Available for freelance, contract and part-time opportunities.

OFFENSIVE SECURITY · PENETRATION TESTER

Faris Krivić

Offensive Security

Cybersecurity professional with hands-on experience in penetration testing, security engineering and vulnerability research across web applications, APIs, mobile applications, networks, Active Directory and IT/OT environments.

6 public CVEs Oracle · Nokia · SonicWall · Informatica recognition EU + BiH work eligible
6Public CVEs
4+Years in cybersecurity
Web → OTBroad security experience

Offensive security experience with a defensive perspective.

My background combines penetration testing and vulnerability research with hands-on security engineering. I assess systems from an attacker’s perspective while keeping remediation, operational risk and business impact in view.

My experience spans product security research, client-facing penetration testing and consulting, and enterprise security engineering across both IT and OT environments.

Web SecurityAPI SecurityMobileNetworkActive DirectoryIT / OTIncident ResponseVulnerability Research

PENETRATION TESTING SERVICES

Security testing focused on exploitable risk.

Manual and tool-assisted assessments tailored to the target, attack surface and rules of engagement. Click a service to see the testing scope and deliverables.

01

Web Application Testing

Authentication, authorization, business logic, input handling, session security and server-side attack surfaces.

02

API Security Testing

REST and GraphQL security testing focused on authorization, authentication, injection and business logic abuse.

03

External Network Testing

Internet-facing infrastructure, exposed services, remote-access surfaces and externally exploitable configuration weaknesses.

04

Internal Network & AD Testing

Internal networks, Active Directory, privilege escalation, segmentation and lateral movement attack paths.

05

Mobile Application Testing

Android and iOS application security across local storage, authentication, traffic, APIs and client-side assumptions.

WHAT YOU GET

Clear findings. Reproducible evidence. Practical remediation.

01Scoping & rules of engagement 02Manual + tool-assisted testing 03Executive + technical reporting 04Remediation guidance & retesting

WORK WITH ME

Available beyond individual penetration testing engagements.

I’m open to freelance, contract and part-time opportunities in offensive security, penetration testing, vulnerability research and security engineering — from focused short-term work to ongoing collaboration.

Discuss an opportunity ↗

CURRICULUM VITAE

Professional experience

Cybersecurity roles spanning product security research, penetration testing, consulting and enterprise security engineering.

02/2026 — 08/2026

Cyber Security Engineer

DPMetals BH · DPM Metals Inc.

  • Safeguarded information systems and operational technology infrastructure within a global mining environment.
  • Maintained controls across network, server and endpoint environments using EDR, SIEM.
  • Conducted internal penetration testing and vulnerability management across IT and OT environments.
  • Incident response, threat monitoring, security awareness and audit support.
05/2022 — 03/2026

Penetration Tester / Information Security Consultant

Infigo IS

  • Conducted penetration tests of web, mobile and network environments, identifying vulnerabilities such as RCE, privilege escalation and IDOR.
  • Developed custom offensive tooling and automation in Python and Go for reconnaissance and exploitation workflows.
  • Delivered reports aligned with OWASP and MITRE ATT&CK, including proof-of-concept evidence and remediation guidance.
  • Presented findings to clients, supported remediation and mentored new team members.
11/2021 — 05/2022

Security Researcher

Bright Security

  • Performed product security assessments and vulnerability research, including LFI and race-condition findings.
  • Validated bug bounty submissions and reproduced reported vulnerabilities.
  • Implemented Bright scanner integration in CI/CD workflows using GitHub Actions and other CI/CD tools.

SECURITY RESEARCH

Public vulnerabilities & recognition

Responsible disclosure work recognized by major technology vendors, alongside multiple public CVE records.

ORACLEAcknowledged vulnerability disclosure
NOKIAAcknowledged vulnerability disclosure
SONICWALLAcknowledged vulnerability disclosure
INFORMATICAAcknowledged vulnerability disclosure

CREDENTIALS

Education, certifications & technical skills

EDUCATION

Bachelor’s Degree — Information Technology

CERTIFICATIONS
CASA

Certified API Security AnalystAPIsec University

PNPT

Practical Network Penetration TesterTCM Security

CAPen

Certified AppSec PentesterThe SecOps Group

CAP

Certified AppSec PractitionerThe SecOps Group

PMPA

PMPATCM Security

TECHNICAL TOOLKIT

Offensive Web, Mobile, API, Network, Active Directory

Operations SIEM, EDR, Firewalls, Incident Response

Tools Burp Suite, Nmap, Nessus, Metasploit, SQLmap

Automation Python, Go

Frameworks OWASP Top 10, MITRE ATT&CK

CONTACT

Penetration testing, freelance, contract or part-time?

Send a short description of what you need, the scope or role, and your preferred timeframe. I’ll have the context needed to continue the conversation.

Your message is sent directly to hello@fariskrivic.com.