Usama Arshad. Résumé
gusama21@gmail.com Résumé ↓

Riyadh · Saudi Arabia Offensive Security Lead Currently @ Tabby

Usama Arshad.

Red Team · Fintech & Cloud

OSCP-certified, nine-plus years deep in red team, AppSec, and cloud security — web, mobile, API, GCP, AWS, Kubernetes. Currently leading the offensive security function at Tabby, MENA's largest BNPL fintech, protecting 14M+ users. Published CVE-2024-3681.

Years in offensive security
09+
Engagements — F500 & SAMA
80+
Users protected at Tabby
14M+
Published CVE · 2024-3681
01
National CTF titles — Pakistan
03×
Halls of fame — disclosure
04

Profile

The brief.

Offensive security is a reporting discipline as much as a technical one — the exploit only matters if the business understands it. For nine-plus years I've built and run red team, AppSec, and cloud security programs across web, mobile, API, GCP, AWS, and Kubernetes, turning complex exploitation chains into decisions executives can act on.

Today I lead the offensive security function at Tabby, MENA's largest BNPL fintech. There I've architected autonomous VAPT pipelines, embedded AppSec gates into GitLab CI/CD, and hardened GKE workloads at the scale of 14M+ users. Before that: 80+ engagements delivered for Fortune 500 companies and SAMA-regulated financial institutions.

The research habit never switched off. I published CVE-2024-3681, took Pakistan's national CTF podium three years running, reached the BlackHat MEA CTF finals twice — and hold hall-of-fame credits from the United Nations, Walmart, Achmea, and The Sun for responsible disclosure.

Career

Track record.

01 Jun 2025 — Present Riyadh, Saudi Arabia Current

Offensive Security Lead

Tabby · MENA's largest BNPL fintech

  • Lead the offensive security function for 14M+ users: red team, AppSec, and cloud security across web, mobile, API, GCP, and GKE.
  • Architected autonomous VAPT dashboards with Jira and tracker automation — cut assessment cycle time by 60% and eliminated manual reporting.
  • Run continuous red team and adversary simulations, surfacing real-world attack chains before release.
  • Embedded SAST, DAST, secret scanning, and container scanning into GitLab CI/CD, gating insecure releases at merge time.
  • Hardened GKE workloads via Workload Identity, network policies, admission controllers, and runtime detection.
02 Aug 2024 — May 2025 Riyadh, Saudi Arabia

ISM Consultant & Team Lead

SecurEyes

  • Led large-scale SAMA fintech security assessments for major Saudi financial institutions: end-to-end VAPT, source code review, red team.
  • Full-scope red team operations: external/internal infrastructure, web, mobile, API, Active Directory, WiFi, physical, cloud, DLP/EDR evasion.
  • Mentored consultants, reviewed deliverables, and presented findings to executives and regulators.
03 Dec 2021 — Jul 2024 Lahore, Pakistan

Senior Security Engineer

Ebryx

  • Delivered 80+ offensive engagements for Fortune 500 clients: pentesting, source code review, red teaming.
  • Led a sub-team of consultants; owned scoping, execution, peer review, and report quality.
  • Translated complex exploitation chains into business-impact narratives for executives.
04 Mar 2021 — Present Remote Part-time

Red Team Member

Synack Red Team

  • Continuous vulnerability discovery and exploitation on private enterprise targets.
  • High-impact findings: IDOR, BOLA, authentication bypass, business-logic flaws.
05 Mar 2018 — May 2021 Lahore, Pakistan

Penetration Tester

Security Wall

  • Validated vulnerabilities across 50+ engagements spanning web, mobile, and network.
  • Built reusable internal tooling and methodologies that raised team throughput.

Capabilities

Capability index.

.01

Red Team & Adversary Simulation

  • MITRE ATT&CK
  • Purple Team
  • Physical Intrusion
  • OSINT
  • Cobalt Strike
  • Sliver
  • Mythic
  • Initial Access
  • Lateral Movement
  • Persistence
  • Defense Evasion
.02

Offensive Testing

  • Web — OWASP Top 10
  • Mobile — OWASP MASVS
  • iOS / Android
  • REST
  • GraphQL
  • gRPC
  • Network & Infrastructure
  • Active Directory
  • WiFi
  • Thick Client
  • Source Code Review
.03

Cloud & Container Security

  • GCP
  • AWS
  • GKE / Kubernetes
  • Container Escape
  • IAM Privilege Escalation
  • Metadata Abuse
  • Workload Identity
  • Terraform IaC Scanning
  • CIS Benchmarks
.04

AppSec & DevSecOps

  • GitLab CI/CD Security Gates
  • SAST
  • DAST
  • SCA
  • Secret Scanning
  • Threat Modeling — STRIDE
  • Secure SDLC
  • Code Review — Python / Go / Node / Java
.05

Tooling & Automation

  • Burp Suite Pro
  • Frida
  • Ghidra
  • IDA
  • Nmap
  • Nuclei
  • Nessus
  • Metasploit
  • BloodHound
  • Sliver
  • FFUF
  • Sqlmap
  • Wireshark
  • Custom Python & Go tooling
.06

Compliance & Frameworks

  • SAMA CSF
  • PCI DSS
  • ISO 27001
  • OWASP ASVS
  • NIST CSF

Recognition

On the record.

CVE-2024-3681

Reflected XSS in the WordPress Interactive World Maps plugin (≤ 2.4.14) — original discovery and responsible disclosure. Catalogued by MITRE, NVD, and Wordfence.

Apr 20240-DayCVSS 6.1

BlackHat MEA CTF Finalist

Top 32 (2023) and Top 29 (2024) of 250+ teams globally, representing Pakistan.

2023 · 2024CTF

National CTF Hat-Trick

Podium finishes at Pakistan's national cyber hackathon three consecutive years — awarded by the President, the Prime Minister, and the IT Minister.

2021 — 2023CTF

Four Halls of Fame

Responsible-disclosure recognition from the United Nations, Walmart, Achmea, and The Sun.

×4HoF

Speaker

Recurring talks at universities and security conferences on offensive security and AI-driven attack automation.

OngoingTalks

Projects

Selected work.

Feature 01 — Open Source

SecurityWire

A security platform combining a mobile vulnerability scanner with a web bug-bounty marketplace: companies onboard targets, researchers submit findings, and validated reports trigger payouts.

View on GitHub

Feature 02 — Internal

AI-Driven Offensive Automation

Internal tooling and dashboards automating end-to-end VAPT: Jira integration, triage orchestration, and autonomous assessment pipelines for offensive security teams.

Internal tooling · not public

Certifications & Education

Credentials.

OSCP

Offensive Security Certified Professional Offensive Security

HTB Offshore

Pro Lab — Active Directory & banking infrastructure Hack The Box

PEH

Practical Ethical Hacker TCM Security

CNSS

Certified Network Security Specialist ICSI

Education

BSc Computer Science

COMSATS University, Lahore · 2018 — 2021

Correspondence

Make contact.

If it can be broken, better that I find it first.

gusama21@gmail.com