Dhaka, Bangladesh — open to security assessments

Delwar Alam

Cyber Security Assessor & Security Researcher

Certified Information Systems Auditor with over a decade hardening applications across the public and private sectors. I break web and mobile systems on purpose — then publish what I learn. Eleven papers on SQL injection, XSS, race conditions and kernel memory vulnerabilities, published from Dhaka to Dublin to Jakarta.

CISAISACA · 2022
CEHEC-Council · 2019
M.Sc.Cyber Security
Portrait of Delwar Alam
11publications
8major assessments
  • 0 Years in security
  • 0 Papers & a book
  • 0 Major assessments
  • 0 Countries published in
01 — About

Security is a research problem
before it is a checklist.

I am a Certified Information Systems Auditor and security researcher based in Dhaka. For over eight years I have assessed web applications, mobile apps, networks and payment infrastructure for banks, fintechs, national media and government programmes.

My work sits where offensive testing meets formal audit: I plan and execute research-driven assessments, run red-team and blue-team exercises, and document findings so engineering teams can actually act on them. Alongside application security I work with encryption technologies, machine learning and blockchain — Solidity, Hyperledger Fabric, and the tooling around them.

The research half matters just as much. I have co-authored roughly a dozen papers on the security posture of the Bangladeshi web — SQL injection across the .bd domain, XSS and CSRF in public services, the Heartbleed fallout — plus a Bengali-language book on ethical hacking published at the Ekushey Book Fair.

Certified Information Systems Auditor

ISACA · credential 221897398

Issued Aug 2022 · valid to Jan 2026

Certified Ethical Hacker

EC-Council · credential ECC9506871432

Issued Dec 2019

Education

  • 2016 — 2018 M.Sc. Cyber Security IU International University of Applied Sciences
    Bad Honnef, Germany
  • 2011 — 2015 B.Sc. Software Engineering Daffodil International University
    Dhaka, Bangladesh

Focus areas


      
02 — Experience

Where I have been working.

  1. Feb 2018 — PresentCurrent

    Cyber Security Assessor & Security Researcher

    BugsBD Limited · Dhaka, Bangladesh

    Lead vulnerability assessments and penetration tests for enterprise and government clients — planning engagements, executing web, mobile and network testing, and maintaining findings through remediation.

  2. Sep 2017 — PresentCurrent

    Organizing Committee

    WMSCI · Orlando, Florida, USA

    Serving on the organizing committee for the World Multiconference on Systemics, Cybernetics and Informatics, reviewing and shaping the security programme.

  3. May 2016 — Jan 2018

    Cyber Security Analyst

    IQSA Soft · Dhaka, Bangladesh

    Day-to-day security analysis and application testing across client systems, with a focus on web application defence.

  4. Jan 2014 — Apr 2016

    Cyber Security Engineer

    Soft IT Security · Dhaka, Bangladesh

    Built and hardened security controls for customer environments; first hands-on years of offensive testing and secure configuration.

03 — Toolkit

What I work with.

Security

Vulnerability assessment, security research, web gateways, penetration testing, red team and blue team operations.

Testing tools

Metasploit · Nmap · SIEM · PAM · Nessus · Wireshark · Nexpose · Archery

Languages

C · JavaScript · Python · PHP · Perl · MySQL

Frameworks

Laravel · CodeIgniter · Django

Systems

Mixed Windows and Linux — Kali, Red Hat, Backtrack, Ubuntu — across databases and virtualised or physical servers.

Blockchain

Solidity · Truffle · Ganache CLI · EVM · Remix · Hyperledger Fabric · Hyperledger Composer

IT discipline

Cloud security, networks, application design, distributed computing, Active Directory and business recovery.

Environments

Visual Studio · Eclipse · NetBeans · Android Studio · MATLAB

04 — Research

Published work.

Peer-reviewed papers on the security posture of real systems, published at IEEE and international conferences across seven countries.

// publication venues · orthographic projection
drag to rotate
    1. 2018

      Hacking er Golokdhadha Book

      Co-author · published at Ekushey Book Fair 2018, Dhaka

      A Bengali-language book on ethical hacking and cyber security — texts, code and the logic behind common attacks.

    2. 2018

      A Study of the Effects of Heartbleed Vulnerability in Bangladesh Journal

      Zaman, M., Alam, D., Bhuiyan, T., & Farah, T. — International Journal of Cyber-Security and Digital Forensics, 7(3), 243–248

    3. 2017

      Study of the Dirty Copy on Write, a Linux Kernel Memory Allocation Vulnerability IEEE

      D. Alam, M. Zaman, T. Farah, R. Rahman, M. S. Hosain — International Conference on Consumer Electronics and Devices (ICCED), London, pp. 40–45

      10.1109/ICCED.2017.8019988
    4. 2017

      Study of Race Condition: A Privilege Escalation Vulnerability

      Farah, T., Shelim, R., Zaman, M., & Alam, D. — WMSCI 2017, Orlando, Florida, USA

    5. 2016

      Evaluating the Readiness of Cyber Resilient Bangladesh Journal

      Bhuiyan, T., Alam, D., & Farah, T. — Journal of Internet Technology and Secured Transactions, 4(3), 405–415

      10.20533/jitst.2046.3723.2015.0051
    6. 2016

      Assessment of Vulnerabilities of Web Applications of Bangladesh: A Case Study of XSS & CSRF IEEE

      T. Farah, M. Shojol, M. Hassan, D. Alam — Sixth International Conference on Digital Information and Communication Technology and its Applications (DICTAP), Konya, pp. 74–78

      10.1109/DICTAP.2016.7544004
    7. 2015

      A Case Study of SQL Injection Vulnerabilities Assessment of .bd Domain Web Applications IEEE

      D. Alam, M. A. Kabir, T. Bhuiyan, T. Farah — Fourth International Conference on Cyber Security, Cyber Warfare and Digital Forensic (CyberSec), Jakarta, pp. 73–77

      10.1109/CyberSec.2015.23
    8. 2015

      Investigation of Bangladesh Region Based Web Applications: 64 Based, Local and Global SQLi Vulnerability IEEE

      T. Farah, D. Alam, M. N. Bin Ali, M. A. Kabir — IEEE International WIE Conference on Electrical and Computer Engineering (WIECON-ECE), Dhaka, pp. 177–180

      10.1109/WIECON-ECE.2015.7443891
    9. 2015

      SQLi Vulnerability in Education Sector Websites of Bangladesh IEEE

      D. Alam, T. Bhuiyan, M. A. Kabir, T. Farah — Second International Conference on Information Security and Cyber Forensics (InfoSec), Cape Town, pp. 152–157

      10.1109/InfoSec.2015.7435521
    10. 2015

      SQLi Penetration Testing of Financial Web Applications: Investigation of Bangladesh Region IEEE

      T. Farah, D. Alam, M. A. Kabir, T. Bhuiyan — World Congress on Internet Security (WorldCIS), Dublin, pp. 146–151

      10.1109/WorldCIS.2015.7359432
    11. 2015

      Exploring the SQL Injection Vulnerabilities of .bd Domain Web Applications

      Alam, D., Farah, T., & Kabir, M. A. — 3rd International Conference on Advances in Computing, Electronics and Communication (ACEC), pp. 10–11

    05 — Selected work

    Assessments & engagements.

    A selection of organisations whose systems I have tested, audited or hardened.

    01 2022

    SOS Bangladesh

    Lead Cyber Security Auditor

    Web vulnerability assessment and penetration testing — an independent review of security controls and information systems, testing the safety and effectiveness of individual cyber-defence components.

    02 2021

    TallyKhata — Progoti Systems

    Project Manager

    Web and mobile application security assessment. Managed a team of senior security and information-assurance professionals, working directly with management on cyber security strategy.

    03 2020

    aamarPay

    Network Security Specialist

    PCI compliance. Designed and supported network security architecture — firewalls, unified threat management, web filtering, WAF, email security, two-factor authentication and VPN.

    04 2020

    SureCash

    Security Analyst

    Vulnerability assessment and penetration testing, including physical security assessment of systems, servers and network devices.

    05 2019

    Daffodil International University

    Vulnerability Assessor

    Assessment of systems and networks within the university network environment, identifying deviations from acceptable configurations.

    06 2018

    Prothom Alo

    Penetration Tester

    Web vulnerability assessment and penetration testing across computer systems, networks and applications for the country's largest daily.

    07 2018

    a2i — Access to Information

    Cyber Security Specialist

    Web and mobile application vulnerability assessment and penetration testing for the national digital-government programme, with ongoing scanning and network monitoring.

    08 2017

    Computer Ease Limited

    Cyber Security Specialist

    Vulnerability assessment and penetration testing of Management Information Systems, with continuous scanning and patch verification.

    07 — Community

    Building the next generation.

    • 01 2015 — Present Co-Founder & Advisor SofoLab, Daffodil International University
    • 02 2014 — Present Advisor Software Engineering Club, Daffodil International University
    • 03 2015 — Present Alumni Adviser SWE Alumni Association, Daffodil International University
    • 04 2014 — Present Owner SqliWiki — forum.sqliwiki.com
    • 05 2015 — 2016 Secretary DIU ISACA Student Group, Daffodil International University
    08 — Contact

    Let's talk about
    your attack surface.

    Available for security assessments, penetration testing, audit engagements and research collaboration.

    Send a message