Abdullah Kareem · CyberKareem
Penetration Tester · Security Researcher
I test applications, APIs, cloud, and identity systems, then explain the attack path and the fix.
I'm Abdullah Kareem. My work combines authorized penetration testing, security engineering, and coordinated vulnerability disclosure.
- Current role
- Penetration Tester
- Since April 2026
- Public research
- 25 assigned CVEs
- Vendor-linked records and case studies
- Core credentials
- HTB CAPE · OSWE · OSEP · OSCP+ · HTB CPTS · CISSP
- Provider-verifiable records
Experience
Offensive security backed by enterprise systems experience.
My background spans infrastructure operations, security engineering, and authorized penetration testing.
View professional background- NowApr 2026 to present
Penetration Tester
Security assessment team
Authorized application, mobile, and adversary-simulation assessments with peer review and remediation-focused reporting.
- RecentFeb to Apr 2026
Cybersecurity Specialist
Smart Oasis Company
Network and identity testing, vulnerability management, monitoring, and security-by-design review.
- FoundationDec 2017 to Dec 2025
IT & Telecommunications Specialist
United Nations
Enterprise infrastructure, identity modernization, network operations, security response, and staff awareness.
Selected evidence
Work you can inspect.
Public source, methodology, and operating limits accompany each entry.
kameHunt
An LLM-assisted variant-analysis engine that validates and ranks static-analysis matches into a short list of manually-verifiable leads.
Python · Public MVPView project Recon intelligenceSurfaceLens
A local-first attack-surface workbench for turning common recon output into explainable priorities.
Python · Public MVPView project Security engineeringBuilding seg-test: A PCI DSS Segmentation Evidence Runner
seg-test runs approved checks from defined source VLANs, preserves raw Nmap output, and packages evidence without making compliance decisions.
12 Jul 2026 · 10 minRead article Security engineeringBitLocker Cryptographic Erase Utility: Design, Limits, and Validation
A reviewed account of a BitLocker-based cryptographic-erase prototype, its operating assumptions, and the validation required before real-world use.
19 May 2025 · 6 minRead articleStart a conversation
Discuss a role, a security assessment, or a disclosure.
Email me directly. For assessment or disclosure enquiries, start with high-level context and move sensitive details to an agreed private channel.