SALMAN ABEDIN

Software Engineer | Penetration Tester | CS Graduate
Dhaka, Bangladesh
+880 1859 637967
me@salmanabedin.com
linkedin.com/in/salman-abedin
salmanabedin.com
github.com/salman-abedin
tryhackme.com/p/salman.abedin
Salman Abedin

Profile

Software Engineer with a B.Sc. in Computer Science and 4 years of experience engineering, automating, and optimizing high-reliability banking software and data pipelines. Combines core CS fundamentals with professional security certifications (eCPPTv2, ISC2 CC) and polyglot backend engineering (Go, Rust, Python). Pursuing an M.S. in Computer Science to deepen expertise in advanced systems architecture, software security, and reliable distributed infrastructure.

Experience

Associate Software Engineer | Dynamic Solution Innovators Ltd.
Aug. 2024 – Aug. 2025 | Dhaka, Bangladesh
  • Developed and customized dynamic bank statement templates using ISIS Papyrus and DFA language for commercial banking clients, meeting strict visual and compliance specifications.
  • Built utility scripts to optimize data ingestion and document processing workflows, improving batch execution efficiency and pipeline reliability.
  • Investigated and patched technical defects across live composition applications, ensuring uninterrupted
  • Participated in daily cross-functional agile rituals with US client teams to capture functional requirements, submit technical queries, and refine specifications.
Assistant Application Support Engineer | Dynamic Solution Innovators Ltd.
Aug. 2023 – Aug. 2024 | Dhaka, Bangladesh
  • Acted as the primary escalation point for complex, high-priority production incidents spanning distributed microservices and core statement pipelines.
  • Led deep-dive root cause analysis on critical application failures, working with core development teams to implement long-term stability fixes.
  • Trained, mentored, and onboarded junior and trainee support engineers on system architecture, debugging
  • Standardized triage frameworks and refined technical knowledge base repositories, improving overall team resolution efficiency and onboarding speed.
Junior Application Support Engineer | Dynamic Solution Innovators Ltd.
Aug. 2022 – Aug. 2023 | Dhaka, Bangladesh
  • Managed and resolved tier-2 application incidents across print statement engines and microservices-based eStatement applications under tight client SLAs.
  • Diagnosed recurring application defects and data parsing errors using application logs, database queries, and environment diagnostics.
  • Updated and expanded technical troubleshooting guides, post-mortems, and SOPs to capture solutions for
  • Partnered with software engineering squads to log verified bugs, test emergency patches, and validate hotfixes in staging environments.
Trainee Application Support Engineer | Dynamic Solution Innovators Ltd.
Feb. 2022 – Aug. 2022 | Dhaka, Bangladesh
  • Mastered system architectures across statement composition pipelines and eStatement microservices by reviewing codebases, environment configs, and operational workflows.
  • Handled entry-level support tickets and routine production batch checks under senior guidance, adhering to documented SLA timelines.
  • Performed preliminary log searches and error tracking for application failures, documenting initial
  • Followed established Standard Operating Procedures (SOPs) and knowledge base articles to execute standard system recovery and data fix procedures.
Software Engineer | NEXT Ventures Ltd.
Sep. 2021 – Dec. 2021 | Dhaka, Bangladesh
  • Designed, backtested, and deployed automated trading bots using Python and MQL, implementing real-time trade execution and automated risk controls.
  • Created end-to-end GitHub Actions CI/CD automation to validate code quality and execute zero-downtime deployments to production environments.
  • Administered and configured production VPS environments, setting up monitoring, auto-restart capabilities, and server security for mission-critical trading algorithms.
  • Built internal software tools and automated data pipelines to optimize workflows across research, operations, and trading desks.
Web Developer | YY Ventures Ltd.
Apr. 2021 – Aug. 2021 | Dhaka, Bangladesh
  • Engineered high-performance static websites and web applications utilizing Svelte/Astro, Vue/Nuxt, GraphQL, and various Headless CMS architectures.
  • Communicated directly with local and international clients to capture functional requirements, define
  • Managed ongoing maintenance, performance tuning, and security updates for live WordPress business websites.
  • Actively contributed to daily cross-functional standups, collaborating with UI/UX designers, backend developers, and project managers to streamline project delivery.
Engineering Intern | YY Ventures Ltd.
Jan. 2021 – March. 2021 | Dhaka, Bangladesh
  • Assisted in building modern static websites using Svelte/Astro and Vue/Nuxt integrated with GraphQL APIs and Headless CMS platforms under senior developer guidance.
  • Supported the maintenance of existing client WordPress websites, applying plugin updates, content revisions,
  • Participated in requirement-gathering sessions with local and international clients to document feature requests and site specifications.

Education

B.Sc. in Computer Science (Minor: Business) | BRAC University
2017 – 2022 | Dhaka, Bangladesh
  • CGPA: 2.83 / 4.00.
  • Relevant coursework: Algorithms, Data Structures, Database Systems, Operating Systems, Artificial Intelligence, Automata & Computability, Discrete Mathematics, Data Communications, Digital Logic Design.

Certifications

Certified Professional Penetration Tester (eCPPT v2) | INE Security
Apr. 2024
  • Demonstrated hands-on expertise in network vulnerability assessment, web application security testing (OWASP Top 10), and exploitation across complex Windows and Linux environments. - Exploit Development & Memory Corruption: Developed and modified custom x86 stack-based buffer overflow exploits to achieve remote code execution on target systems.
  • Developed and modified custom x86 stack-based buffer overflow exploits to achieve remote code execution on target systems.
  • Executed advanced pivoting techniques (SSH tunneling, Proxychains, Metasploit routing) to traverse segmented multi-tier internal networks and compromise deep infrastructure.
  • Applied advanced privilege escalation methods on Windows and Linux targets, conducting post-exploitation tasks, credential harvesting, and lateral movement.
  • Authored comprehensive, industry-standard penetration testing reports featuring step-by-step proof-of-concept exploits, risk ratings, and actionable mitigation guidance.
Junior Penetration Tester (eJPT) | INE Security
Sep. 2023
  • Conducted hands-on vulnerability assessments and penetration tests across live Windows and Linux network environments.
  • Performed active and passive information gathering, network mapping, port scanning, and service enumeration using tools like Nmap and Masscan.
  • Identified and exploited system, network, and service-level vulnerabilities to gain initial access using manual techniques and Metasploit.
  • Assessed web applications for common flaws, including SQL injection, directory traversal, broken authentication, and parameter tampering.
  • Executed basic post-exploitation tasks, local privilege escalation checks, credential harvesting, and network routing/pivoting through compromised hosts.
Certified in Cybersecurity (CC) | ISC2
Jul. 2023
  • Thorough understanding of the CIA triad (Confidentiality, Integrity, Availability), security policies, risk management fundamentals, and ISC2 Code of Ethics.
  • Applied knowledge of Identity and Access Management (IAM), multi-factor authentication (MFA), Least Privilege, and access control models (RBAC, DAC, MAC).
  • Grounded in fundamental network security concepts, port/protocol analysis, firewalls, network segmentation, and defensive controls against common cyber threats.
  • Familiar with data classification, system hardening, patch management, privacy standards, and log monitoring practices.
  • Understanding of Incident Response (IR) lifecycles, Business Continuity Plans (BCP), and Disaster Recovery (DR) strategies
Certified Cloud Associate (ICCA) | INE Security
Aug. 2023
  • Gained foundational expertise in designing, deploying, and managing infrastructure across AWS, Microsoft Azure, and Google Cloud Platform (GCP).
  • Applied core cloud security principles, including the Shared Responsibility Model, least-privilege Identity and Access Management (IAM), and multi-cloud compliance frameworks.
  • Administered virtual machines, cloud storage, virtual private networks (VPC/VNet), and container basics across multi-cloud environments.
  • Demonstrated practical proficiency through hands-on cloud labs covering resource provisioning, security group configuration, and cloud asset monitoring.

Technical Skills

Communication Skills