Mohammed Al-Faleh is a Riyadh-based penetration tester with 5 industry certifications and a verified track record of discovering critical vulnerabilities in production systems at global companies. Available for web application, network, API, and cloud security engagements.
I wasn't always a pentester. I started in enterprise IT support at a Saudi company — fixing systems and wondering how they'd actually been broken. That curiosity pulled me into offensive security, and it's still what drives me every day.
Today I hold five professional certifications — including CPTS and eWPTXv2 — and I'm completing my Computer Science degree while staying active in bug bounty programs. I've found critical, real-world vulnerabilities in production systems at global companies, and I've been trusted with enterprise clients in Riyadh.
The day you stop learning in this field is the day you start falling behind — so this is a full-time commitment, not a side project. I write reports for humans, not just developers: every finding includes business impact, reproduction steps, and fixes your team can actually apply. And I work with clients in Arabic and English.
Structured security assessments delivered with clear, actionable reports. Every engagement includes a retest to confirm your fixes are effective.
✦ Introductory rates currently available.
Testing aligned with OWASP Top 10:2025, NIST SP 800-115, and mapped to the SAMA Cyber Security Framework and NCA Essential Cybersecurity Controls (ECC) compliance expectations — ideal for regulated Saudi enterprises.
Manual testing of your web applications for OWASP Top 10 vulnerabilities — IDOR, XSS, authentication bypass, business logic flaws, and more. Includes full PoC documentation.
Internal and external network assessments targeting misconfigurations, weak credentials, lateral movement paths, and privilege escalation opportunities across your infrastructure.
Manual review of cloud environments (AWS, Azure) for misconfigurations — exposed S3 buckets, overpermissioned roles, insecure storage, and weak access controls before attackers find them first.
Systematic scanning and manual review of your environment to identify, classify, and prioritize security weaknesses — ideal as a first step before a full pentest engagement.
Deep testing of REST and GraphQL APIs for BOLA/IDOR, broken authentication, excessive data exposure, and mass assignment — including business logic abuse specific to your API design.
After your team addresses findings from a pentest, I retest every vulnerability to confirm the fix is effective and no new issues were introduced in the process.
A clear, low-friction process from the first conversation to a confirmed fix. You always know what happens next — and what it costs.
A 30-minute call to understand your environment, goals, and anything off-limits. You get a fixed quote and timeline before any work begins.
Targeted manual and structured testing against the agreed scope, with progress updates along the way — never a silent black box.
A clear report ranked by business risk, with reproduction steps, proof-of-concept evidence, and practical fix guidance your team can act on.
After your team applies fixes, I retest every finding to confirm it is resolved — and confirm no regressions were introduced.
Every engagement starts with a free, no-obligation scoping call.
Book Your Free Scoping CallReal vulnerabilities discovered and responsibly disclosed in production systems at global companies through bug bounty programs.
Third-party-owned apex bucket served via CloudFront on an HSTS domain, allowing full control over served assets. Followed by a world-writable S3 origin leading to stored XSS via JavaScript chunk injection.
Missing ownership checks on P2P offer endpoint exposed bank and payment details of 81 distinct users across 118 offers. No authentication bypass required — a structural authorization failure.
JWT-embedded country code claim not re-validated per request, allowing financial withdrawal API to be reached from any egress IP, bypassing country-level financial controls entirely.
Missing re-authentication on email, password, and 2FA change endpoints enabled complete account takeover from a single valid session. Step-up controls existed on other endpoints, confirming deliberate misapplication.
Non-merchant users at LEVEL_0 could mint valid merchant API keys accepted by production merchant endpoints, effectively granting unauthorized merchant-tier access.
Three critical vulnerabilities identified including OTP hijacking, JSON manipulation exploit, and email flooding attack vector. Recognized for responsible disclosure by flynas security team.
Hands-on, practical certifications from recognized offensive security bodies — not just theoretical knowledge.
Build a quick estimate based on the type and size of assessment you need. The final quote is confirmed after reviewing your scope.
Estimated timeline: 4–7 days
Final pricing depends on scope, access requirements, and testing complexity.
Request Exact QuoteStraight answers to the questions clients ask most before starting an engagement.
Tell me about your environment and what you need tested. I'll respond within 24 hours with a clear scope, timeline, and pricing.