root@security:~# whoami
Hashemi Rafsanjani
Cybersecurity Researcher·OSINT Practitioner·Threat Analyst·Bug Bounty Hunter·Software Research Engineer
@hashemi.official@gmail.com #+62 856-3901-995 >Kendal, Central Java, ID inlinkedin.com/in/hashemirafsanjani ghgithub.com/aloc999 glgitlab.com/aloc999 ~Indonesian · English
Hashemi Rafsanjani
// Professional Summary

Software Research Engineer, Cybersecurity Researcher, and Bug Bounty Hunter (Intigriti, Bugcrowd) with hands-on experience in banking IT Security Operations — 24/7 SOC monitoring, threat hunting, and cyber threat intelligence. Builds open-source offensive tooling (redgun, Xploit47, ZER0CODE, CODA) spanning web/API, cloud, Web3, mobile, and AI/LLM security. Engineers detection-as-code across Splunk, Sentinel, and Chronicle (Sigma, KQL, SPL, YARA), zero-trust DevSecOps platforms, multi-framework SDET automation with sub-30-minute regression gates, and production Next.js/Prisma/PostgreSQL SaaS. Blends Red Team depth with Blue Team rigor — penetration testing, DFIR, and security monitoring — delivering intelligence-led findings with clear business impact.

// Core Competencies
$ security_ops | defense
SIEM / SOAR Threat Hunting DFIR Threat Intelligence MITRE ATT&CK IDS / IPS EDR / XDR Network Analysis Incident Response
$ offensive_security | research
Bug Bounty Penetration Testing Red Teaming Web / API Security Burp Suite OWASP Top 10 Active Directory Cloud Red Team Phishing Ops OSINT / Dark Web Mobile Security AppSec / SAST
$ ai_llm | web3 | specialized
AI / LLM Security Prompt Injection AI Red Teaming MCP / AI Agents Web3 / Smart Contracts Smart Contract Audit Attack Path Planning Security Tooling
$ qa_sdet | detection | devsecops
QA Automation Playwright Selenium Appium k6 / Locust Pact / Contract Testing Sigma KQL / SPL YARA / YARA-L SOAR Playbooks Jenkins / CI-CD SonarQube Docker Terraform / Ansible SBOM / Supply Chain
$ engineering_stack
Python PHP TypeScript / JS Node.js Express React Next.js Tailwind CSS Prisma PostgreSQL RESTful API API Integration Git GitLab CI Docker SQL / KQL Shell / CLI Linux & Windows HTML / CSS Java C++ / C# ASP.NET FFmpeg WebRTC Secure SDLC ISO 27001 / 27701 / 42001
// Work Experience
Security Researcher
Aug 2025 — Present
Intigriti (Bug Bounty Platform)
  • Perform web application and API penetration testing across live bug bounty programs — recon, vulnerability identification, and exploit validation with proof-of-concept evidence.
  • Validate severity and business impact for each finding; report with clear remediation guidance for program owners.
  • Follow responsible disclosure practices, delivering reproducible technical reports within program SLAs.
Security Researcher
Aug 2025 — Present
Bugcrowd (Bug Bounty Platform)
  • Run continuous vulnerability research across diverse targets — attack-surface mapping, recon automation, and manual validation to filter false positives.
  • Assess authentication flows, application logic, and endpoint exposure; report confirmed findings with impact assessment.
  • Triage and retest: verify fixes on previously reported vulnerabilities and track program scope changes for new attack surface.
IT Security Operations
Feb 2021 — Dec 2025
PT Bank Syariah Indonesia Tbk
  • Triaged ~50 security alerts per shift in a 24/7 SOC; tuned false positives and escalated confirmed incidents with severity classification.
  • Produced daily shift-handover reports and weekly cyber threat intelligence summaries for SOC leadership, mapping observed activity to MITRE ATT&CK.
  • Operated Splunk and Microsoft Sentinel SIEM alongside Defender EDR for detection triage; enriched investigations with VirusTotal, AbuseIPDB, and MISP.
  • Performed penetration testing for security hardening; analyzed malware and phishing emails end-to-end — header forensics, URL/attachment detonation, IOC extraction and blocking, and credential-reset coordination.
  • Administered cloud security, IDS/IPS, and firewall issues; patch recommendations and system updates.
  • Conducted OSINT investigations with structured collection methodology and dark-web monitoring under OpSec discipline using sock-puppet accounts.
  • Researched emerging attack vectors and kill-chain patterns; collaborated across departments on remediation.
Operational, Inventory and IT Support Staff
Jan 2020 — Feb 2021
PT Bank BNI Syariah
  • Maintained financing contracts (mortgage, multipurpose, SME) with data-quality and documentation controls.
  • Managed inventory / warehouse systems and warehouse administration (stock recording, goods movement, and warehouse operational documentation).
  • Operated branch server infrastructure including routing and intranet broadband.
  • Coordinated with public notaries for financing guarantees; reporting to financial authorities.
  • IT support ticketing and operational resolution across branch systems.
IT Support Assistant
Jan 2017 — Dec 2019
PT Bank Negara Indonesia (Persero) Tbk
  • Hands-on experience with network, hardware, and software (installation, configuration, troubleshooting, and maintenance).
  • Desktop, network, and Microsoft 365 troubleshooting; software network-traffic analysis.
  • Helpdesk administration: complaint handling, ticket lifecycle, and remediation reporting.
  • Cloud and firewall issue resolution; system health checks and software patch updates.
  • Cross-department coordination for incident and request fulfillment.
// Portfolio
Security Research Portfolio · github.com/aloc999
Open security research and methodology: Bug-Hunting-Methodology (36 vuln classes, payloads, bypasses), PENTESTING-TECHNIQUES (web · network · AD · cloud path), and ExploitNinja (147 pentest skills — bug bounty, web3, mobile, cloud, OSINT, AI/LLM security). Methodology that directly feeds bug bounty hunting and penetration testing.
Software Engineering Portfolio · github.com/aloc999 · gitlab.com/aloc999
Security engineering products: redgun (CLI web auditor — black/white-box, ~120 modules, AI attack chains), Xploit47 (AI-powered pentest reasoning MCP — Beam Search + MCTS attack-path planning), ZER0CODE (AI red-team coding agent for offensive workflows), and CODA (smart-contract audit arsenal — 26 tools, static analysis to formal verification). Full-stack depth proven by the production SaaS below.
QA / SDET Engineering — QARonin · github.com/aloc999/QARonin
SDET automation monorepo — RoninShop system-under-test exercised by Playwright-TS/C#, Cypress, Selenium 4, Appium 2, Karate, Behave, pytest API + Postman/Newman; Pact contracts, agentic AI self-healing locators, k6/Locust/JMeter SLOs, SQL validation, and a sub-30-minute 4-shard regression gate (GitHub Actions + GitLab CI mirror).
Detection Engineering (Blue Team) · github.com/aloc999/DetectionEngineeringPortfolio
Enterprise detection-as-code across Splunk / Sentinel / Chronicle: Sigma, KQL, SPL, YARA-L/YARA rules mapped to MITRE ATT&CK (endpoint, cloud, container, identity, network), LLM CTI→hunt pipeline, SOAR phishing-response playbooks, and pytest + CI validation.
DevSecOps & Platform Engineering · github.com/aloc999/DevSecOpsPortfolio
Zero-trust DevSecOps platform: Jenkins CI/CD, SonarQube quality gates, JFrog Xray + Snyk SCA, Docker supply-chain (SBOM/Cosign), Terraform + Ansible IaC, and SAST/DAST/secrets/IaC automation with CIS/NIST/PCI compliance mapping.
Full-Stack SaaS — TicketMind · Snaplink · Invoicely · ticketmind · snaplink · invoicely
Production Next.js 15 + Prisma + PostgreSQL SaaS trio: TicketMind (AI support desk — RBAC, auto-classification, draft replies, analytics), Snaplink (URL shortener — REST API, click analytics dashboards), Invoicely (multi-tenant invoicing — org-scoped data, plan limits, printable docs).
// Education
Bachelor — Economics and Business, Accounting Information Systems
Aug 2012 — Aug 2016
Universitas Dian Nuswantoro
// Courses & Certifications
[ red_team · offensive_security ]
Certified Red Team Specialist (CRTS)
CyberWarfare Labs · Lateral movement, AD, adversary simulation, CI/CD
Apr 2026
Certified Offensive Phishing Operator
CyberWarfare Labs · BiTB, device-code phishing, illicit consent, MFA
Apr 2026
Multi-Cloud Red Team Analyst
CyberWarfare Labs · AWS · GCP · Azure misconfigurations
Mar 2026
Web Red Team Analyst
CyberWarfare Labs · Modern web vulnerability assessment
Mar 2026
Cybernetics Pro Labs
Hack The Box · AD, phishing, lateral movement, privilege escalation
Jan 2026
Certified Red Team Analyst (CRTA)
CyberWarfare Labs · AD pentest, network/Windows, adversary sim
Dec 2025
Certified API Red Team Analyst
CyberWarfare Labs · WebApp, API, AWS CloudNative security
Dec 2025
Certified Associate Penetration Tester
Hackviser · AD, VAPT, AppSec, network security
Dec 2025
Certified Red Team Operations Management
Red Team Leaders · Red Team security operations management
Dec 2025
[ blue_team · cti · dfir · osint ]
CSI Linux Certified Investigator Academy
CSI Linux · Real threat intelligence investigations
Jan 2026
Certified Threat Intelligence & Governance Analyst
Red Team Leaders · CTI on case scenarios
Jan 2026
Certificate of Competence — Chinese OSINT
Hacktoria · China-focused OSINT investigations
Jan 2026
DFIR Foundations & Techniques
Blue Cape Security · SIEM/SOAR, Splunk, Autopsy, Win forensics
Jan 2026
Hands-On KQL for Security Analysis
Blu Raven Academy · KQL-based security analysis
Jan 2026
ICS CyberSecurity Vulnerabilities (21OW-07)
U.S. Department of Homeland Security · ICS vulnerabilities
Jan 2026
Operation Gambler OSINT CTF
UK OSINT Community · Real-world OSINT investigations
Jan 2026
Cyber Threat Intelligence Analyst
arcX · CTI and APT threat analysis
Dec 2025
Blue Team Junior Analyst
Security Blue Team · OSINT, DFIR, dark web, threat hunting
Dec 2025
Advanced OSINT Mastery
Red Team Leaders · SOCMINT, GEOINT, dark web, OPSEC
Mar 2026
Maltego for Cybercrime
Maltego · Detecting & tracking criminal activity
2026
[ governance · ai · privacy · foundations ]
ISO/IEC 42001:2023 Lead Auditor
AI Management System (AIMS) · Conformity & non-conformity auditing
Jul 2026
ISO/IEC 27701:2025 Lead Auditor
Privacy Information Management System (PIMS) · Audit capability
Jul 2026
ISO/IEC 27001:2022 Lead Auditor
MasterMind Assurance · ISMS conformity & non-conformity auditing
Dec 2025
CSCSO Certification
ICTTF · SME cyber risk, NIST, DORA, GDPR
Dec 2025
CRPO Certification
ICTTF · Ransomware protection framework
Dec 2025
Google Cybersecurity Professional Certificate
Google · Python, Linux, SQL, SIEM, IDS/IPS, EDR/XDR
Dec 2025
APU PPT — AML & Counter-Terrorism Financing
LPPI Indonesia · AML / CFT regime
Oct 2022
Lean Six Sigma White Belt
The Council for Six Sigma Certification
Dec 2025
// Hobbies
Reading · Coding · Basketball · Football · Coffee · Music
Offline mode — CV cached