Chowdhury Faizal
AhammedSenior Cloud IAM Engineer at Synchrony Financial. Building secure systems by knowing exactly how they break.
About Me
Breaking things to make them stronger
I'm a 24-year-old security enthusiast who's been breaking things since my teens. With 7+ years in offensive security, I've evolved from curious script kiddie to a seasoned penetration tester and cloud security architect.
Currently serving as a Senior Cloud IAM Engineer at Synchrony Financial, I architect enterprise-scale identity and access management solutions while maintaining my offensive edge through red teaming and bug bounty hunting.
I hold multiple CVEs across SSRF, RCE, IDOR, and XSS vulnerability classes, and I've competed in CTFs at both national and international levels. My unique blend of offensive security and cloud engineering gives me an attacker's perspective on defense — I build secure systems because I know exactly how they break.
CVE Discoveries
Vulnerabilities responsibly disclosed across SSRF, RCE, IDOR, and XSS classes
Server-side request forgery allowing internal network access and cloud metadata exfiltration.
Remote code execution via unsafe deserialization of user-controlled input.
Insecure direct object reference enabling unauthorized access to user resources.
Remote code execution through command injection in file processing pipeline.
Server-side request forgery via URL parameter manipulation in API endpoint.
Stored cross-site scripting through unsanitized user input in application interface.
Certifications
Validated offensive security expertise
OffSec Certified Professional+
OffSec
Certified Red Team Analyst
CyberWarFare Labs
Certified AD Red Team Specialist
CyberWarFare Labs
Certified Network Pentester
The SecOps Group
Certified AppSec Practitioner
The SecOps Group
CTF Achievements
National and international competition wins
Arsenal
Languages, tools, and techniques in the toolkit
Open Source
Security tools built and released for the community
ADCSDumper
Active Directory Certificate Services enumeration and exploitation tool for red team operations.
catrole
AWS IAM role enumeration and privilege escalation discovery tool for cloud security assessments.
tfswitch
Terraform version manager for seamless switching between Terraform versions in your workflow.