$ cat about.txt

About Me

🔐

$ whoami

I'm Tameen Kassem — a penetration tester and security researcher focused on offensive security, penetration testing, and bug bounty hunting.

I actively compete on HackTheBox and TryHackMe, and publish detailed writeups to help the community learn from each challenge.

My areas of interest include web application security, Active Directory attacks, binary exploitation, and OSINT.

Certifications

CompTIA Security+
CompTIA
2024active
Google Associate Cloud Engineer
Google Cloud
2024active
Blue Team Level 1 (BTL1)
Security Blue Team
2024active

Experience

Vulnerability Assessment Contractor
Independent · Two Private Clients — Dubai, UAE
Jan 2026 — Apr 2026
  • Client A (multi-family wealth management): identified 2 Critical and 2 High severity findings across network and web-app attack surfaces using WPScan, Nmap, OpenVAS, and Burp Suite.
  • Client B (international skincare & beauty clinic chain): uncovered critical WordPress issues — exposed XML-RPC endpoint, unauthenticated user enumeration, and missing brute-force protection — through manual testing and passive reconnaissance.
  • Ran structured post-remediation retests, verifying client fixes against the original findings and providing formal sign-off.
Security Operations & Automation Engineer
[REDACTED] · Fashion E-commerce Platform — Dubai, UAE
Feb 2025 — Dec 2025
  • Designed a SOC architecture on Vultr Cloud VMs using Windows 10 endpoints, Wazuh, Shuffle SOAR, and TheHive.
  • Configured Wazuh agents and detection rules to centralize endpoint telemetry, raise alerts, and trigger active responses to suspicious behavior.
  • Built Shuffle SOAR playbooks that enrich IOCs with OSINT and auto-generate structured TheHive cases (mapped observables, severity, and triage tasks), reducing manual case creation; tracked remediation in Jira.
Network Solutions Consultant
PartySocial — Dubai, UAE
Oct 2024 — Feb 2025
  • Deployed SPF, DKIM, and DMARC records on Google Workspace to prevent email spoofing.
  • Performed incident response on an email-based attack — identifying PowerShell execution artifacts and suspicious logon activity with DeepBlueCLI and Windows Event Viewer, then quarantining the affected endpoint.
  • Reduced Wi-Fi latency by ~50% by optimizing Layer 2 bridging and wireless settings.
Cyber Security Analyst
Log Impactful Tech Solutions — Lisbon, Portugal
Jun 2024 — Aug 2024
  • Deployed OpenVAS to scan target networks and tuned results to eliminate false positives.
  • Built a pre-configured VM scanner for company-wide use with supporting documentation, and hardened hosts by disabling unused ports and services.
Network Security Analyst
[REDACTED] · Technology Services Firm — Amman, Jordan
May 2023 — May 2024
  • Reduced phishing email delivery by 30% through email quarantining, filtering, and sender blocking, tracking each reported event and remediation action in Jira.
  • Investigated suspicious attachments in sandboxed VMs, performing forensic triage with KAPE, ProcDump, Autopsy, and Scalpel.
  • Analyzed PCAP logs in Wireshark and used Splunk to detect anomalies and investigate persistence mechanisms in compromised systems.

Skills & Tools

Offensive Security
Web App PentestingNetwork PentestingActive Directory AttacksBuffer Overflow
Tools & Frameworks
Burp SuiteNmap / MasscanMetasploitGobuster / ffufWiresharkBloodHound
</>Languages
PythonBash / ShellPowerShellJavaScriptSQL
Platforms
HackTheBoxTryHackMeVulnHubHackerOne

// full resume

Download My Resume

PDF with full work history, certifications, and references.

⬇ Download Resume (PDF)