Penetration Tester & Cybersecurity Specialist

IMAD
OUGUAHI

Red Teamer. Web Exploitation Expert. AI Automation Engineer.
I find vulnerabilities before they become incidents.

🛡️CompTIA Security+
⚔️HTB CWES
🎯CRTA
🔐ISO 27001
scroll

The mind behind the hunt.

My journey in cybersecurity began long before my formal studies — driven by CTF challenges since 2019, I honed an offensive mindset well before entering the industry. After four years in a role that offered limited growth, I made the decisive choice to return to my true calling: Offensive Security and Penetration Testing.

Now a CompTIA Security+ certified professional and developer of the CloudReaper framework, I combine years of self-taught passion with rigorous technical training. I specialize in auditing complex infrastructures, identifying critical vulnerabilities, and continuously pushing technical limits.

Location Casablanca, Morocco
Experience 4+ years in cybersecurity
Current M2 — SUPEMIR 2024–2025
Bootcamp DataProtect / SkillsLab — Red Teaming (Aug–Dec 2025)
Platforms HackTheBox · TryHackMe · CTFtime
CTF 1st Place (recent) · 3rd National (2019)
Languages Arabic (Native) · English B2 (IELTS) · French B2 (TCF TP)
Email ouguahii@gmail.com

Tools of the trade.

⚔️

Offensive Security

Red TeamingPenetration TestingBug BountyAD ExploitationAndroid REOSINT
🌐

Web Security

OWASP Top 10XSS / SQLi / IDORAPI SecurityBurp Suite ProLogic Flaws
📡

Network & Email

SPF/DKIM/DMARCDNS SecurityNetwork PentestingWiresharkNmap
🔬

Reverse Engineering

GhidraIDA ProRadare2x64dbgGDBBinwalk
🛡️

Defense & Standards

MITRE ATT&CKISO 27001NISTPTESSplunk SIEMSOC
💀

Exploitation Frameworks

MetasploitCobalt StrikeBloodHoundMimikatzImpacket

AI & Automation Arsenal

🤖

AI & LLMs

Prompt EngineeringLangChainOpenAI / AnthropicRAG Pipelines
⚙️

Automation

PythonBash/ShellPowerShelln8nMake
☁️

Cloud & Infra

AWSGCPDockerCI/CDAPI Integration
🔗

Security Automation

AI-Assisted ReconCustom ToolingCloudReaper
PythonRustC#BashPowerShellPHPJavaScriptSQLHTML/CSS

Earned, not given.

Jan 2026🛡️

CompTIA Security+ (SY0-701)

CompTIA

Nov 2025🏆

HTB Certified Web Exploitation Specialist

HackTheBox — CWES

Mar 2025🎯

Certified Red Team Analyst (CRTA)

CWL

May 2025🔐

ISO/IEC 27001:2022 Information Security Associate

SkillFront

4 years in the field.

Dec 2020 – Dec 2024 · Tangier, Morocco

GM SARL — Cybersecurity Consultant & Email Security Specialist

SPF/DKIM/DMARCPenetration TestingOSINTSecurity Architecture
  • Architected and deployed email authentication frameworks across 20+ enterprise domains, reducing successful phishing attacks by 90%
  • Conducted Black/Gray Box penetration tests identifying critical vulnerabilities in web applications and network infrastructure
  • Led advanced OSINT investigations for threat profiling and developed targeted countermeasures
  • Spearheaded the company's new branch operations in Istanbul, Turkey
  • Delivered cybersecurity awareness training to 100+ employees
Aug 2019 – Feb 2020 · Beni Mellal, Morocco

EcoSmart Business — Web Security Developer (Internship)

Secure DevelopmentOWASPSSL/TLSCode Auditing
  • Developed secure web applications adhering to "Security by Design" and OWASP Top 10 principles
  • Conducted comprehensive code reviews, remediating SQL Injection, XSS, and CSRF vulnerabilities
  • Implemented SSL/TLS encryption across production servers and integrated security testing into CI/CD pipelines
2017–2019 · Morocco

ISTA NTIC / COSUMAR / FerLio — System Admin & Industrial/Dev Internships

Work in the field.

02
ACTIVE

Red Team Operations

Simulating real-world attacks to test and strengthen security postures. Advanced pentesting and full-scope assessments.

03
ACTIVE

Bug Bounty Hunting

XSS, SQLi, IDOR, API logic flaws. Proactive responsible disclosure on major platforms.

04
COMPLETE

Email Security Hardening

SPF/DKIM/DMARC on 20+ domains. Measurable 90% phishing reduction.

05
IN PROGRESS

M2 Pentest Project

Black-box pentest of a private platform. Full security report and remediation roadmap.

06
COMPLETE

CTF Competitions

1st place recently, 3rd national in 2019. Active on HackTheBox and TryHackMe.

From the field.

$ fetching posts from Medium...

Let's work together.

Available for penetration testing, security audits, red team engagements, and AI automation projects. Freelance & contract.