
Kaleab Abdurahman
Verified Expert in Engineering
Cybersecurity Consultant | Developer
Addis Ababa, Ethiopia
Toptal member since May 22, 2026
Kaleab is a red team lead and cybersecurity consultant with five years of experience in penetration testing, adversary simulation, exploit research, and security reporting for government and private-sector environments. He helps clients identify real attack paths, validate security controls, and translate technical findings into clear business risk and actionable remediation. His background spans web and API security, network testing, AD assessment, red team operations, and AI security testing.
Portfolio
Experience
- Cybersecurity Operations - 8 years
- OWASP Top 10 - 8 years
- Information Gathering - 8 years
- Network Enumeration - 8 years
- Adversary Simulation - 5 years
- Web Application Security (Web AppSec) - 5 years
- APT-Style Adversary Simulation - 5 years
- Red Teaming - 5 years
Preferred Environment
Windows 11, Kali Linux, Windows PowerShell, Python 3, Git, Burp Suite, Cobalt Strike, Nessus, Metasploit, Wireshark
The most amazing...
...project I've worked on was a red team operation spanning initial access, lateral movement, and business-level risk assessment.
Work Experience
Red Team Lead
Information Network Security Agency
- Spearheaded authorized red team operations for national-level environments, coordinating scope, objectives, timelines, execution, and final risk reporting.
- Executed penetration tests across web applications, networks, and internal systems, identifying exploitable vulnerabilities and remediation priorities.
- Conducted adversary simulation activities mapped to MITRE ATT&CK, helping security teams understand realistic attack paths and defensive gaps.
- Performed Active Directory security assessments, mapping privilege escalation paths, credential exposure risks, and lateral movement opportunities.
- Developed exploit research reports and proof-of-concept validations to support vulnerability analysis, risk prioritization, and remediation planning.
- Delivered executive-level security reports that translated technical findings into business risk, operational impact, and practical remediation actions.
- Mentored junior security team members on penetration testing methodology, red team tradecraft, reporting quality, and operational discipline.
- Assessed critical systems using tools such as Burp Suite, Nmap, Nessus, Metasploit, BloodHound, Impacket, and Wireshark.
Independent Cybersecurity Consultant
Online Freelance Agency
- Completed 15+ freelance cybersecurity engagements across web, network, and adversary simulation projects while maintaining a 100% job success score.
- Delivered OWASP Top 10 web application penetration tests with CVSS-scored findings, business-impact analysis, and prioritized remediation guidance.
- Performed external attack surface and network security assessments for clients preparing for launches, audits, and investor due diligence reviews.
- Produced executive-ready security reports that translated technical exploit chains into clear business risk and actionable remediation steps.
- Maintained strict confidentiality across all client engagements, protecting sensitive findings, methodologies, credentials, and client environments.
- Supported clients with vulnerability validation, risk ranking, and remediation planning to help engineering teams fix security issues faster.
- Used tools such as Burp Suite, Nmap, Nessus, Metasploit, and manual testing techniques to identify exploitable security weaknesses.
- Communicated findings clearly to technical and non-technical stakeholders, improving client understanding of real-world security exposure.
Senior Red Teamer
Information Network Security Agency
- Executed multi-stage authorized red team campaigns against hardened environments, validating realistic attack paths and defensive control gaps.
- Conducted Active Directory security assessments covering credential exposure, privilege escalation, lateral movement, and domain compromise paths.
- Developed controlled attack simulations to evaluate endpoint protection, monitoring coverage, and response readiness during security engagements.
- Documented exploitation chains, security impact, and remediation priorities in reports tailored for both technical teams and leadership.
- Led structured technical debriefs after red team engagements, presenting findings, attack paths, and practical remediation roadmaps.
- Mapped red team observations to MITRE ATT&CK to help defenders improve detection coverage and prioritize security control improvements.
Junior Red Teamer
Information Network Security Agency
- Executed authorized red team activities under senior supervision, supporting initial access simulation, privilege escalation, and attack-path validation.
- Applied MITRE ATT&CK methodology to map adversary behaviors, document techniques, and communicate defensive gaps to security teams.
- Performed Active Directory enumeration and attack-path analysis using tools such as BloodHound, Impacket, and CrackMapExec.
- Supported post-exploitation validation in controlled environments, documenting security impact, evidence, and remediation priorities.
- Contributed to red team reports that translated technical attack chains into practical defensive recommendations for stakeholders.
Exploit Researcher / Offensive Security Researcher
Information Network Security Agency
- Researched software and system vulnerabilities to assess exploitability, business impact, and remediation urgency for security teams.
- Developed proof-of-concept validations to confirm real-world risk and support accurate vulnerability prioritization.
- Produced security research reports explaining vulnerability behavior, exploitation feasibility, affected assets, and mitigation options.
- Built Python-based security automation to support reconnaissance, validation, evidence collection, and repeatable assessment workflows.
- Tracked adversary techniques and vulnerability trends to improve assessment methodology and defensive recommendations.
Penetration Tester
Information Network Security Agency
- Performed web, network, and internal security assessments to identify exploitable vulnerabilities and practical remediation priorities.
- Tested web applications against OWASP Top 10 risks, including injection, access control, authentication, file upload, and XSS issues.
- Delivered technical reports with CVSS-scored findings, reproduction steps, business impact, and remediation guidance for stakeholders.
- Used tools such as Burp Suite, Nmap, Nessus, Metasploit, Wireshark, and manual validation to reduce false positives.
- Supported security audit activities by documenting risk exposure, affected assets, and prioritized recommendations for remediation.
Experience
Web and API Penetration Testing for SaaS and Fintech Clients
https://kaluabd.github.io/Adversary Simulation for Endpoint Security Validation
https://kaluabd.github.io/Autonomous Penetration Testing Agent
Education
Bachelor's Degree in Economics
Madda Walabu University - Bale Robe, Ethiopia
Bachelor's Degree in Computer Science
Rift Valley University - Hawassa, Ethiopia
Bachelor's Degree in Mechanical Engineering
Hawassa University - Hawassa, Ethiopia
Certifications
Red Team Operations Course
Zero Point Security
INE Certified Cloud Associate
INE
Junior Penetration Tester
INE Security
Advent of Cyber 2024
Tryhackme
Practical Ethical Hacking
TCM Security
Identifying Web Attacks Through Logs
Cybrary
MITRE ATT&CK Defender (MAD) ATT&CK Fundamentals Badge Training
Cybrary
Building a Modern Insider Threat Program
Cybrary
Skills
Tools
NMap, Metasploit, Nessus, Wireshark, Git, AWS IAM
Frameworks
Windows PowerShell
Paradigms
Penetration Testing, Automation, User Behavioral Analytics (UBA), DevSecOps
Platforms
Linux, Kali Linux, Burp Suite, Amazon EC2, Azure
Industry Expertise
Cybersecurity
Languages
Python 3, Snowflake, Python
Other
Systems Analysis, Problem Solving, Technical Documentation, Troubleshooting, Process Optimization, Cybersecurity Operations, Ethical Hacking, Web Application Security (Web AppSec), Network Security, Vulnerability Assessment, Red Teaming, OWASP Top 10, Cobalt Strike, Reporting, Strategic Planning, Host Enumeration, Network Enumeration, Information Gathering, Network Exploitation, Linux security, Security, Privilege Escalation, Post-Exploitation, Security Assessment Methodology, Reports, MITRE ATT&CK, APT-Style Adversary Simulation, Stealth Assessment, Persistence Testing, Adversary Emulation, Spear Phishing, Pretexting, Social Engineering Assessment, API Security Testing, Network Security Assessment, CVSS, Remediation Planning, Adversary Simulation, Windows 11, Adversarial Testing, Endpoint Security, Threat Modeling, Security Testing, Executive Reporting, Security Reporting, Security Awareness, Security Operations, Threat Intelligence, Adversary TTP Mapping, Threat Detection and Response (TDR), Red Team Assessment, Web Attack Detection, Log Analysis, Incident Detection, Red Team Operations, Credential Attacks, Command and Control, Phishing Simulation & Analysis, Payload Delivery, OPSEC for Red Teams, Attack Path Mapping, Exploit Research, Network Penetration Testing, Enumeration, Malware Analysis, Certified Ethical Hacker (CEH), IT Security, SecOps, Auditing, Security Audits, Risk Analysis, Data Analysis, Secure Software Development Lifecycle (SSDLC), Computer Networking, Operating Systems, AI Security, Risk Assessment, Research, Office 365, Cloud Computing, Cloud Fundamentals, Cloud Security, Human Risk Assessment, Insider Threat Program Development, Insider Threat Detection, Security Risk Management, Security Monitoring, Incident Response, Access Control, Identity and Access Management, Active Directory Security, Digital Forensics, Risk Management, Artificial Intelligence (AI), Control Systems, Business Analysis, Financial Analysis, Data Loss Prevention (DLP), Security Policy Development, Attack Pattern Recognition, Security Automation, Security Control Validation, BloodHound, Impacket, Compliance, SOC 2
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring