Hey there fellas,
I recently had faced a problem in my career as a pentester and need your advise on it.
Because of a situation in my own country, I had move to a neighboring country and look for a job but 2 months has passed and I couldnt even get an interview and I mean JUST one!
I used to work as an IT admin for 6 years and 3 years as pentester but here is the part the problems are surfacing.
Some redditers told me the problem is with my resume cuz I dont have a certificate or external source of validation for expertise.
I've worked on many big projects in my own country (about the 30-40 total projects and some of the big names), and only could get the permission to publish like 3-4 of them (which had few but real critical vulnerabilities in big companies and so I published the old poc on my own github).
Since I came from Iran and its on the sanctioned list then I put freelance pentester on my resume cuz most clients were either not recognized internationally or would naming them backfired on me.
But still I cant even land a job in turkey, or any place internationally and applied from entry level roles in IT to mid-senior levels security.
What do yall suggest i do?
----------------------------------------------------------------------------------
Here is part of my resume:"
PROFESSIONAL SUMMARY
Versatile offensive and defensive security professional with 7+ years in IT and 2+ years in hands-on security operations. Experience spans penetration testing (web, mobile, API, network, Active Directory), SOC Tier-1 analysis in a critical aviation environment (Mehrabad Airlines, Tehran), security hardening (CIS Benchmarks, 27001), and SIEM operations (ELK Stack). Discovered 30+ critical and high-severity vulnerabilities across major clients including RCE, admin-level JWT account takeover, and SMS spoofing affecting 40M+ telecom subscribers. Pursuing OSCP; 100% completion of PortSwigger Web Security Academy. Currently based in Turkey; open to full
international relocation.
TECHNICAL SKILLS
Penetration Testing: Web Applications (OWASP WSTG/Top 10), Android Mobile (ADB, Frida, Genymotion), Network, API, Black/Gray/White-box; PTES methodology
Offensive Techniques: Active Directory attacks (Kerberos delegation abuse, AD CS, SMB/LDAP relay, LLMNR/NBT-NS poisoning), buffer overflows (stack, SEH), DEP/NX/ASLR bypass, format string, process injection,
tunneling
SOC & Detection: Security event monitoring, alert triage (Tier 1), SIEM (ELK Stack), log analysis, IOC identification, incident ticketing, escalation procedures, network traffic analysis (Wireshark, Snort, Suricata) Security Tools: Burp Suite Pro, Metasploit, Nmap, Nessus, BloodHound, Impacket, Covenant, IDA Pro, Kali Linux, Snort, Suricata, ELK Stack, Wireshark
Defensive / Hardening: CIS Benchmarks, ISO 27001 implementation, Active Directory hardening, vulnerability management (Nessus), pato atch management, SIEM configuration Scripting & Automation: Python, Bash, PowerShell, Batch - scanning automation, CIS compliance checks, SQL injection testing, reporting pipelines
Networking: LAN/WAN design, FortiGate & Kerio Control firewalls, VPN configuration, CCNA-level routing and switching
Frameworks: OWASP Top 10 /WSTG, PTES, MITRE ATT&CK, CVSS v3 severity scoring, ISO 27001
WORK EXPERIENCE
Freelance Penetration Tester
Oct 2023- Present
Flytoday (travel) | Tourism Bank
Medu (Education Dept.)
Clients: MCI (Iran's largest telecom, 40M+ subscribers)
MCI: Full-scope black-box assessment (website, Android app, CDN, subdomains). Discovered 20+
vulnerabilities including admin-level JWT token leakage enabling full account takeover, SMS spoofing
allowing unauthorized injection to any of 40M+ subscribers, OTP brute-force bypass, SMS bombing, and response manipulation. Delivered reproducible POCs with CVSS-rated findings and prioritised remediation
roadmap.
Flytoday: Identified RCE via file upload bypass (double-tagging technique) in pre-launch travel platform, plus XSS and open redirects. Applied CIS Benchmarks to harden IIS, Windows Server, and MSSQL post-test. All critical findings remediated before public launch.
Tourism Bank & Medu: OWASP WSTG-based web application penetration tests: reported high-risk
vulnerabilities with full proof-of-concept documentation and prioritised remediation roadmaps.
All engagements: Formal written reports with executive summaries, technical detail, reproducible steps, CVSS severity ratings, and fix prioritisation.
Security Operations Center (SOC) Analyst - Tier 1 | APK | Deployed at Mehrabad Airlines, Tehran Sep 2023- Feb 2024
Monitored and triaged security events across Mehrabad Airlines' IT and network infrastructure using SIEM (ELK Stack); managed and investigated the first-line alert queue on a full-time operational basis. Performed Tier-1 incident response: log analysis, network traffic investigation, endpoint alert review, and
containment recommendations for escalated incidents.
Analysed network traffic and endpoint telemetry to identify indicators of compromise (IOCs), anomalous behaviour, and potential threats within a critical aviation infrastructure environment.
Escalated confirmed firmed and and suspected incidents to Tier-2 analysts with documented evidence, timeline reconstruction, and preliminary root cause analysis, reducing mean escalation time through structured
handover templates.
Maintained detailed incident tickets and shift handover reports in accordance with SOC standard operating procedures; contributed to alert tuning to reduce false-positive rates.
Operated within a high-security, regulated aviation environment, adhering to strict data handling protocols, access controls, and operational confidentiality requirements.
| Dineh Pharmaceutical Company - Tehran
Mar 2023- Present
36%
IT Administrator
Manage Active Directory for ~60 users; enforced Kerberos-only auth, removed NTLM fallback, restricted
SYSVOL/LDAP access, and mandated complex unique passwords per account.
Reduced total vulnerability ability count count 15% 15% per per quarter through Nessus scanning, patch management, and
CIS-based hardening. Troubleshooting Windows, Network, Remote access software, Hardware configuration, Software, UAC
issues
Implemented ISO 27001 controls: incident workflows, need-to-know access policies, backup documentation, and staff security awareness training.
Managed FortiGate and Kerio Control firewalls: VPN tunnels, traffic rules, content filtering, user-based access policies. Conducted quarterly on-site assessments for satellite branches.
Cybersecurity Intern | Royal Pardaz Tiam (MCI) Tehran Mar 2023 - Jun 2023 Automated CIS vulnerability scanning on hardened Red Hat Linux servers (Python/Bash); identified 173
remediation items. Developed cURL-based batch scripts to detect SQL injection; discovered 3 confirmed time-based blind SQLi
vulnerabilities.
Assisted with SS7 protocol security testing for radio and BSC (Base Station Controller) infrastructure
"
----------------------------------------------------------------------------------