Muhammad Khan

Muhammad Khan

Senior Penetration Tester @ Motion Recruitment

About

I am a Penetration Tester and Senior Security Engineer with over 6 years of experience delivering offensive security assessments across web applications, APIs, Active Directory, enterprise networks, and cloud platforms (AWS, Azure, GCP). My work has consistently followed industry frameworks including PTES, NIST 800-115, MITRE ATT&CK, and OWASP, ensuring assessments are structured, repeatable, and directly aligned to business impact. Over the course of more than 50 penetration tests and red team engagements, I have identified and exploited high-impact vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), broken access control, and misconfigurations. Beyond discovery, I work closely with IT and engineering teams to validate remediation and implement durable defenses—closing lateral movement paths, improving identity security, and strengthening network and cloud perimeters. My technical expertise spans penetration testing and red teaming (scoping, threat modeling, exploitation, reporting, and re-testing), and a strong toolkit including Kali Linux, Burp Suite, Nmap, Metasploit, SQLmap, Wireshark, Dirbuster, and Nikto. I am also experienced in infrastructure and cloud security, including network segmentation, Active Directory hardening, firewall policy optimization, and cloud perimeter controls. In addition, I leverage Python and Bash scripting to automate reconnaissance, evidence collection, and reporting, enabling more efficient and scalable testing operations.

Country

United States

City

New Brunswick

Industry

Information Technology & Services

Skill

Red Team, Penetration Testing, Kali Linux, Python (Programming Language), Red Teaming, Network Administration, DevOps, Network Engineering, Microsoft Azure, Linux Firewalls, Google Cloud Platform (GCP), Identity and Access Management (IAM), Software Development, Security Information and Event Management (SIEM), Amazon Web Services (AWS), Information Security, Cyber Threat Hunting (CTH), Security Implementation, Network Security Implementation, Security Management

Experience

Motion Recruitment

Senior Penetration Tester

Motion Recruitment

LinkedIn
2025-4 - Present · 1 yr 6 mos

New Jersey, United States

Penetration Testing & Bug Bounty • Conducted penetration testing on web applications (OWASP WSTG) and mobile applications (OWASP MSTG). • Performed security assessments on Docker, AWS, and Kubernetes environments. • Implemented and validated bug bounty findings, reproducing exploits to confirm impact and remediation. Red Team Operations & Adversary Emulation • Executed red team engagements on Active Directory, aligned with MITRE ATT&CK tactics (Reconnaissance → Initial Access → Execution → Persistence → Privilege Escalation → Credential Access → Lateral Movement → Exfiltration). • Simulated adversary techniques against AWS services (IAM, EC2, S3, ROSA, EKS, Lambda) to identify misconfigurations and gaps. Application Security • Reviewed and validated developer-implemented mitigations, ensuring secure SDLC practices. • Defined security verification requirements for production releases. • Implemented SAST tools (SonarQube, Snyk, Semgrep, MobSF) to identify vulnerabilities in CI/CD pipelines. • Performed DAST scanning on new product releases to uncover runtime security flaws.

JANA Corporation

Penetration Tester

JANA Corporation

LinkedIn
2021-12 - 2025-5 · 3 yrs 6 mos

Toronto, Ontario, Canada

Led 50+ web/mobile/API and internal network tests under PTES/NIST 800-115; mapped findings to OWASP Top 10 and MITRE ATT&CK and drove re-tests to closure. Ran vulnerability management across on-prem/cloud with Nessus/Qualys; triaged by CVSS, set SLAs, and tracked remediation with engineering/IT. Executed grey/black-box exploitation using Burp Suite, Nmap (NSE), SQLMap, and custom Python/Bash on Kali Linux; uncovered IDOR, auth bypass, crypto, and logic flaws. Conducted adversary emulation with Cobalt Strike and traffic analysis in Wireshark; documented lateral-movement paths and recommended segmentation/IDS/EDR controls. Assessed AWS and APIs against OWASP API Top 10; identified misconfigurations, hardened cloud perimeters, and improved data-pipeline security.

Ontario Power Generation

Security Engineer

Ontario Power Generation

LinkedIn
2019-5 - 2021-12 · 2 yrs 8 mos

Toronto, Ontario, Canada

Led web & API penetration tests under PTES/NIST 800-115 using a Kali Linux toolchain (Burp Suite, OWASP ZAP); uncovered OWASP Top 10 issues and validated fixes. Executed internal network and Active Directory assessments; mapped attack paths and lateral movement with Nmap, BloodHound, and CrackMapExec; recommended segmentation and firewall hardening. Drove vulnerability management across on-prem and cloud (AWS/Azure); tuned Nessus/Qualys scans, prioritized by CVSS, and tracked remediation to closure. Built Python/Bash automation in Kali Linux to standardize recon (Nmap scripts), wordlists, and evidence collection, improving speed and consistency. Produced decision-ready reports and PoCs mapped to MITRE ATT&CK; collaborated with engineering/IT to implement controls, re-test, and close findings (Metasploit, Wireshark).

Toronto Metropolitan University

Electrical and Computer Engineering Representative

Toronto Metropolitan University

LinkedIn
2017-9 - 2019-4 · 1 yr 8 mos

Toronto, Ontario, Canada

• Collaborated with students from all academic levels in electrical engineering programs to identify challenges at the intersection of EE and cybersecurity, such as limitations in hands-on network security training for embedded systems and vulnerabilities in IoT device simulations, and presented these insights during faculty meetings, resulting in curriculum improvements that enhanced student preparedness for roles involving penetration testing of hardware-integrated networks and ethical hacking in electrical infrastructure. • Organized and led cybersecurity labs for electrical engineering students, focusing on practical exercises in network vulnerability scanning, secure coding for embedded devices, and simulating attacks on IoT networks using tools like Nmap and Wireshark, fostering hands-on skills in penetration testing and improving participants' ability to secure electrical systems against cyber threats.

Education

Toronto Metropolitan University

Toronto Metropolitan University

LinkedIn

Electrical and Electronics Engineering

Relavent Course Material : Computer Programming Fundamentals Software Systems Digital Systems Electric Networks Engineering Algorithms and Data Structures Discrete Mathematics for Engineers Differential Equations and Vector Calculus Signals and Systems I Probability and Stochastic Processes Communication Systems Control Systems Signals and Systems II

Muhammad Khan's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.