Summary
Overview
Work History
Education
Skills
Certification
Security Expertise
Training & Practical Experience
Bug Bounty Achievements
Hobbies and interests
CTF and Community Contributions
Languages
Work Availability
Portfolios and Profiles
Reference
Timeline
AdministrativeAssistant
MD ASIF HOSSAIN

MD ASIF HOSSAIN

Uttara

Summary

Accomplished Security Researcher with extensive experience at Yogosha and HackerOne, specialising in Threat & Vulnerability Management, Penetration Testing, and Cybersecurity. Demonstrated expertise in Digital Forensics, Ethical Hacking, and Security Incident Response. Proven track record as a Cyber Security Engineer at Jobmofy in Germany, excelling in Vulnerability Assessment and Penetration Testing (VAPT). Adept at problem-solving with strong communication skills. Committed to advancing cybersecurity measures and enhancing digital safety.

Overview

5
5
years of professional experience
1
1
Certification

Work History

HackerOne

Ambassador & Security Researcher
05.2020 - Current

Yogosha

Security Researcher
05.2022 - Current

BugCrowd

Security Researcher
01.2020 - Current

Jobmofy

Cyber Security Engineer
01.2021 - 12.2021

Education

BSc - Computer Science & Engineering

Uttara University
01.2024

Diploma - Civil Engineering

CTT Polytechnic Institute
01.2020

Skills

  • Vulnerability assessment
  • Security vulnerability assessment
  • Information security management
  • CTF problem-solving skills
  • Intelligence sourcing
  • Digital evidence analysis
  • Cybersecurity assessment
  • Incident response management
  • Vulnerability assessment expertise
  • Strategic issue analysis
  • Effective communication
  • Remote team management

Certification

  • Certified AppSec Practitioner (CAP), The SecOps Group, 7030396
  • Web application Penetration Tester eXtreme, INE, 100003164
  • Android Forensics with Belkasoft, Belkasoft

Security Expertise

  • Strong knowledge and hands-on experience with SSRF, IDOR, SQL Injection, XSS, and Privilege Escalation.
  • Proficient in identifying and exploiting vulnerabilities in web applications and systems.
  • Skilled in penetration testing, vulnerability assessment.

Training & Practical Experience

  • Penetration Testing & Vulnerability Assessment.
    Hands-on experience with Metasploit, Burp Suite, and Nessus for identifying and exploiting security flaws.
  • Active Directory Penetration Testing.
    Performed attacks such as Kerberoasting, Pass-the-Hash, and Golden Ticket using tools like BloodHound, CrackMapExec, and Impacket.
  • Reconnaissance & OSINT.
    Utilized tools like Subfinder, Amass, Burp Suite, and various OSINT techniques to uncover sensitive and confidential information.
  • Target Testing.
    Experience in security testing of Web Applications, Mobile Applications, Boot2Root machines, and OSINT-based targets.
  • TryHackMe – Junior Penetration Tester Path.
  • PortSwigger Web Security Academy – Lab Completion.
  • Red Team & Blue Team Training (Self-Directed).

Bug Bounty Achievements

  • Reported over 1,000 valid vulnerabilities across various platforms, demonstrating deep expertise in vulnerability discovery, impact analysis, and responsible disclosure.

Severity Breakdown:

  • 🔴 Critical: 80 bugs (8%)
  • 🟠 High: 174 bugs (17.4%)
  • 🟡 Medium: 454 bugs (45.4%)
  • 🔵 Low: 113 bugs (11.3%)

Recognized in Hall of Fame/Acknowledgments by:

  • Google – Hall of Fame
  • Microsoft – Hall of Fame
  • ESET – Official Acknowledgment
  • Nokia, Dev.to, Ellucian, Eur.nl, KNB.nl – Hall of Fame
  • And many other private and public programs
  • 4th Place – SUST CTF, showcasing skills in real-world exploitation and problem-solving under pressure.
  • Contributed to strengthening the security of numerous global platforms through detailed technical reports, PoCs, and ongoing collaboration with security teams.

Hobbies and interests

  • Passionate about cybersecurity and continuous learning.
  • Regularly reads books on cybersecurity topics.
  • Writes engaging content on various platforms.
  • Actively participates in solving CTF challenges to develop technical and analytical skills.

CTF and Community Contributions

  • Competed in various national-level CTF competitions, demonstrating strong problem-solving and technical skills.
  • Regularly post cybersecurity-related write-ups on Medium.com
  • Delivered two talks on cybersecurity topics at the university’s Cybersecurity Club, educating peers on practical and theoretical aspects of the field.
  • Contributed to open-source cybersecurity tools and projects, supporting the community by enhancing security tools and sharing insights.

Languages

Bengali
Proficient
C2
English
Proficient
C2

Work Availability

monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse

Portfolios and Profiles

https://linkedin.com/in/0x0asif

https://hackerone.com/0x0_asif

https://bugcrowd.com/0x0asif

https://app.yogosha.com/r/0x0asif

https://medium.com/@0x0asif

Reference

Dr. A. H. M. Saifullah Sadi                                                                                                   
Professor, Department of Software Engineering
Faculty of Science and Information Technology
Daffodil International University
Email: sadi.swe@diu.edu.bd
Phone: 01795379956 



Md. Wahidur Rahman 

Assistant Professor, Department of CSE Uttara University

Email: mwrahman@uttarauniversity.edu.bd

Phone: +880 17 7920 8267

Timeline

Yogosha

Security Researcher
05.2022 - Current

Jobmofy

Cyber Security Engineer
01.2021 - 12.2021

HackerOne

Ambassador & Security Researcher
05.2020 - Current

BugCrowd

Security Researcher
01.2020 - Current

Diploma - Civil Engineering

CTT Polytechnic Institute

BSc - Computer Science & Engineering

Uttara University
MD ASIF HOSSAIN