Offensive Security Specialist

Finding vulnerabilities before attackers do

Mohammed Al-Faleh is a Riyadh-based penetration tester with 5 industry certifications and a verified track record of discovering critical vulnerabilities in production systems at global companies. Available for web application, network, API, and cloud security engagements.

20+
Critical/high findings for enterprise clients
8+
Real-world vulnerabilities found in under one week
5
Industry certifications including CPTS & eWPTXv2
4
Global companies with confirmed security findings
MA

From fixing systems to breaking them — on purpose.

I wasn't always a pentester. I started in enterprise IT support at a Saudi company — fixing systems and wondering how they'd actually been broken. That curiosity pulled me into offensive security, and it's still what drives me every day.

Today I hold five professional certifications — including CPTS and eWPTXv2 — and I'm completing my Computer Science degree while staying active in bug bounty programs. I've found critical, real-world vulnerabilities in production systems at global companies, and I've been trusted with enterprise clients in Riyadh.

The day you stop learning in this field is the day you start falling behind — so this is a full-time commitment, not a side project. I write reports for humans, not just developers: every finding includes business impact, reproduction steps, and fixes your team can actually apply. And I work with clients in Arabic and English.

Trilingual — Arabic · English · Filipino B.Sc. Computer Science (in progress) Certifications: CPTS · eWPTXv2 · eCPPT · eJPT · Security+
Certified by HTB CPTS eWPTXv2 eCPPT eJPT CompTIA Security+

Penetration Testing Services

Structured security assessments delivered with clear, actionable reports. Every engagement includes a retest to confirm your fixes are effective.

✦ Introductory rates currently available.

Testing aligned with OWASP Top 10:2025, NIST SP 800-115, and mapped to the SAMA Cyber Security Framework and NCA Essential Cybersecurity Controls (ECC) compliance expectations — ideal for regulated Saudi enterprises.

OWASP Top 10:2025 NIST SP 800-115 SAMA CSF NCA ECC ISO 27001:2022

Web Application Pentest

Manual testing of your web applications for OWASP Top 10 vulnerabilities — IDOR, XSS, authentication bypass, business logic flaws, and more. Includes full PoC documentation.

Starting from SAR 7,500

Network Penetration Test

Internal and external network assessments targeting misconfigurations, weak credentials, lateral movement paths, and privilege escalation opportunities across your infrastructure.

Starting from SAR 9,500

Cloud & Infrastructure Security Review

Manual review of cloud environments (AWS, Azure) for misconfigurations — exposed S3 buckets, overpermissioned roles, insecure storage, and weak access controls before attackers find them first.

Starting from SAR 8,000

Vulnerability Assessment

Systematic scanning and manual review of your environment to identify, classify, and prioritize security weaknesses — ideal as a first step before a full pentest engagement.

Starting from SAR 3,500

API Security Testing

Deep testing of REST and GraphQL APIs for BOLA/IDOR, broken authentication, excessive data exposure, and mass assignment — including business logic abuse specific to your API design.

Starting from SAR 5,500

Retest & Remediation Verification

After your team addresses findings from a pentest, I retest every vulnerability to confirm the fix is effective and no new issues were introduced in the process.

30% of original engagement

How It Works

A clear, low-friction process from the first conversation to a confirmed fix. You always know what happens next — and what it costs.

1

Free Scoping Call

A 30-minute call to understand your environment, goals, and anything off-limits. You get a fixed quote and timeline before any work begins.

2

Testing Phase

Targeted manual and structured testing against the agreed scope, with progress updates along the way — never a silent black box.

3

Report & Prioritisation

A clear report ranked by business risk, with reproduction steps, proof-of-concept evidence, and practical fix guidance your team can act on.

4

Retest & Closure

After your team applies fixes, I retest every finding to confirm it is resolved — and confirm no regressions were introduced.

Every engagement starts with a free, no-obligation scoping call.

Book Your Free Scoping Call

Verified Security Findings

Real vulnerabilities discovered and responsibly disclosed in production systems at global companies through bug bounty programs.

Coupang · HackerOne Critical

S3 Origin Takeover via CloudFront

Third-party-owned apex bucket served via CloudFront on an HSTS domain, allowing full control over served assets. Followed by a world-writable S3 origin leading to stored XSS via JavaScript chunk injection.

Business impact: attackers could replace content served to all visitors of an HSTS domain — undermining full trust in the site.
Wallet in Telegram · HackerOne Critical

BOLA/IDOR — Financial Data Exposure

Missing ownership checks on P2P offer endpoint exposed bank and payment details of 81 distinct users across 118 offers. No authentication bypass required — a structural authorization failure.

Business impact: bank and payment details of 81 users exposed — direct financial and regulatory risk.
Wallet in Telegram · HackerOne High

Geographic Restriction Bypass

JWT-embedded country code claim not re-validated per request, allowing financial withdrawal API to be reached from any egress IP, bypassing country-level financial controls entirely.

Business impact: country-level financial controls bypassed, enabling withdrawals from restricted jurisdictions.
23andMe · HackerOne Critical

Full Account Takeover Chain

Missing re-authentication on email, password, and 2FA change endpoints enabled complete account takeover from a single valid session. Step-up controls existed on other endpoints, confirming deliberate misapplication.

Business impact: complete takeover of any account, including sensitive personal data — exploitable at scale with minimal skill.
Wallet in Telegram · HackerOne High

Broken Access Control — Merchant API Key Minting

Non-merchant users at LEVEL_0 could mint valid merchant API keys accepted by production merchant endpoints, effectively granting unauthorized merchant-tier access.

Business impact: any user could gain merchant-tier API access, exposing payment-side operations.
flynas · BugBounty.sa Critical

OTP Hijacking & JSON Manipulation

Three critical vulnerabilities identified including OTP hijacking, JSON manipulation exploit, and email flooding attack vector. Recognized for responsible disclosure by flynas security team.

Business impact: bypassed one-time passcodes — the final safety net for customer accounts.

Certifications

Hands-on, practical certifications from recognized offensive security bodies — not just theoretical knowledge.

CPTS
Certified Penetration Testing Specialist
Hack The Box · 2026
eWPTXv2
Web App Pentester eXtreme
INE Security · 2024
eCPPT
Certified Professional Penetration Tester
INE Security · 2023
eJPT
Junior Penetration Tester
INE Security · 2022
Sec+
CompTIA Security+ (CE)
CompTIA · 2022

Security Assessment Calculator

Build a quick estimate based on the type and size of assessment you need. The final quote is confirmed after reviewing your scope.

Detailed report PoC documentation Retest included
Estimated starting range
SAR 7,500

Estimated timeline: 4–7 days

Final pricing depends on scope, access requirements, and testing complexity.

Request Exact Quote

Frequently Asked Questions

Straight answers to the questions clients ask most before starting an engagement.

What exactly do I receive at the end?
A detailed report ranking every finding by business risk, with reproduction steps and proof-of-concept evidence, plus practical remediation guidance your team can action. A re-test is included to confirm fixes work.
How long does an engagement take?
Most assessments complete in 4–10 working days depending on scope. You receive a confirmed timeline during the scoping call, before any commitment.
Is the engagement confidential? Do you sign an NDA?
Yes. An NDA is signed before testing begins, and findings are disclosed only to you. Public disclosure of any vulnerability is never done without your written approval.
Will you test our production systems safely?
Yes. Before we start, we agree on a rules-of-engagement document that defines scope, testing windows, authorised techniques, and any systems or actions that are strictly off-limits.
Can this help with our compliance requirements?
Yes. Testing follows OWASP Top 10:2025 and NIST SP 800-115 methodology, and reports can be mapped to the SAMA Cyber Security Framework, NCA Essential Cybersecurity Controls (ECC), ISO 27001:2022, or other frameworks you need, to serve as compliance evidence.
What if we can't fix everything immediately?
That's normal. You receive a priority-ranked list so your team can tackle the highest-risk issues first, and a re-test remains available within 3 months at 30% of the original engagement fee (from SAR 2,500).

Request a Pentest

Tell me about your environment and what you need tested. I'll respond within 24 hours with a clear scope, timeline, and pricing.

Based in Riyadh, KSA — Remote & On-site available

Opens your email app with this request ready to send to m45faleh@falehsec.dev.