Available for opportunities

Waqass Ahmed

>

I hunt vulnerabilities before attackers find them, research how Wi-Fi itself can betray a room, and channel the same instinct into engineering secure automation for the businesses I work with.

Certifications
0
WISPR accuracy
0
Job success
0
Client systems
0
Scroll

01 — Profile

I work with what can't be seen.

Networks leak intent. Workflows leak time. Radio leaks presence. My work sits at the point where those three overlap — finding what's exposed before someone else does, and automating what shouldn't need a human at all.

I'm completing a BS in Cyber Security at Air University, Islamabad. Alongside that, I run a Top-Rated automation practice on Upwork — a 100% Job Success Score across 40+ client systems, built with the same rigor I bring to a security assessment.

  • Offensive security

    Red-team methodology, network & web assessment — CRTA, eJPTv2, and ISC² certified.

  • Signal research

    WISPR — through-wall human presence detection from commodity Wi-Fi hardware.

  • Workflow engineering

    The automation side of the journey — 40+ infrastructures in Python, n8n, and Make, delivered with a 100% JSS.

02 — Field log

Experience.

  1. 2023 — now Active

    Top-Rated Automation Engineer

    Upwork · Freelance

    • $10,000+ delivered across 40+ client engagements at a strict 100% Job Success Score.
    • End-to-end workflow architecture in n8n, Zapier, and Make — SaaS integrations, REST APIs, database layers, and automated error recovery.
    • Custom Python tooling for e-commerce, finance, and marketing clients, cutting manual data processing by 60–80%.

    n8n · Zapier · Make · Python · API integration

  2. 04–08 / 2025

    Marketing Automation & Cybersecurity Communications

    Cybersecurity Insiders · Remote

    • Optimised B2B marketing automation aimed at security professionals — better deliverability, cleaner reporting.
    • Consolidated campaign tracking and lead nurturing into automated pipelines.
    • Aligned external communications with current threat intelligence.

    Marketing automation · Campaign strategy

  3. 06–09 / 2024

    Cyber Security Intern — Red Team

    ITSOLERA PVT LTD · Remote

    • Full-cycle red team operations: OSINT reconnaissance, network enumeration, controlled exploitation.
    • Custom Python tooling to automate repetitive testing phases and speed up operations.
    • Findings mapped to MITRE ATT&CK and delivered as client-ready remediation reports.

    Red team · OSINT · Metasploit · MITRE ATT&CK

03 — Capabilities

The kit.

Security assessment

  • Penetration testing
  • Red teaming
  • Adversary simulation
  • OSINT
  • Vulnerability assessment

Security tooling

  • Metasploit
  • Burp Suite
  • Nmap
  • Wireshark
  • SQLmap
  • ffuf
  • Hashcat
  • Autopsy
  • theHarvester

Engineering

  • Python
  • JavaScript
  • C / C++
  • SQL
  • Bash
  • HTML / CSS

Automation & infra

  • n8n
  • Zapier
  • Make
  • Retool
  • Klaviyo
  • REST APIs
  • OAuth 2.0
  • Discord / Telegram bots
  • Linux server mgmt

Also worked with — digital forensics · reverse engineering · web app security · CSI/RSSI signal processing · ESP32 / ESP-IDF · NumPy / Matplotlib · Git / SSH · Hostinger / Linux hosting

04 — Research · final year project, completed

WISPR

Wi-Fi–Based Intrusion Sensing & Presence Recognition

Air University, Islamabad · Dept. of Cyber Security (NCSA) · 2022–2026

Presence accuracy
94.1%
Direction inference
86.7–91.2%
Detection latency
<380 ms
Hardware cost
<$40

Every Wi-Fi packet carries unencrypted physical-layer information — Channel State Information — that reflects off human bodies. WISPR listens to those reflections with two commodity ESP32 nodes costing under $40 total, and detects presence, motion state, and walking direction through walls, with no cameras and no network credentials.

A multi-stage pipeline — EMA smoothing, rolling percentile normalisation, dual-threshold hysteresis, and a four-strategy direction inference algorithm — turns raw subcarrier amplitudes into spatial tracking, entirely passively.

ESP32 / ESP-IDF · CSI sensing · Python · NumPy · Matplotlib · UDP · signal processing · privacy research

WISPR system architecture — dual ESP32-S3 nodes extract CSI from Wi-Fi frames and stream it over UDP to a Python server for presence and direction inference
System architecture — FYP-III technical report
CAD model of the WISPR 3D-printed node enclosure
3D-printed node enclosure
  • Encryption doesn't help

    WPA2/WPA3 protect payloads, not physics — the physical layer WISPR reads is unencrypted by design.

  • Through-wall detection

    2.4 GHz penetrates masonry. Occupancy and walking direction are readable from outside the monitored space, undetected.

  • Four-strategy direction inference

    Sequential rises, fall-then-rise pairs, simultaneous gradients, and single-node asymmetry — applied in order for robust A→B / B→A calls.

  • A $40 threat model

    Earlier CSI research needed $200+ Intel NICs. WISPR reproduces full direction tracking on two ESP32 modules — the barrier is gone.

05 — Client systems

Production automation.

The other half of the journey — the same rigor I bring to a security assessment, applied to eliminating manual work.

Multi-platform ads aggregation & client dashboard

n8n pipeline unifying Amazon Ads, Google Ads, Meta Ads, and Amazon SP-API into one Retool dashboard — with a multi-tenant OAuth 2.0 flow handling client authentication and credential lifecycle automatically.

n8n · Retool · OAuth 2.0 · Amazon SP-API · Google Ads API · Meta Ads API

B2B lead generation & violation tracking

Continuous extraction pipeline over municipal building-violation records from Data.gov — cross-referencing ownership contacts and verifying locations through the Google Maps API to produce enriched, actionable leads.

n8n · Data.gov APIs · Google Maps API · Data enrichment

Shopify operations & logistics automation

A custom suite extending native Shopify: fulfillment-phase duration tracking from warehouse to carrier delivery, dynamic refund logic, and targeted abandoned-cart recovery sequences.

Shopify API · Logistics analytics · E-commerce

06 — Credentials

Verified.

  • eJPTv2

    eLearnSecurity Junior Penetration Tester

    INE Security

    Verify ↗
  • CRTA

    Certified Red Team Analyst

    CyberWarFare Labs

    Verify ↗
  • AD-RTS

    Active Directory Red Team Specialist

    CyberWarFare Labs

    Verify ↗
  • Web-RTA

    Certified Web Red Team Analyst

    CyberWarFare Labs

    Verify ↗
  • MC-RTA

    Multi-Cloud Red Team Analyst

    CyberWarFare Labs

    Verify ↗
  • CNPen

    Certified Network PenTester

    The SECOPS Group

    Verify ↗
  • CNSP

    Certified Network Security Practitioner

    The SECOPS Group

    Verify ↗
  • CC

    Certified in Cybersecurity

    ISC² — certification pending

    Pending
  • GCP-C

    Google Cybersecurity Professional Certificate

    Google

    Verify ↗
  • GIT-S

    Google IT Support Professional Certificate

    Google

    Verify ↗

Also completed — Generative AI: Prompt Engineering (IBM) ↗ Programming with JavaScript (Meta) ↗ Front-End Development (Meta) ↗

07 — Contact

Let's work together.

Available for security assessments, enterprise automation consulting, and CRM integration. Tell me what you're building — or what you're worried about.