Offensive Security Consultant

BERK.

~$ 

Istanbul, Turkey X-Force Red ATT&CKcon 6.0 Speaker
Scroll

01 / About

Red team by trade,
engineer by nature.

Offensive security consultant specialising in web application, API, mobile, and network penetration testing. Operating with one of the most respected offensive security teams in the industry, conducting adversarial assessments against enterprise clients across aviation, energy, and financial sectors.

Holder of both a Bachelor's and Master's degree in Computer Engineering from Bahçeşehir University, Istanbul. Former cybersecurity working student at Siemens, with hands-on exposure to IEC 62443, OT/ICS environments, and product security frameworks.

Speaker at MITRE ATT&CKcon 6.0. Fluent in Turkish and English. Outside of offensive work: distance runner, occasional trekker on the Lycian Way, and amateur astronomer.

MSc
Computer Engineering
4+
Attack Surfaces
IST
Istanbul, Turkey
EN/TR
Languages

02 / Expertise

Attack surfaces covered.

01
Web Application

OWASP Top 10, business logic abuse, authentication bypasses, injection chains, and complex multi-step vulnerabilities.

OWASP Burp Suite SQLi SSRF
02
API Security

REST & GraphQL assessments, JWT validation flaws, IDOR chains, mass assignment, and payment flow abuse.

REST GraphQL JWT IDOR
03
Mobile

iOS & Android reverse engineering, runtime manipulation, certificate pinning bypass, and insecure data storage analysis.

Android iOS Frida MobSF
04
Network & AD

Internal infrastructure assessments, Active Directory exploitation, lateral movement, and ADCS abuse chains.

AD BloodHound Kerberos ADCS

03 / Speaking

Conference appearances.

2025
MITRE ATT&CKcon 6.0
Speaker — McLean, Virginia, USA

Let's talk red.