for monitoring and alert management.

My Certifications

Professional certifications and training
Certified Vulnerability Assessor certificate

Certified Vulnerability Assessor (CVA)

Mile2

January 2024
Certified Network Security Practitioner certificate

Certified Network Security Practitioner (CNSP)

SecOps

January 2025
Certified AppSec Practitioner certificate

Certified AppSec Practitioner (CAP)

SecOps

January 2025
AWS Cloud Practitioner Essentials certificate

AWS Cloud Practitioner Essentials

AWS

October 2025
Certified API Security Analyst certificate

Certified API Security Analyst (CASA)

APIsec University

APIsec Certified Practitioner certificate

APIsec Certified Practitioner (ACP)

APIsec University

Research Publications

IEEE conference publications

Published Work

A Secure Video Steganography Framework Using RSA Cryptography and Randomized XOR-LSB Embedding

IEEE 4th International Conference (RAAICON) 2025 View Publication

Anomaly Detection for Ransomware Prevention Using Machine Learning and Local Interpretable Model-agnostic Explanations (LIME)

IEEE 4th International Conference (RAAICON) 2025 View Publication

Contact Me!

Get in touch

Talk to me

Email mahfuz33r@gmail.com
Telegram @mahfuz33r Write Me
Messenger @mahfuz33r Write Me

Write Me Your Thoughts