Open to software & security roles

Hello, I'm

Abdelrahman Swidan

I build apps. I break APKs. I read Binder traces for fun. The stack runs from kernel to UI — I've touched all of it.

Egypt
12
Projects
#43
Hextree rank
6+
Vulns reported
4
Domains
swidan@portfolio: ~

swidan@portfolio:~$

01about

Engineer across the full stack

Software engineer working across mobile, backend, and offensive security. I ship production software on Android, web, and Windows desktop, design REST APIs in ASP.NET Core and Go, and reverse-engineer Android apps to find real vulnerabilities. I care about systems that hold up in production — maintainable code, sound architecture, and security that's designed in, not bolted on.

I've built RESTful backends in Go and ASP.NET Core, designed dual-database snapshot architectures, and automated release pipelines that cut manual effort. On the security side, I hold a DEPI certification in Vulnerability Analysis & Penetration Testing, have reported triaged findings on HackerOne, and ranked Top #43 on Hextree's Google-sponsored Android security platform.

Most engineers stop at the API. I go deeper — framework, runtime, kernel. Understanding the machine is how I master it.

🎓 BSc in Computer & Informatics — Information Systems📍 Egypt

Cross-platform delivery

Production apps shipped to real users on Android, web, and Windows desktop.

Backend & data

REST APIs in ASP.NET Core and Go, backed by SQL Server, PostgreSQL, Redis, and MongoDB.

Offensive security

Android pen testing and reverse engineering, OWASP MASVS, HackerOne findings, Hextree Top #43.

Engineering rigor

Clean Architecture, CI/CD pipelines, auditing systems, and security designed in from the start.

02experience

Professional journey

Engineering and security work across product teams, freelance clients, and independent research.

Software Engineer

Feb 2025 – Feb 2026

Future of Egypt · Cairo, Egypt

Led Flutter-based web development inside the organization's digital transformation, turning operational workflows into production software.

  • Delivered and maintained internal web-system features as part of a digital-transformation effort
  • Designed and implemented a full auditing system for user-activity tracking and compliance
  • Translated cross-functional requirements into workflow-driven features
  • Refactored legacy code for maintainability and debugged issues across development and production
  • Monitored and supported systems to keep them stable and available

Freelance Software Engineer

2025

Syanatuk — Appliance Maintenance Center · Remote

Architected and shipped a Windows desktop ERP that digitized a maintenance business end to end.

  • Built complete device lifecycle management: reception, diagnosis, repair, delivery
  • Designed warehouse and spare-parts modules with real-time stock tracking
  • Implemented invoicing, revenue reporting, and debt tracking
  • Applied role-based access control across four staff roles
  • Integrated encrypted Backblaze B2 backups for disaster recovery
  • Built a CI/CD pipeline with automated builds, code signing, and installer generation

Freelance Flutter Developer

2024

El Mohamady Educational Platform · Remote

Built a cross-platform e-learning platform used by teachers and students for daily academic work.

  • Developed the app with Flutter and Firebase
  • Implemented secure authentication, real-time updates, and an online exam system
  • Integrated the YouTube API for lesson content delivery
  • Applied Clean Architecture and MVVM for long-term maintainability

Vulnerability Analysis & Penetration Testing

Jul 2024 – Nov 2024

Digital Egypt Pioneers Initiative (DEPI) · Egypt

Completed a government-backed program focused on real-world penetration testing of web and Android applications.

  • Completed PortSwigger Web Security Academy paths (auth, access control, API security)
  • Performed Android penetration testing against common mobile attack surfaces
  • Ran a full OWASP MASVS compliance assessment on an open-source Android app as the capstone
  • Discovered and documented 6+ real vulnerabilities including IDOR, OTP leakage, and Firebase misconfiguration
  • Delivered a formal security report with evidence and remediation guidance

Bug Bounty & Security Research

2024 – Present

HackerOne · Hextree · Remote

Independently researched Android applications, reported real-world findings through HackerOne, and sharpened offensive skills through challenges.

  • Triaged CSRF bypass on Bykea: reverse-engineered the APK, extracted a cryptographic key, and forged valid tokens
  • Reported a hardcoded Mapbox secret API key in the Inspectorio production APK
  • Ranked Top #43 on Hextree, a Google-sponsored Android security platform
  • Applied static analysis (JADX, Apktool), dynamic instrumentation (Frida), and traffic interception (Burp Suite)
03work

Selected projects

From shipped products to security assessments. Each opens a full case study.

04tech radar

Tools I reach for

Grouped by how often I actually use them in production — not arbitrary percentages.

AdoptDaily drivers — reach for these firstProficientComfortable in productionFamiliarWorking knowledge, used on real projects

Mobile Engineering

FlutterDartClean ArchitectureMVVMBLoC / Cubit / ProviderOffline-first & SyncFirebaseKotlin

Backend Engineering

C# / ASP.NET CoreEntity Framework CoreREST API DesignGo / GinHangfireJWT / RBACGemini AI Integration

Data & Infrastructure

SQL ServerPostgreSQLRedisMongoDBDocker / ComposeCI/CD PipelinesLinuxBackblaze B2

Offensive Security

OWASP MASVS / Mobile Top 10Android Pen TestingFridaBurp SuiteJADX / ApktoolMobSFReverse EngineeringWeb Security (PortSwigger)
05recognition

Achievements & certifications

Triaged

HackerOne — CSRF Bypass

Triaged · Bykea

Found an SMS-exhaustion and CSRF-protection bypass: reverse-engineered the APK, extracted a hardcoded cryptographic key, and forged valid CSRF tokens enabling mass SMS abuse against arbitrary users.

Reported

HackerOne — API Key Disclosure

Reported · Inspectorio

Identified a hardcoded Mapbox secret key (sk.*) inside a production Android APK's strings.xml, exploitable for unauthorized geolocation queries and quota abuse.

Certified

DEPI Certification

Vulnerability Analysis & Penetration Testing

Digital Egypt Pioneers Initiative — a government-backed program covering web and Android penetration testing, PortSwigger Academy labs, and OWASP compliance assessments.

06contact

Let's build something that holds up in production.

Open to software engineering and security roles. The fastest way to reach me is email — I read everything.