x: 0 y: 0
CLIENT: Unknown
VIEWPORT: 0x0 SCREEN: 0x0
DEPTH: 0BIT
Identity Verified

SHAZ SYED ALI

SECURITY ENGINEER

Cloud Security | Application Security | DevSecOps

System Status

Operational
Location Pakistan, Karachi
Encryption AES-256

Log: Experience

Bazaar Technologies

Security Engineer

FEB 2025 - PRESENT
Bazaar Technologies

Security Engineer driving cloud, container, and application security — automating CI/CD security pipelines, hardening Kubernetes, deploying AWS-wide SIEM monitoring, and cutting remediation times through custom tooling and developer enablement.

NayaPay

Associate DevSecOps Engineer

APR 2024 - SEP 2024
NayaPay

Handled cloud, Linux, and container infrastructure end-to-end — from CIS-compliant server hardening to AWS operations, encrypted storage, and full-stack monitoring for improved reliability and performance.

Modules

SECURITY
Penetration Testing Burp Suite AWS Security Kubernetes Security SIEM
DEVSECOPS
Semgrep Trivy TruffleHog Dependabot CI/CD Security
CLOUD & INFRA
AWS Terraform Docker Prometheus Grafana
LANGUAGES
Golang Python Bash Node.js Java

Credentials

Google Cybersecurity Specialization
Google Cybersecurity Specialization
Google

System // Expertise

Application Security
Cloud Security
DevSecOps
Bug Bounty
SIEM & Monitoring
Kubernetes Security

Hall of Fame // COMPANIES I HAVE HACKED

Comcast
Comcast
Etsy
Etsy
AMEX
AMEX
NASA
NASA
Plusgrade
Plusgrade
Indeed
Indeed
Comcast
Comcast
Etsy
Etsy
AMEX
AMEX
NASA
NASA
Plusgrade
Plusgrade
Indeed
Indeed
Comcast
Comcast
Etsy
Etsy
AMEX
AMEX
NASA
NASA
Plusgrade
Plusgrade
Indeed
Indeed
Comcast
Comcast
Etsy
Etsy
AMEX
AMEX
NASA
NASA
Plusgrade
Plusgrade
Indeed
Indeed

Operations // Projects

Bug Bounty Researcher

Top 500 researcher identifying 70+ vulnerabilities, including critical RCE and account takeovers for 15+ companies. Recognized by major tech companies for responsible disclosure.

Burp Suite OWASP API Security

FavHunt

Open-source reconnaissance tool, fingerprinting web services via favicon analysis integrated with Shodan, useful to find hidden assets.

Python Shodan API Reconnaissance

Google Cybersecurity Portfolio

Professional certification project showcasing network traffic analysis with Wireshark and Splunk, documenting real-world cyberattack scenarios and mitigation strategies.

Splunk Wireshark Linux