Report this freelancer

Youssef Khaled

AppSec (Mobile, Web)
Middle East
25 September 1999
  • Successful Projects
    0
  • Services Delivered
    1
  • Completed Services
    0
  • Services Pending
    0

Freelancer Information

I’m a Senior Application Security Engineer with over 6 years of hands-on experience securing mobile (Android/iOS) and web applications.
I specialize in identifying, fixing, and preventing security vulnerabilities across the full development lifecycle. Whether you need to secure a mobile app, conduct a code review, or integrate security tools into your CI/CD pipeline—I’ve got you covered.

🔐 My Expertise Includes:

  • Mobile & Web App Penetration Testing
  • Vulnerability Assessment & Remediation
  • OWASP Top 10 (Mobile & Web) Mitigation
  • SDLC Integration & Secure Code Review
  • Tools: Burp Suite, Frida, Objection, SAST, DAST, SCA, IAST
  • Security Hardening: SSL Pinning, Root/Jailbreak Detection, Biometric Bypass Fixes
  • Reverse Engineering & Runtime Protection
  • Leading & mentoring AppSec teams

I’ve worked with high-impact companies like AAIB, MDI, Dsquares, and Orcas, helping them lock down their platforms, eliminate critical security bugs, and build secure-by-design products. I’m also OSCP-certified and have hands-on experience with mobile penetration testing (Attify certified).
If your app or platform needs serious security attention, from deep vulnerability testing to secure architecture planning, I’m here to help. Let’s ensure your users and protect your business.


Freelancer Education

B
AUG 2017 – JUL 2021 Bachelor in computer Science
Higher Institute of Computer Science and Information Systems in 6th of October

Work & Experience

A
Jan 2018 - Mar 2019 Android Developer
Abstract

This is a Digital Marketing Solutions and software house • I worked on security issues and penetration test bugs and fixed it like Biometric Authentication Bypass, Sensitive Data Leaked in Application’s Memory, SSL-Pinning Bypass, Root Detection Bypass, Side-Channel Information Leakage, Lack of Anti-Tampering and Runtime Integrity Detection. • I worked on developing TheCrew app. You can order the crew to do your event • I worked with Firebase Database to retrieve and display data from NoSql Database • I used MVP architecture patterns to develop the application. • I developed a chat module using Firebase Realtime Database.

S
Apr 2019 - Apr 2023 Senior Android Developer
Orcas

Orcas is a mobile application that connects parents and students with trusted tutors. Orcas has 200k users and helps more than 6000 tutors to get more experience and money. • I worked on security issues and penetration test bugs and fixed it like : Sensitive Data Leaked in the Application’s Memory, SSL-Pinning Bypass, Side-Channel Information Leakage, Lack of Anti-Tampering and Runtime Integrity Detection. • I revamped all the screens in the app and refactored 80% of the legacy code and changed the architecture from one model app to modular architecture and single activity and applied clean Architecture principle, and wrote a unit test, and added some online session fetchers this helped the company to increase his users from 50k to 200k. • Reduced the application vulnerability by 95% in the first year of service and maintained a steady decrease from year to year. • I improved the app security from non-security to adding NDK to the security base URL and SDK keys and PRO-GURAD to Shrink, obfuscate, and optimize app size, and converted icons and images from PNG to WEBP. • I improve app performance and navigation between fragments. • Test the app and find security issues and penetration test bugs and fix it. • I used MVVM architecture patterns with a single channel to develop the application. • I implemented RxJava to use observable sequences to perform asynchronous and event-based programming. • I developed a chat module using Pusher . • I integrated with many SDKs like: Zoom, Moengage, Mixpanel, and Firebase. • I am monitoring and supporting Mid and Junior developers and reviewing their code and telling them how to fix and improve.

S
Jan 2021 - Apr 2023 Senior Application Security Engineer
Orcas

• Developed Detection modiolus • Mitigated OWASP top 10 vulnerabilities and applied secure SDLC practices. • Conducted penetration testing and fixed security bugs such as Sensitive Data Leaked in the Application’s Memory and SSL-Pinning Bypass • Enhanced app security by implementing NDK to the security base URL and SDK keys, as well as utilizing PRO-GURAD for app size optimization.

S
Apr 2023 - Nov 2023 Senior Application Security Engineer
Dsquares

Dsquares is the leading B2B loyalty and rewards solutions provider, working with Fortune 500 companies, multinational corporations, and global giants. And millions of people use his loyalty programs. • I worked on AlexPoint app this app is the loyalty program for alexBank and improve his security layer and performance. • I worked on Vat app this app is the loyalty program for Egyptian Ministry of Finance and improve his security layer. • I worked on Android Sdk to integrate with ExxonMobil app and create his security layer. • I worked on Gamification sdk in both framework android and ios to integrate easily with a lot of companies. • I worked in All of this projects on security issues and penetration test bugs and fix it like : Biometric Authentication Bypass , Sensitive Data Leaked in Application’s Memory , SSL-Pinning Bypass , Root Detection Bypass , Side-Channel Information Leakage , Lack of Anti-Tampering and Runtime Integrity Detection . • I am monitoring and supporting Mid and Junior developers and reviewing their code and telling them how to fix and improve.

S
Dec 2023 - Present Senior Application Security Engineer
AAIB - Arab African International Bank

Arab African International Bank (AAIB) is Egypt’s first Arab multinational bank, offering innovative banking services across the MENA region, with a strong presence in Egypt, UAE, and Lebanon. • I am working on improving the application security and close the vulnerabilities . • Integrate the SDLC cycle in the pipeline. • Install and integrate the SAST, SCA, IAST, and DAST. • Collaborate with the development team to fix the code scan and SCA scan vulnerabilities. • Collaborate with the penetration test team in Web and Mobile pentest. • Set security controls for the applications. • Lead the application security team.


Awards

M
October 2018 Mobile application development
Mobile application development from RUSSIAN CULTURE CENTER in Egypt