Hello, I'm

Muhammad Naqib Fitri

Cybersecurity Professional

SOC Analyst • Penetration Tester • CTF Competitor

Dedicated cybersecurity specialist with hands-on experience in Security Operations, Penetration Testing, and Threat Intelligence. Certified Ethical Hacker (CEH) and CompTIA Security+ holder with a passion for securing digital infrastructure.

About Me

I'm a Computer Science graduate specializing in Information Security and Assurance from Universiti Sains Islam Malaysia (USIM) with a CGPA of 3.64. I completed my internship at Bank Negara Malaysia's Security Operations Centre, where I work with SIEM platforms, threat detection, and incident response.

My journey in cybersecurity has been marked by active participation in CTF competitions, public speaking engagements on cybersecurity awareness, and leadership roles in the Information Security and Assurance Club at USIM. I'm passionate about ethical hacking, penetration testing, and contributing to the cybersecurity community.

As a JPA Scholarship (PIDN) holder and former Maybank/Graduan Student Ambassador, I've demonstrated both technical excellence and leadership capabilities. I'm eager to contribute to organizations that prioritize security and innovation.

Red Team Tools

  • Metasploit
  • Burp Suite
  • Nmap/Zmap
  • Social Engineer Toolkit
  • Nessus

Blue Team Tools

  • SIEM (Security Information and Event Management)
  • Wireshark
  • Volatility
  • Autopsy
  • EDR/NDR Solutions

Programming

  • Python
  • PowerShell
  • PHP
  • JavaScript
  • SQL/MySQL

Operating Systems

  • Kali Linux
  • Parrot OS
  • Ubuntu
  • Windows Server

Experience

Feb 2025 – Aug 2025

Security Operations Centre (SOC) Intern

Bank Negara Malaysia

  • Contributed to log source onboarding and parsing on SIEM platform, including integration of new server log sources
  • Monitored and analyzed security logs using SIEM tools to detect potential threats and support incident response
  • Developed PowerShell scripts to automate housekeeping of decommissioned servers and log validation
  • Led special project to create custom scripts for automated retrieval of IoCs from Financial Threat Intelligence Platform
  • Performed on-site installation of SIEM agent collectors and validated log transmission
2022 – 2023

President

Information Security and Assurance Club (ISAC), USIM

  • Introduced hands-on training sessions, workshops, and hackathons enhancing members' technical skills by 90%
  • Organized events contributing to 90% engagement of the cybersecurity community at the university
  • Led team in organizing CTF competitions and cybersecurity awareness programs
2022

Cybersecurity Instructor

GetCTO.asia - Web App Beginner Pentest Workshop

  • Conducted penetration testing methodology training focused on OWASP Top 10 vulnerabilities
  • Demonstrated secure coding practices and vulnerability exploitation using DVWA and PortSwigger
  • Provided hands-on training in web application security assessment

Certifications

CompTIA Security+

2025

Industry-standard certification covering network security, compliance, and operational security

Certified Ethical Hacker (CEH)

2024

Advanced penetration testing and ethical hacking methodologies certification

Certified in Cybersecurity (CC)

2023

ISC² entry-level cybersecurity certification covering security principles

Certified Network Security Practitioner (CNSP)

2024

Network security and infrastructure protection certification

Certified AppSec Practitioner (CAP)

2023

Application security and secure development practices certification

Featured Projects

PCI-DSS Payment Gateway Penetration Test

Conducted authorized penetration testing on payment gateway web application for PCI-DSS compliance. Identified critical vulnerabilities including SQL Injection, IDOR, and XSS. Delivered comprehensive remediation roadmap.

Burp Suite SQL Injection PCI-DSS Web Security

Physical Security & Social Engineering Assessment

Performed social engineering and physical security assessment measuring organizational resilience. Successfully executed controlled entry attempts and documented security weaknesses with comprehensive countermeasures.

Social Engineering Physical Security Risk Assessment

IoC Custom Dashboard

Built custom web dashboard using Flask to visualize Indicators of Compromise (IoCs) worldwide and Malaysia-based. Fetches real-time data on hashes, URLs, domains, and IP addresses from various sources.

Python Flask Threat Intelligence API Integration

Custom Intrusion Detection System (IDS)

Developed Python-based IDS to detect malicious network packets including Nmap scans and DDoS attacks. Integrated with webhooks for real-time alerts via Telegram and Email notifications.

Python Network Security Packet Analysis Webhooks

Real-time Water Level System using IoT

IoT-based project with custom dashboard using ReactJS and NodeJS. Implemented real-time database using API for updating JSON data from Arduino. Features GPS location and map integration.

IoT ReactJS NodeJS Arduino

Bad USB Development

Created custom payload using Digi Spark and Raspberry Pi Pico to act as USB Rubber Ducky. Capable of executing malicious code like backdoor scripts or reverse connections via PowerShell.

Hardware Hacking PowerShell Payload Development

RFID Security

Ethical research into contactless access credentials and RFID/NFC systems, including analysis of commercial access cards. Investigated cloning risks, duplication scenarios, and real-world attack vectors to better understand how credentials are compromised.

RFID / NFC Security Research Hardware

Achievements & Recognition

Black Hat Asia 2024 Scholarship

Selected student from Asia based on contributions to cybersecurity community and outstanding achievements

Microsoft AI Hackathon Champion

First place in Microsoft AI for Accessibility Hackathon 2024

Dean's List Award

Recognized for academic excellence in 4th and 6th semesters

CTF Competition Finalist

Multiple finalist positions in prestigious CTF competitions including UMCTF, Wargames, and ASCIS

Get In Touch

Let's Connect

I'm currently open to new opportunities in cybersecurity, particularly in SOC operations, penetration testing, and red teaming roles. Feel free to reach out if you'd like to discuss potential collaborations or just want to connect!

Available upon request
Kuala Lumpur, Malaysia