SECURE BOOT // Cyber Security
ACCESS GRANTED
CLICK OR PRESS ANY KEY TO SKIP
Information Security Specialist Private Commercial Bank

Md. Zahid Hossain

Senior information security professional specializing in the defense of financial infrastructure. Expertise spans offensive security (penetration testing), threat intelligence, and ISO/IEC ISMS 27001, governance, underpinned by regulatory compliance frameworks including PCI DSS and SWIFT CSP.

Network and System Security Risk Analyst, Senior Executive Officer, Information Security & Governance Division — Private Commercial Bank, Dhaka.

16.7+
Years in IT & Security
7+
Years in Banking
14
Professional Certs
#1
Fin. Inst. — Nat. Cyber Drill
Portrait of Md. Zahid Hossain
SECURITY LEAD  ·  THREAT WATCH  ·  SECURITY LEAD  ·  THREAT WATCH  ·   Dhaka · BD
01 Profile

Securing the systems that move money.

In banking, a vulnerability left undiscovered is not a statistic. It is a breach of the trust a customer placed in the institution.

I lead vulnerability assessment, penetration testing, and security governance for a commercial bank, owning the assessment lifecycle end to end — scoping, exploitation, remediation tracking, and audit-ready reporting — across mobile, API, infrastructure, and cloud estates.

Over sixteen years in IT and security, my practice has evolved from network engineering into offensive security and ISMS governance. Every finding is mapped to the control frameworks that supervisors and auditors genuinely test: Bangladesh Bank ICT Security Guideline, ISO/IEC 27001, PCI DSS, SWIFT CSP, and OWASP.

I hold EC-Council's offensive track in its entirety — CEH, ECSA, and LPT Master — alongside threat intelligence and ISO/IEC 27001 Lead Auditor credentials. Representing my institution at the Bangladesh Cyber Drill, I contributed to a first-place national ranking among financial institutions.

Discipline
Offensive Security & ISMS Governance
Sector
Banking & Financial Services
Experience
16.7+ years across IT & security
Assurance Frameworks
BB ICT Guideline · ISO 27001 · PCI DSS · SWIFT CSP · OWASP

Core Focus Areas

VAPT Penetration Testing Threat Intelligence Mobile App Security API Security Cloud Security Malware Analysis ISO 27001 PCI DSS SWIFT CSP PAM Risk Management Security Awareness OWASP
02 Credential Registry

Verified certifications.

Every credential below is independently verifiable through its issuing body and credential ID.

ENTRIES: 14
ISSUERS: Red Team Leaders · ISC2 · EC-Council · Mile2 · BV · Microsoft · Cisco · Qualys · OPSWAT
Idx
Credential
Issuer
ID / Reference
001
CAISRCertified AI Security & Risk
Red Team Leaders
002
CTIGACertified Threat Intelligence & Governance Analyst
Red Team Leaders
003
CCEPCertified Cybersecurity Educator Professional
Red Team Leaders
004
LPT MasterLicensed Penetration Tester (Master)
EC-Council
ECC0694523871 · 2021
005
ECSA v10EC-Council Certified Security Analyst
EC-Council
ECC8142039675 · 2021
006
CEHCertified Ethical Hacker · score 91.2
EC-Council
ECC8519360742 · 2020
007
C)TIACertified Threat Intelligence Analyst
Mile2
17554-168-997-3713 · 2023
008
CCCertified in Cybersecurity
ISC2
1237127 · 2023
009
ISO/IEC 27001 Lead AuditorISMS · CQI & IRCA certified course
Bureau Veritas
22/IN/1023466/2670 · 2022
010
Adv. Malware Analysis & Ransomware40-hour certified expert course
CyberFoxTrain
CFT/CN000221903018 · 2022
011
Qualys Certified SpecialistVulnerability Mgmt · Scanning Strategies
Qualys
VM · SS · 2020
012
OCFA & ICIPCybersecurity Fundamentals · Critical Infrastructure
OPSWAT
o5QjNoeidw · 2024
013
MCSE / MCSA / MCPServer Infrastructure · Windows Server 2012
Microsoft
E251-0753 · 2013
014
CCNACisco Certified Network Associate
Cisco
CSCO11527615 · 2008
03 Certifications

The credentials, in full.

Every certificate below is genuine and verifiable. Filter by category, or open any card to view the full certificate.

Latest credential
Certified Artificial Intelligence Security & Risk (CAISR) badge
Red Team Leaders·Issued 17 Jul 2026·Verify ↗
04 Experience

A path from networks to offensive security.

JUL 2019 — PRESENT
Network and System Security Risk Analyst
Senior Executive Officer
Mercantile Bank PLC Information Security & Governance Division

Lead VAPT, penetration testing, and threat analysis across the bank's digital platforms. Implement ICT security policies and governance, conduct periodic risk and gap assessments of ICT assets, and deploy SOC, SIEM, 2FA (RSA) and PAM controls to reduce cyber-attack exposure. Drive ISO 27001 and PCI DSS programs as project manager, run institution-wide security awareness, and act as the primary point of contact for investigating and resolving security incidents.

SEP 2013 — MAR 2017
Network Administrator
BIPSOT Bangladesh Army & UN Peace Operations

Built and secured intranet/internet networks for a UN peace-support training institute. Managed Active Directory, Linux web/e-learning servers, MikroTik core routing with load balancing, and the CPTM online examination platform for the Bangladesh Army, Navy, and Air Force.

NOV 2010 — JUN 2013
System Engineer
Incepta Pharmaceuticals Ltd. IT — Head Office

Joined as Assistant Officer, IT and promoted to System Engineer in Jan 2013. Maintained domain controllers, mail and SMS servers, and inter-site data links between the head office and Savar & Dhamrai plants. Managed Kaspersky AV, proxy, VPN, and MikroTik bandwidth control, with full server backup and uptime monitoring.

DEC 2006 — MAR 2010
Support Engineer — NMC
Link3 Technologies Ltd. Network Monitoring Center

Joined as Assistant Engineer and promoted to Support Engineer in the Network Monitoring Center under Service Delivery. Handled BTS monitoring, switch and router troubleshooting, radio-link diagnostics, and client-facing resolution to keep corporate networks running smoothly and securely.

05 Recognition

Awards & competition results.

2023

ICT Minister Award — MIST LeetCon

Rank 10 nationally across Bangladesh and 1st among all financial institutions in the national cybersecurity contest.

2022

National Cyber Drill — 1st (Fin. Institutions)

Led team MBL_XForce to first place among financial institutions, organized by BGD e-GOV CIRT (N-CERT).

2021

National Cyber Drill — 1st (Fin. Institutions)

First place among financial institutions for the second consecutive year with team MBL_XForce.

2022

Best Performer — Cyber Drill Programs

Recognized by the Managing Director & CEO of Mercantile Bank for outstanding results in Financial and National Cyber Drill programs.

2021

Presidium Award — Magna Cum Laude

Silver Medal for academic distinction in the M.Sc. in Computer Science program.

2023

ACS Skills Assessment — Australia

Assessed suitable for skilled migration under ANZSCO 263111 (Computer Network & Systems Engineer) by the Australian Computer Society.

06 Education

Academic background, independently assessed.

M.Sc. in Computer Science
American International University — Bangladesh
CGPA 3.88 / 4.002021
Praesidium Award · Magna Cum Laude · Silver Medal
B.Sc. in Computer Science
American International University — Bangladesh
CGPA 3.07 / 4.002006
Foundation in computer science & networking
ACS ICT Skills Assessment
Ref. A-397749  ·  23 June 2023

The Australian Computer Society assessed both degrees and the full employment record against Australian standards, confirming suitability for skilled migration.

ANZSCO 263111 — Computer Network & Systems Engineer
M.Sc. Assessed as comparable to an AQF Bachelor Degree with a major in computing
B.Sc. Assessed as comparable to an AQF Associate Degree with a major in computing
Employment Link3 · Incepta · BIPSOT · Mercantile Bank — all assessed at an appropriately skilled level
Issued by the Australian Computer Society Inc. (ACT), National Secretariat, Sydney.
Assessment Letter
07 Methodology

The Cyber Kill Chain.

Every intrusion moves through seven stages. Understanding the attacker’s path is how I break it — detecting, disrupting, and defending at each link before it reaches its objective.

01
Reconnaissance

Attacker harvests targets — employees, emails, exposed services, and public infrastructure.

DEFENDOSINT monitoring, attack-surface management, credential-leak alerting.
02
Weaponization

Malicious payload is coupled with an exploit into a deliverable, such as a rigged document.

DEFENDThreat intel, sandbox detonation, IOC feeds, signature research.
03
Delivery

Weapon is transmitted to the target via email, web, USB, or a compromised supply chain.

DEFENDEmail security, web filtering, DMARC/SPF, user awareness training.
04
Exploitation

Code executes on the victim, exploiting a vulnerability or human trust to gain a foothold.

DEFENDPatch management, hardening, EDR behavioural blocking, least privilege.
05
Installation

Malware or a persistence mechanism is installed to maintain long-term access.

DEFENDEDR, application allow-listing, integrity monitoring, privileged access mgmt.
06
Command & Control

Compromised host beacons out to attacker infrastructure to receive instructions.

DEFENDDNS/egress filtering, network segmentation, C2 traffic analytics.
07
Actions on Objectives

Attacker achieves the goal — data theft, fraud, encryption, or lateral movement.

DEFENDDLP, SIEM correlation, honeypots, incident response, immutable backups.
Stage 00 / 07
The chain arms itself automatically. Hover any stage to inspect it — each lists the defensive control that breaks the chain at that link.
08 Live Intelligence

The threat landscape, in real time.

A near real-time view of global cyberattacks — DDoS and application-layer events broken down by region, vector, and protocol — streamed from Radware's global deception network.

Open to international & remote security roles

Let's secure something.

Available for penetration testing, security assessment, and information security advisory engagements — locally in Dhaka and internationally.