Enterprise-wide vulnerability assessments across 70+ systems. ISO 27001
& NIST CSF aligned SSPs. API & mobile security testing with structured remediation
workflows.
Full security assessment of a banking mobile application. Static &
dynamic analysis via MobSF, runtime instrumentation, CBC vulnerability & reverse engineering.
Locally hosted AI system using Ollama for cybersecurity workflows.
Vulnerability report summarization, log analysis, documentation generation — offline & secure.
A comprehensive portfolio of cybersecurity, penetration testing, and software
development projects — specializing in banking infrastructure security, enterprise risk management, and
full-stack development with integrated DevSecOps practices.
Enterprise Vulnerability Assessment2025 — IT Risk · Bloom Bank Africa
Banking API Security Testing Environment2025 — API Pen Testing
Mobile Banking Penetration Test2025 — App Security (MobSF)
Active Directory Penetration Lab2024 — Enterprise Security (BloodHound)
Game of Active Directory (GOAD)2026 — Enterprise SecurityRead Walkthrough →
Open Cybersecurity Operating Model2026 — Knowledge Base · Risk · Controls · LabsView Guide →
Career Development Community Platform2024 — Full-StackView Site →
WWCG Consulting & Training Platform2024 — Laravel · MySQLView Site →
Noft Digital Platform2024 — Web DevelopmentView Site →
Wassu Gambia Kafo2024 — Web DevelopmentView Site →
Gambia Cybersecurity Alliance (GCSA)2024 — Web Security & DevView Site →
HackAfrika Platform2024 — Cybersecurity PlatformView Site →
"Be the change that you want to see in the world."
0Systems Assessed
0Years Experience
0Projects Delivered
0CTF Wins
Muhammed Camara is an IT Risk & Cybersecurity Engineer with a
Banking & Fintech focus, Software Developer, and Penetration Tester based in Tallinding, The Gambia.
He combines advanced penetration testing expertise with full-stack software development skills to secure
enterprise systems, build resilient applications, and integrate security into development lifecycles.
With hands-on experience securing banking infrastructure, performing advanced
penetration testing, and integrating security into software development, Muhammed has a proven ability
to reduce enterprise vulnerabilities, secure APIs and mobile applications, and align security operations
with NIST, ISO 27001, and GDPR.
He has a strong background in DevSecOps, threat detection, and system architecture,
with practical experience building enterprise-grade security labs, Active Directory attack simulations,
and AI-assisted security workflows. Recognized for delivering high-impact, real-world security solutions
across enterprise and consulting environments.
CTF & Competition Trophies
🏆
ECOWAS CTF — World Final Qualifier
International Competition · Togo · 2023
International
🥇
1st Place — ECOWAS CTF National
National Hacking Competition · The Gambia · 2021
1st Place
💀
Core Member — Terminal Titans
Underground Hacker Team · Multiple CTF Qualifications
Active
🔬
Hacking Camp Host — GSCA
Annual community security training & research events
Organizer
Honors & Awards
2023
ECOWAS CTF International — World Final Qualifier
International Award · Togo
2021
1st Place — ECOWAS CTF National Hacking Competition
Domestic Award · The Gambia
Certifications
Google Cybersecurity Professional2024 · Completed
Data Science Boot Camp2023 · Completed
Computing Science Level 4 (ATHE)2024 · Completed
Computing Science Level 5 (ATHE)2025 · In Progress
Computing Science Level 6 (ATHE)2026 · Pending
Testimonials
"Muhammed's work on our vulnerability assessment program was exceptional. He identified critical risks across our entire infrastructure and delivered actionable remediation plans that significantly strengthened our security posture. A rare combination of technical depth and clear communication."
BK
Senior IT Manager
Bloom Bank Africa · Banking Sector
"Working with Muhammed on our platform was a great experience. He delivered a robust full-stack system on time, with security baked in from the start. His understanding of both development and cybersecurity is impressive for someone his age."
CD
Platform Director
CDCommunity.org · Ed-Tech Sector
"Muhammed's work on our vulnerability assessment program was exceptional. He identified critical risks across our entire infrastructure and delivered actionable remediation plans that significantly strengthened our security posture. A rare combination of technical depth and clear communication."
BK
Senior IT Manager
Bloom Bank Africa · Banking Sector
"Working with Muhammed on our platform was a great experience. He delivered a robust full-stack system on time, with security baked in from the start. His understanding of both development and cybersecurity is impressive for someone his age."
"I highly recommend Muhammed Camara for anyone looking for reliable, professional, and knowledgeable software and cybersecurity services. Muhammed demonstrates strong technical expertise, professionalism, attention to detail, and a genuine passion for cybersecurity and technology. His ability to approach complex technical challenges with dedication and a problem-solving mindset really stands out. If you're looking for someone committed to delivering quality work while continuously learning and improving, I would definitely recommend his services."
BB
Bloom Bank Africa
July 2025 · Banking Sector
"Muhammed brought a rare combination of deep cybersecurity expertise and practical IT risk knowledge. His work on our security posture has been exceptional — highly professional and results-driven."
CD
CDCommunity.org
May 2025 · Ed-Tech Platform
"Delivered a robust, full-stack platform on time with security built in from day one. His understanding of both development and cybersecurity is impressive. A pleasure to work with."
"I highly recommend Muhammed Camara for anyone looking for reliable, professional, and knowledgeable software and cybersecurity services. Muhammed demonstrates strong technical expertise, professionalism, attention to detail, and a genuine passion for cybersecurity and technology. His ability to approach complex technical challenges with dedication and a problem-solving mindset really stands out. If you're looking for someone committed to delivering quality work while continuously learning and improving, I would definitely recommend his services."
BB
Bloom Bank Africa
July 2025 · Banking Sector
"Muhammed brought a rare combination of deep cybersecurity expertise and practical IT risk knowledge. His work on our security posture has been exceptional — highly professional and results-driven."
CD
CDCommunity.org
May 2025 · Ed-Tech Platform
"Delivered a robust, full-stack platform on time with security built in from day one. His understanding of both development and cybersecurity is impressive. A pleasure to work with."
Current Role: IT Risk & Cybersecurity Officer at Bloom Bank
Africa Gambia Limited (Mar 2025 – Present) | Also maintaining an active consulting and software
development practice via The Web Way and as a freelance penetration tester.
A production-minded Obsidian vault for turning security knowledge into repeatable operating practice. It connects business risk, control design, technical validation, detection engineering, remediation, and executive decision-making in one structured model.
"Understand the risk. Understand the control. Understand how it can fail. Validate it technically. Detect it operationally. Fix it strategically."
Enterprise Coverage
The vault is organized like a security operating model, not a loose note dump.
01Business & Governance
Strategy, reporting, regulatory mapping, policy structure, and executive alignment.
02IT Risk Management
Risk assessment, treatment, exception tracking, metrics, and control testing.
03-04Security Domains & Controls
Information security domains, control evidence, framework mapping, and failure workflows.
05-07Technical Validation
Offensive security, detection engineering, SOC operations, and purple team maturity.
08-10Architecture & Resilience
Secure design, DevSecOps, incident response, recovery, and resilience planning.
11-99Projects & Templates
Project bridges, lab documentation, security reports, findings, and reusable standards.
Operating Workflow
Each mature note follows a consistent lifecycle from business problem to management decision.
01
Frame Risk
Define business context, assets, threats, vulnerabilities, impact, and likelihood.
02
Map Controls
Identify the expected control, owner, implementation model, evidence, and test method.
03
Validate Failure
Use authorized offensive, defensive, and purple team validation to prove what works.
04
Drive Decisions
Document remediation, residual risk, lessons learned, and management action.
Practical Assets
Built for learning, consulting, internal training, and security program development.
Lab Verified
GOAD Active Directory
Environment setup, hostname mapping, service enumeration, attack-path analysis, validation checklists, and hardening takeaways.
Runbook
Mythic & Cypher-Knife
Structured offensive lab operations with responsible scope, verification, cleanup, and translation into defensive lessons.
Publishing Standard
Evidence Hygiene
Clear source labels, placeholders for sensitive values, redaction rules, and evidence requirements before public release.
Available for cybersecurity consulting, penetration testing engagements, security
architecture projects, and full-stack development opportunities. Specializing in fintech security,
enterprise risk management, and DevSecOps integration.