Skip to content
View masmi9's full-sized avatar

Block or report masmi9

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
masmi9/README.md

πŸ›‘οΈ Malik Smith

Profile Picture

Application Security Tester @ OnDefend


πŸ‘¨β€πŸ’» About Me

I’m Malik Smith, an Application Security Engineer specializing in application security testing, secure code review, static analysis, mobile and web application security, and DevSecOps automation. I work closely with development teams to identify, validate, and remediate security vulnerabilities throughout the Secure Software Development Lifecycle (SSDLC), helping organizations deliver resilient, secure applications at scale.

My experience spans manual application penetration testing, secure design reviews, custom SAST rule development, vulnerability management, and security automation. I’ve worked with commercial and government organizations, supporting security assessments for modern mobile and web applications while developing automation that streamlines vulnerability detection, validation, and remediation.

I’m passionate about building security into the development process through custom static analysis, CI/CD security integrations, Infrastructure-as-Code (IaC) security, and developer-focused security tooling. Personal projects such as MobileMorphAgent and BluJay reflect my interest in combining offensive security techniques with scalable security engineering solutions that improve efficiency without sacrificing security.

My long-term goal is to become a Principal Vice President and ultimately a Chief Information Security Officer (CISO) by combining deep technical expertise with security leadership, cloud security, AI security, and secure software engineering.


🧠 Skills

Application Security

  • Secure Code Review
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA)
  • Threat Modeling
  • Vulnerability Assessment & Risk Analysis
  • Secure Software Development Lifecycle (SSDLC)

Offensive Security

  • Mobile Application Penetration Testing (Android & iOS)
  • Web Application Penetration Testing
  • API Security Testing
  • OWASP Top 10
  • OWASP API Security Top 10
  • OWASP MASVS & MSTG

Security Engineering & DevSecOps

  • Security Automation
  • Custom Semgrep & CodeQL Rule Development
  • CI/CD Security Integration
  • GitHub Actions
  • Jenkins
  • GitLab CI/CD
  • Infrastructure-as-Code (IaC) Security

Cloud & Platform Security

  • AWS Security Fundamentals
  • Container & Dependency Security
  • Vulnerability Management
  • Secure Configuration Reviews

Tools & Technologies

  • Semgrep
  • CodeQL
  • Coverity
  • Burp Suite Pro
  • MobSF
  • Frida
  • Ghidra
  • JADX
  • OWASP ZAP
  • Docker
  • GitHub
  • GitLab
  • Jenkins

πŸ“œ Certification Roadmap

βœ… Completed Certifications

  • CEH – EC-Council Certified Ethical Hacker v12
  • Foundation Level Cyber Threat Intelligence – arcX
  • Static Analysis & Code Security Specialization – Semgrep, CodeQL, custom rule development, taint tracking, CI/CD integration, and secure code review automation

πŸ”Ή Short-Term Goals (Mid-Late 2026)

  • Q3 2026 PMPA – TCM Security's Practical Mobile Pentest Associate (in progress)
  • Q4 2026 PAPA – TCM Security's Practical AI Pentest Associate (in progress)

Strengthen expertise in application security, secure software development, mobile security, AI security, and DevSecOps to position for Senior Application Security, Product Security, and DevSecOps Security Engineer roles.


πŸ”Ή Mid-Term Goals (2027)

  • Q1 2027 IAPP AIGP - Artificial Intelligence Governance Professional
  • Q2-Q3 2027 CISM – Certified Information Security Manager (ISACA)
  • Q4 2027-Q1 2028 CISSP – Certified Information Systems Security Professional (ISCΒ²)

Combine deep technical expertise with security governance and leadership to prepare for Principal Security Engineer, Security Architect, and technical leadership opportunities.


πŸ“… Educational Milestone (2028+)

  • MS in Cybersecurity Operations - Projected Graduating Class Fall 2028
    • Focus Areas:
      • Security Leadership
      • Goverance & Risk Leadership
      • Cloud & Enterprise Security
      • Cyber Operations
      • Security Program Management

Complements advanced technical certifications with leadership, business, and strategic decision-making skills.


πŸ”Ή Long-Term Goals

*By 2030, develop a well-rounded background spanning:

  • Application Security
  • Product Security
  • DevSecOps
  • Cloud Security
  • AI Security
  • Security Leadership & Governance

Career Goal:

  • Principal Application Security Engineer
  • Security Architect
  • Director of Application Security
  • Chief Information Security Officer (CISO)
  • CEO of my own Tech Consulting/Contracting Firm

🎯 Focus Areas

Domain Certifications
AppSec/DevSecOps & Automation CSSLP, Semgrep, CodeQL, Custom SAST Rules
Mobile App Security PMPA
AI Security PAPA
Cloud Security AWS Certified Security-Specialty
Threat Intelligence arcX CTI Foundation
Leadership & Governance CISM, CISSP
Secure Development CSSLP, CI/CD Security, Threat Modeling
Security Automation Custom SAST Rules, DevSecOps, CI/CD Integration

πŸ“« Contact

Pinned Loading

  1. MobileMorphAgent MobileMorphAgent Public

    A modular Android agent APK for research on OS-level command execution, dynamic code injection, and binary hooking.

    Python 3 1

  2. BluJay BluJay Public

    A high-accuracy, extensible SAST tool designed to analyze Java and Python source code and binaries without execution. It performs automated source code reviews using AST-based and taint-aware analy…

    Python 1 1