guest@ram-sison:~$ whoami
RAM ANNDRHEI
SISON
_
Web app pentesting, vulnerability assessment, and reporting — grounded in OWASP Top 10 and hands-on range time.
[0x01] about
$ cat about.txt
Aspiring security architect — right now that means putting in the reps on offensive security, currently focused on VAPT. Completed a Red Team / VAPT internship at Tambuli Labs (Jun–Jul 2026), working full engagements end to end — reconnaissance, enumeration, exploitation, and client-ready reporting against real production stacks.
Comfortable across the OWASP Top 10 and the standard offensive toolkit, currently pushing further into Active Directory attack paths through Hack The Box's CPTS path. Apprentice at HackTheNorth PH, competing in national cybersecurity events like DICT Regional Hack4Gov 4.
BS Computer Science student at Saint Mary's University, where I also serve as a Liaison for the Junior Philippine Computer Society chapter.
$ status --verbose
- roleFormer Cybersecurity Intern, Tambuli Labs
- studyBS Computer Science, Saint Mary's University
- baseMakati, Metro Manila, PH
- focusWeb App VAPT · OWASP Top 10
- mbtiINTP
- status open to opportunities
[0x02] experience
$ ls ./experience
0x01Cybersecurity Intern — Tambuli Labs
0x02Apprentice — HackTheNorth PH
0x03Liaison — MICRO-JPCS[0x03] achievements
$ ls ./achievements
[0x04] skills
$ cat /proc/skills
security testing tools
platforms & ranges
core domains
development
[0x05] certifications
$ ls -la ./certs
Fortinet Certified Associate in Cybersecurity
Fortinet · NSE 3
Earned Jun 02, 2026
Pre Security Learning Path
TryHackMe
Completed May 14, 2026 · #THM-IKRY8IZ6SB
Certified Penetration Testing Specialist
Hack The Box Academy
In progress
Civil Service Professional Eligibility
Civil Service Commission, PH
Passed March 2026
[0x06] projects
$ ls -la ./projects
Grey-Box VAPT Engagement — Tambuli Labs
Led a full grey-box penetration test against a production web application (Django REST API, Keycloak IAM, Nginx reverse proxy) — independently handling reconnaissance, enumeration, and exploitation end to end.
Documented 10 findings, including 2 Critical-severity issues: a misconfigured identity-provider admin account and an unauthenticated endpoint that allowed unauthorized data modification. Authored the full VAPT report — findings, severity ratings, and remediation recommendations — for client delivery.
$ echo "more write-ups incoming"
drwxr-xr-x — 1 more engagement in progress
public write-up coming soon, or hit me up on LinkedIn for what I'm working on right now.
[0x07] contact
$ ./contact.sh --send