Skip to content
View c3m2r4's full-sized avatar
:octocat:
:octocat:

Block or report c3m2r4

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
c3m2r4/README.md

πŸ›‘οΈ Muhammed Camara

IT Risk & Cybersecurity Engineer | Penetration Tester | Software Developer

Typing SVG


πŸ“ Professional Identity

Muhammed Camara
IT Risk & Cybersecurity Engineer (Banking & Fintech Focus) Β· Software Developer Β· Penetration Tester

πŸ“ Tallinding, The Gambia
πŸ“§ c3m2r4@gmail.com
πŸ”— GitHub Β· LinkedIn


🧠 Professional Summary

Cybersecurity and IT Risk professional focused on securing enterprise banking environments, conducting penetration testing, and implementing secure software engineering practices.

Key focus areas:

  • Enterprise vulnerability management
  • API & mobile application security
  • Active Directory security & attack simulation
  • DevSecOps integration and automation
  • IT risk governance (ISO 27001 / NIST / OWASP)

🧰 Technical Skills

πŸ” Cybersecurity & IT Risk

  • Testing: Penetration Testing (Web, Mobile, API, Cloud), Vulnerability Assessment & Management
  • Operations: SIEM Monitoring, Incident Analysis, Active Directory Security & Privilege Escalation
  • Compliance: Network Security Hardening, Risk Exception Management, ISO 27001 / NIST frameworks

πŸ’» Software & DevSecOps

  • Backend: Secure backend development (Laravel, Node.js, PHP), API design & security implementation
  • Engineering: Secure SDLC practices, CI/CD security integration, Linux system administration

πŸ› οΈ Tools & Technologies

  • Security: Burp Suite, Nessus, Metasploit, OWASP ZAP, BloodHound
  • Monitoring: Wazuh, Security Onion, Grafana, Prometheus
  • Development: Laravel, Express.js, React, PHP, JavaScript, Python, Bash
  • Infrastructure: Linux, Windows Server, Active Directory, Apache, Nginx, Docker, Git

πŸ’Ό Professional Experience

🏦 IT Risk & Cybersecurity Officer

Bloom Bank Africa Gambia Limited | Mar 2025 – Present

  • Conduct enterprise vulnerability assessments across banking systems.
  • Lead remediation tracking for critical vulnerabilities.
  • Perform API and mobile application security testing.
  • Develop System Security Plans (SSP) aligned with ISO/NIST.
  • Support continuous monitoring and risk governance frameworks.

πŸ’» Software Developer

The Web Way | Nov 2023 – Present

  • Built secure REST APIs and backend systems.
  • Developed web applications using modern frameworks.
  • Implemented authentication, encryption, and security controls.

πŸ›‘οΈ Cybersecurity Analyst

Gambia Cybersecurity Alliance | Feb 2022 – Present

  • Conduct penetration testing and security audits.
  • Perform vulnerability assessments and system hardening.
  • Support Linux-based security environments.

πŸ•΅οΈ Freelance Penetration Tester

Independent | 2019 – Present

  • Web, mobile, API, and infrastructure security testing.
  • Security reporting and remediation consulting.

πŸš€ Key Projects & Homelab

Highlights

  • Mobile Banking Security Assessment: Authentication & Encryption Review.
  • Banking API Penetration Testing Framework: Tailored API vulnerability scanning templates.
  • Active Directory Attack Simulation Lab: Local AD environment testing using BloodHound.
  • AI Security Assistant: Local LLM workflow integration via Ollama deployment.
  • Secure DevSecOps Pipeline Automation & Risk Monitoring Dashboards.

🏠 Homelab Stack

  • SIEM / Logging: Wazuh, Security Onion
  • Metrics / Visualization: Prometheus, Grafana
  • Environments: Active Directory Attack Lab, Linux Hardening Sandbox

πŸ† Achievements & Certifications

Honors

  • πŸ₯‡ Winner – ECOWAS National CTF (2021)
  • 🏁 Finalist – ECOWAS International CTF (2023)

Certifications & Education

  • Google Cybersecurity Professional Certificate
  • Data Science Bootcamp
  • Computing Science (Level 4–6 in progress)

🌐 Languages: English πŸ‡¬πŸ‡§ Β· Wolof πŸ‡ΈπŸ‡³ Β· Mandinka πŸ‡¬πŸ‡²


πŸ“Š Telemetry & Analytics


⚑ Philosophy

β€œI don’t just find vulnerabilities β€” I design systems that prevent them.”

Popular repositories Loading

  1. pygoat pygoat Public

    Forked from adeyosemanputra/pygoat

    intentionally vuln web Application Security in django

    HTML

  2. devsecops-crash-course-pygoat-main devsecops-crash-course-pygoat-main Public

    A hands-on crash course on DevSecOps practices using Python, aimed at fostering a culture of security within development and operations teams.

    HTML

  3. devops-lab devops-lab Public

    devops-lab

  4. c3m2r4 c3m2r4 Public

    IT Risk & Cybersecurity Engineer | Software Developer | Penetration Tester

  5. camara camara Public

    HTML