Khusham asghar web loader

Hi, my name is,


Khusham Asghar
System Engineer | Penetration Tester | Devops Engineer | Certified Ethical Hacking Master

I have 2 years of experience as a Penetration Tester at Gulf Trends. Initially, I started as a Mobile Application developer at Arfa Software Technology Park, Lahore. Currently, my work is on DevOps technologies such as AWS, Docker, Kubernetes, Terraform, Nexus, and Jenkins. My expertise lies in automation, encompassing security automation, Jenkins automation, AWS EC2 automation, and infrastructure code development using Terraform.

01. About

Hi πŸ‘‹ My name is Khusham Asghar. I am a Penetration Tester, Experienced API Developer with hands-on experience in designing, developing, and testing RESTful APIs. Skilled in creating scalable and secure solutions, collaborating with cross-functional teams and delivering high quality results within tight deadlines.

DevOps Engineer with a strong background and hands-on experience in AWS, Docker, Kubernetes, Terraform, Nexus, and Jenkins, proficient in security automation, Jenkins automation, AWS EC2 automation and infrastructure as code development using Terraform.

  • Backend Languages
  • Frontend Technologies
  • Cloud and DevOps
  • Cybersecurity
  • Security Tools
Khusham Asghar profile image

02. Experience

Penetration Tester

@Gulf Trends, Dubai

AUG 2023 - Present

  • Utilized python scripting for process automation, improving system efficiency and reducing manual workload by 35%.
  • Developed and maintained backup and disaster recovery procedures to ensure business continuity.
  • Conducted thorough system monitoring and performance analysis, identifying and rectifying potential system failures ahead of time, achieving 99.9% uptime across all systems.
  • Discovered and reported 10+ high-risk vulnerabilities that led to the immediate remediation of security flaws, reducing potential exploitation by 80%.
  • Executed simulated external and internal cyber-attacks using various pentesting tools such as Burp Suite, Metasploit, Nmap, Wireshark, Nexpose, Maltego, and Beef resulting in the successful identification of system weaknesses before malicious actors could exploit them.
  • Collaborated closely with development and IT teams to implement security patches and secure coding practices, resulting in a 25% decrease in security incidents post-engagement.
  • Led vulnerability assessments and risk analyses, prioritizing security fixes and assisting clients in meeting industry standards such as OWASP Top 10, NIST, and PCI DSS compliance.
  • Performed social engineering assessments, including phishing, vishing, and baiting, to evaluate human vulnerabilities and raise awareness, contributing to a 25% reduction in social engineering attacks across client organizations.

Application Security Intern

Arfa Software Technology Park

OCT 2022 - JUL 2023

  • Collaborated with cross-functional teams to design and implement intuitive, user-friendly front-end solutions using HTML5, CSS3, JavaScript, and frameworks such as React.js and Vue.js, improving client satisfaction by 30%.
  • Optimized database architecture and queries using MySQL and MongoDB, which resulted in a 20% improvement in data retrieval speed and ensured smooth data handling for high-traffic applications.
  • Built and optimized RESTful APIs, enabling smooth communication between front-end and back-end systems, enhancing the performance of applications and simplifying integrations with external services.
  • Ensured web application security by incorporating OWASP security principles, implementing SSL certificates, and performing regular security audits, significantly reducing vulnerabilities and increasing client trust.
  • Led the adoption of CI/CD pipelines (using tools like Jenkins, GitLab CI), automating deployment processes and reducing deployment times by 40%, ensuring continuous integration and rapid delivery of new features.

03. Skills

Backend Languages
  • Java (API Integration, Spring Boot)
  • SQL
  • PL/SQL
  • PostgreSQL
  • MySQL
  • Python


Frontend Technologies
  • HTML
  • CSS
  • JavaScript


Cloud and DevOps
  • AWS (Amazon Web Services)
  • Docker
  • Kubernetes
  • Terraform
  • Jenkins
  • Nexus
  • Git/GitHub
  • CI/CD


Cybersecurity
  • Penetration Testing
  • Cybersecurity
  • Web Security
  • Firewalls
  • Cryptography
  • Networking
  • Bash Scripting


Security Tools
  • Nmap
  • Metasploit
  • Burp Suite
  • Wireshark
  • Nessus
  • SonarQube
  • Snort
  • Trivy
  • Snyk
  • OWASP ZAP

04. Education

Bachelor's Degree in Information Technology

Apr 2019 - Apr 2023

University of Management & Technology - Lahore

Higher Secondary School Education

July 2016 - July 2018

Punjab Group of Colleges, Pasrur Campus

Secondary School Education | SSC

June 2014 - June 2016

The Educators School Pasrur, Sialkot

05. Projects