Senior information security professional specializing in the defense of financial infrastructure. Expertise spans offensive security (penetration testing), threat intelligence, and ISO/IEC ISMS 27001, governance, underpinned by regulatory compliance frameworks including PCI DSS and SWIFT CSP.
Network and System Security Risk Analyst, Senior Executive Officer, Information Security & Governance Division — Private Commercial Bank, Dhaka.
In banking, a vulnerability left undiscovered is not a statistic. It is a breach of the trust a customer placed in the institution.
I lead vulnerability assessment, penetration testing, and security governance for a commercial bank, owning the assessment lifecycle end to end — scoping, exploitation, remediation tracking, and audit-ready reporting — across mobile, API, infrastructure, and cloud estates.
Over sixteen years in IT and security, my practice has evolved from network engineering into offensive security and ISMS governance. Every finding is mapped to the control frameworks that supervisors and auditors genuinely test: Bangladesh Bank ICT Security Guideline, ISO/IEC 27001, PCI DSS, SWIFT CSP, and OWASP.
I hold EC-Council's offensive track in its entirety — CEH, ECSA, and LPT Master — alongside threat intelligence and ISO/IEC 27001 Lead Auditor credentials. Representing my institution at the Bangladesh Cyber Drill, I contributed to a first-place national ranking among financial institutions.
Every credential below is independently verifiable through its issuing body and credential ID.
Every certificate below is genuine and verifiable. Filter by category, or open any card to view the full certificate.
Lead VAPT, penetration testing, and threat analysis across the bank's digital platforms. Implement ICT security policies and governance, conduct periodic risk and gap assessments of ICT assets, and deploy SOC, SIEM, 2FA (RSA) and PAM controls to reduce cyber-attack exposure. Drive ISO 27001 and PCI DSS programs as project manager, run institution-wide security awareness, and act as the primary point of contact for investigating and resolving security incidents.
Built and secured intranet/internet networks for a UN peace-support training institute. Managed Active Directory, Linux web/e-learning servers, MikroTik core routing with load balancing, and the CPTM online examination platform for the Bangladesh Army, Navy, and Air Force.
Joined as Assistant Officer, IT and promoted to System Engineer in Jan 2013. Maintained domain controllers, mail and SMS servers, and inter-site data links between the head office and Savar & Dhamrai plants. Managed Kaspersky AV, proxy, VPN, and MikroTik bandwidth control, with full server backup and uptime monitoring.
Joined as Assistant Engineer and promoted to Support Engineer in the Network Monitoring Center under Service Delivery. Handled BTS monitoring, switch and router troubleshooting, radio-link diagnostics, and client-facing resolution to keep corporate networks running smoothly and securely.
Rank 10 nationally across Bangladesh and 1st among all financial institutions in the national cybersecurity contest.
Led team MBL_XForce to first place among financial institutions, organized by BGD e-GOV CIRT (N-CERT).
First place among financial institutions for the second consecutive year with team MBL_XForce.
Recognized by the Managing Director & CEO of Mercantile Bank for outstanding results in Financial and National Cyber Drill programs.
Silver Medal for academic distinction in the M.Sc. in Computer Science program.
Assessed suitable for skilled migration under ANZSCO 263111 (Computer Network & Systems Engineer) by the Australian Computer Society.
The Australian Computer Society assessed both degrees and the full employment record against Australian standards, confirming suitability for skilled migration.
Every intrusion moves through seven stages. Understanding the attacker’s path is how I break it — detecting, disrupting, and defending at each link before it reaches its objective.
Attacker harvests targets — employees, emails, exposed services, and public infrastructure.
Malicious payload is coupled with an exploit into a deliverable, such as a rigged document.
Weapon is transmitted to the target via email, web, USB, or a compromised supply chain.
Code executes on the victim, exploiting a vulnerability or human trust to gain a foothold.
Malware or a persistence mechanism is installed to maintain long-term access.
Compromised host beacons out to attacker infrastructure to receive instructions.
Attacker achieves the goal — data theft, fraud, encryption, or lateral movement.
A near real-time view of global cyberattacks — DDoS and application-layer events broken down by region, vector, and protocol — streamed from Radware's global deception network.
Available for penetration testing, security assessment, and information security advisory engagements — locally in Dhaka and internationally.