Security Engineer / Product Security / Offensive SecurityPortfolio / 2026
PRODUCT SECURITYAPPSECOFFSECNODE_SJC / 37.3382

MuhammadUmar AhamedSaleem

Profile / 01

Security engineer and vulnerability researcher who turns attack paths into fixes before they become incidents—combining offensive depth, enterprise remediation, reproducible proof-of-concept development, and automation that compresses hours of manual security work into minutes.Fremont, California / SJSU

1600+ Cloud domains mapped
7500+ Hosting signatures analyzed
20+ Critical flaws identified
#1 Enterprise leaderboard

Umar is a CompTIA-certified cybersecurity professional and former Cybersecurity Intern at Stanford Health Care. He operates with a Purple Team mindset, applying the attacker perspective developed through a #108 finish among 2,000+ Hackfinity CTF teams to build resilient enterprise defenses.

His work centers on protecting clinical operations and patient data against evolving threats. He combines proactive incident response, telemetry-driven threat hunting, and offensive security techniques to improve enterprise defense.

During his three-month Stanford Health Care internship, Umar built multithreaded security automation for enterprise cloud domains, audited backend applications for critical authentication flaws, and reviewed clinical workflows and APIs with Burp Suite.

His expertise spans incident response, malware analysis, root-cause breach investigation, packet analysis, malicious-code deobfuscation, and SIEM telemetry. He also earned the Intermediate SOC Analyst credential and ranked #1 on the enterprise leaderboard after 68+ hours of Immersive Labs training.

03 / Work experience

Security shipped.
Risk reduced.

I don’t just find vulnerabilities—I shorten the distance between exposure and remediation. The result: less manual work, faster validation, and fewer expensive surprises in production. Open any role to inspect the evidence.

May 2026 — Jul 2026
Palo Alto / Hybrid
Stanford Health Care
Cybersecurity Intern
Owned application-security and cloud attack-surface work across a core clinical Django platform, 1,600+ enterprise domains, and sensitive patient-data workflows.
Product SecurityAppSecPython AutomationSAML 2.0

Critical SAML authentication bypass

Collaborated with AppSec Lead David Downs to audit backend Django code. Identified a custom certificate check that omitted cryptographic signature verification, enabling forged SAML assertions. Co-authored the vulnerability report, built proof-of-concept exploits, and validated the production patch with python-saml’s process_response() engine in staging.

Enterprise subdomain and DNS automation

Architected a 50-thread Python scanner covering 1,600+ Route 53 domains in under three minutes. Built a five-stage pipeline spanning DNS resolution, IP classification, TLS handshake, HTTP status, and three-layer fingerprinting against 7,500+ AWS S3, Heroku, Azure, and GitHub Pages signatures.

Risk scoring and reporting

Eliminated false positives, scored severity from 0–100, and produced HTML, CSV, Excel, and JSON reporting for repeatable monthly delta scans.

Clinical AppSec

Used Burp Suite to audit clinical workflows, map REST APIs, and evaluate access-control models protecting sensitive patient data.

Technical stack

Python, Burp Suite Professional, SAML 2.0 / SSO, Django, AWS Route 53, asynchronous programming, multithreading, REST APIs, OX Security, and threat modeling.

Aug 2025
Fremont / On-site
Seagate Technology
Cybersecurity Analyst Intern
Protected enterprise subsidiaries and external assets with EDR telemetry, exposure review, vulnerability assessment, code analysis, and threat intelligence.
Security EngineeringCrowdStrike FalconEDRThreat Intelligence

External asset defense

Monitored and protected subsidiaries’ external infrastructure through CrowdStrike Falcon while reviewing exposed domains, services, and IP addresses.

Vulnerability operations

Conducted systematic vulnerability checks, supported remediation tracking, and applied real-world threat intelligence to active investigations.

Code and configuration review

Assisted with code analysis and system-configuration review to identify architectural weaknesses and convert findings into actionable remediation paths.

Security team impact

Earned expanded responsibilities by demonstrating strong technical depth, curiosity, and a clear fit for future product and enterprise security roles.

May 2025 — Aug 2025
Fremont / On-site
Seagate Technology
Information Technology Intern
Built the systems foundation behind secure operations through identity, endpoint, network, asset-lifecycle, and user-support work.
IAMAsset ManagementLinux / MacMicrosoft 365

Identity and access

Supported account provisioning, password resets, access permissions, onboarding, offboarding, device preparation, and secure decommissioning.

Endpoint and network support

Troubleshot hardware, software, and network issues across Mac, Linux, and enterprise productivity environments.

Asset lifecycle

Tracked inventory, coordinated hardware replacements, maintained lifecycle documentation, and contributed to system-maintenance projects.

Operational discipline

Documented support tickets, collaborated with senior IT staff, and improved day-to-day service delivery while developing cybersecurity fundamentals.

04 / Achievements

Proof under
pressure.

Competitive performance and applied cyber-range training separated from employment history, with direct evidence where available.

Hackfinity Global CTFView certificate ↗
#108

2,000+ global teams / 1,305 points

Cleared 41 tasks, bypassed custom AI guardrails through prompt injection, exploited IDOR flaws, enumerated AWS services, and analyzed persistent command-and-control traffic.

Immersive Labs68+ hours
#1

Enterprise leaderboard / 20,750 points

Earned the Intermediate SOC Analyst credential, reached Expert Tier in Security Operations with a score of 238, and completed hands-on investigation, threat hunting, and incident-response scenarios.

05 / Education

Systems understood.
Security engineered.

A dedicated academic track in network systems management, enterprise infrastructure, administration, security, and ethical hacking.

06 / Capability matrix

Attack surface.
Covered.

Hands-on capability built to create leverage: break what matters, automate what repeats, and turn security findings into fixes teams can actually ship.

Column / 02

AppSec & OffSec

  • Product Security
  • Application Security
  • Burp Suite Pro
  • OWASP Top 10
  • PoC Development
  • Code Review
  • Red Teaming
  • Threat Modeling
  • SAML / SSO
  • REST APIs
  • Nmap
  • Metasploit
  • Kali Linux
  • OX Security
Column / 03

Detection & Analysis

  • Incident Response
  • Malware Analysis
  • Reverse Engineering
  • Threat Hunting
  • Computer Forensics
  • Splunk SIEM
  • Wazuh EDR
  • CrowdStrike Falcon
  • Tenable Nessus
  • Ghidra
  • x32dbg
  • PE Studio
  • dnSpy
  • Wireshark
Column / 04

Security Engineering

  • Python
  • Bash
  • JavaScript
  • Django
  • Docker
  • AWS Route 53
  • Async / Threading
  • Linux Administration
  • Active Directory
  • IAM / PKI
  • TCP/IP / DNS
  • MITRE ATT&CK
Selected repositories / live research
Vulnerability research / PoC

picoGym Writeups

Root-cause vulnerability analysis, custom proof-of-concept exploit scripts, and secure remediation notes for completed picoCTF challenges.

Detection engineering / SOC

SOC Analyst Lab Journal

Hands-on playbooks for SIEM monitoring, threat hunting, log telemetry analysis, incident triage, and repeatable defensive investigations.

Authorized vulnerability researchVDP // 2026

Coordinated Disclosure Research

Conducting authorized application-security research through coordinated vulnerability disclosure programs, with hands-on testing across web applications, APIs, business logic, validation boundaries, and exploitability analysis.

Disclosure / Technical details withheld under program confidentiality policyBurp Suite · API analysis · business logic · control testing · impact validation
Field note / Mentor recommendation
“Umar was proactive, eager to learn, and consistently demonstrated the ability to quickly pick up new concepts and apply them effectively. He took ownership of his work, communicated well, and played a meaningful role in identifying and remediating a critical application security issue, improving Stanford Health Care’s security posture.”David Downs — Security Engineer & Stanford Health Care mentor ↗
07 / ContactFremont, California

Find the flaw.Own the fix.