~$ whoami

Naqib Fitri

Security Engineer ·

Security Engineer at Mesiniaga Berhad, focused on VAPT & penetration testing, endpoint security (EDR/EDLP) and security automation. Previously a SIEM Engineer intern at Bank Negara Malaysia. CEH · CompTIA Security+ · (ISC)² CC.

naqib@fitri: ~/security
~$ cat profile.txt
role: Security Engineer @ Mesiniaga
focus: VAPT · Endpoint Security · Automation
prev: SIEM Engineer @ Bank Negara Malaysia
certs: [CEH, Security+, CC]
degree: BCompSc (InfoSec & Assurance), USIM
~$ ./run_assessment.sh --target life
[+] Offensive + defensive mindset ...... FOUND
[+] CTF finals & podiums ............... 14+
[+] Talks & workshops delivered ........ 13+
~$
01.

About Me

I'm a Security Engineer at Mesiniaga Berhad. My work centres on VAPT and penetration testing of internal web applications and company products, endpoint security across EDR and Endpoint DLP, and building security automation — including an AI-assisted phishing simulation platform that won 1st place in the company's innovation competition.

Earlier I interned as a SIEM Engineer at Bank Negara Malaysia, working on log-source onboarding, detection rules and threat-intelligence automation.

I hold a Bachelor of Computer Science (Hons.) in Information Security and Assurance from USIM (CGPA 3.64) as a JPA Scholarship (PIDN) holder and Dean's List awardee. Outside work I compete in CTFs and run cybersecurity awareness talks and workshops.

0Certifications
0+CTF Finals & Podiums
0+Talks & Workshops
0Innovation Award
Muhammad Naqib Fitri
Security Engineer

Offensive Security

Web App VAPTPenetration TestingBurp SuiteNessusOWASP ZAP

Endpoint & Detection

EDREndpoint DLPTrend Micro XDRResponse Playbooks

Security Automation

PythonPowerShellAI / LLM ToolingPhishing Simulation

Governance & Ops

ISO 27001Data ClassificationCloudflareVPN / Network
02.

Experience

Dec 2025 — Present Current

Security Engineer

Mesiniaga Berhad

  • Lead VAPT and penetration testing on internal web applications and company products, with remediation tracking and risk validation.
  • Designed and built an AI-assisted phishing simulation platform that automates awareness campaigns end-to-end — awarded 1st place in the company's innovation competition.
  • Built custom AI agents and tooling (on MCP servers) for daily security operations — alert monitoring, CVE and security-news reporting, and streamlining AD and security-tooling tasks.
  • Monitor, triage and investigate alerts across EDR and Endpoint DLP (EDLP), with malware/file analysis to confirm true vs. false positives.
  • Author custom EDR policies for access control and application whitelisting; deploy EDR agents on critical servers and handle device housekeeping.
  • Drive ISO 27001-aligned security policies across assets and staff, including data classification and EDLP improvements.
VAPTEDR / EDLPPhishing SimulationAI / LLMISO 27001
Feb 2025 — Aug 2025

SIEM Engineer — Internship

Bank Negara Malaysia

  • Contributed to a SIEM integration project improving server log-source onboarding, building a custom script to automate the process and reporting, alongside threat-intelligence tasks.
  • Created detection rules, onboarded new device log sources and fine-tuned alarms to improve alert accuracy.
  • Supported SIEM performance tuning and troubleshooting of common server issues.
  • Gained hands-on experience with Network Detection & Response (NDR) tooling.
SIEMThreat IntelAutomationNDR
2025 · 5 months

Cybersecurity Trainer — CTF Workshops

Pusat Sebaran Maklumat Nasional (NADI) × Bahtera Digital

  • Trained participants in CTF fundamentals over a five-month workshop series, and created challenges for the NADI × Cybersecurity Grand Final CTF.
CTFTrainingChallenge Design
2021 — 2025

BCompSc (Hons.) Information Security & Assurance

Universiti Sains Islam Malaysia (USIM)

  • CGPA 3.64 / 4.00 · JPA Scholarship (PIDN) holder · Dean's List (4th & 6th semesters).
  • Foundation in Science and Technology, USIM (2020 — 2021).
InfoSecJPA ScholarDean's List
03.

Certifications

CompTIA Security+

2025

Global benchmark for core security skills — network security, threats, cryptography and operations.

Certified Ethical Hacker

2024

EC-Council CEH — offensive security methodology, exploitation techniques and countermeasures.

Certified in Cybersecurity

2023

(ISC)² CC — security principles, incident response, access controls and network security.

04.

Featured Projects

Security Assessments // authorized engagements

Pentest

PCI-DSS Payment Gateway & EDC Pentest

Authorized pentest of a payment gateway and EDC API integration for PCI-DSS compliance. Found critical time-based blind SQLi, IDOR, reflected XSS and session weaknesses; delivered technical + executive reports with a full remediation roadmap.

Burp SuiteSQLiIDORPCI-DSS
Vulnerability Assessment

External Web App Vulnerability Assessment

Nessus + OWASP ZAP assessment with manual validation. Confirmed account enumeration via the login endpoint, bypassed an Akamai WAF through direct origin-IP access, and found an email-verification bypass where the token was exposed in the response body.

NessusOWASP ZAPWAF BypassManual Testing
Red Team

Physical Security & Social Engineering Assessment

Authorized physical intrusion and social engineering engagement — bypassed guard checkpoints, tailgated into restricted areas, and ran controlled vishing campaigns. Delivered findings with countermeasures for visitor management and awareness training.

Physical IntrusionVishingTailgatingAwareness
Pentest

Government Web App Penetration Test

Authorized penetration test on a Malaysian government corporate website's authentication system — including admin privilege escalation — against predefined use cases and a security testing checklist.

Auth TestingPrivEscChecklist-driven

Engineering & Lab // build & automate

Automation

AI-Assisted Phishing Simulation Platform

An internal platform that automates phishing awareness campaigns end-to-end — orchestration, user interaction tracking and dynamic content generation — using AI to make simulations more realistic. Built to strengthen staff awareness; awarded 1st place in Mesiniaga's innovation competition.

PythonAI / LLMSecurity AwarenessAutomation
Homelab

Proxmox Home Lab Server

Self-hosted lab on Proxmox with LXC containers running a media server, private cloud and a forensic lab. Exposed securely via Cloudflare Tunnel on a registered domain, with Tailscale VPN for remote access.

ProxmoxCloudflare TunnelTailscaleLXC
Threat Intel

IoC Threat Intelligence Dashboard

Python collectors fetching the latest global and Malaysia-focused Indicators of Compromise — hashes, URLs, domains and IP addresses — visualized in a custom Flask web dashboard.

PythonFlaskOSINT FeedsAPIs
Detection

Custom Intrusion Detection System

Python IDS detecting malicious traffic — port scans and DDoS patterns — via packet flag analysis, with real-time alerts pushed to Telegram and email via webhooks.

PythonScapyWebhooksTelegram API
06.

Get In Touch

~$ ./connect --via linkedin

I'm open to security engineering roles, VAPT engagements and cybersecurity speaking / training. Have a project, a scope, or just want to talk security? Reach me on LinkedIn.

Connect on LinkedIn
LinkedIn in/naqib-fitri GitHub DarkKancil