> whoami

Mikhail Nabiullin

> _

Offensive security specialist turned AppSec engineer. 10+ years breaking and defending systems across military, fintech, and enterprise environments.

10+
years in
security
80+
pentest
engagements
30+
high-impact
vulns (synack)
#1
portswigger
hall of fame
scroll

From Military Defense
to Offensive Security

Started in military cyber defense — SIEM, IDS/IPS, firewalls for the Ministry of Defense of Kazakhstan. Transitioned into offensive security and application security engineering.

Led secure SDLC programs at Exness, managed bug bounty operations, reviewed millions of lines of code across Python, Go, and Java. Currently conducting adversarial research on bot detection systems at Bright Data.

location Italy
education Mozhaisky Military-Space Academy
languages Russian / English / Italian
focus Web AppSec & Research

Career Timeline

2025 — now active

Bright Data

Data Security Researcher

Bot Detection Adversarial Research
2021 — now active

Synack Red Team

Red Team Researcher

Web & Network Pentesting 30+ High-Impact Vulns
2021 — 2025

Exness

Senior Application Security Engineer

SSDLC Bug Bounty Code Review WAF ASPM Developer Training
2018 — 2021

Digital Security

Penetration Tester

30+ Projects Web / Mobile / Desktop Code Review
2016 — 2018

Ministry of Defense of Kazakhstan

Senior Network Security Officer

SIEM / IDS / IPS Incident Response Firewalls

Technical Arsenal

Offensive Security

  • Web App Pentesting
  • API Security Testing
  • Mobile & Desktop
  • Network Pentesting
  • White-Box Testing
  • Red Teaming

AppSec Engineering

  • Secure Code Review
  • SSDLC Integration
  • ASPM Development
  • Bug Bounty Management
  • Threat Modeling
  • Security Design Review

Certifications & Recognition

Let's Connect

Looking for an experienced security professional?
Consulting, research, or penetration testing.