SECURE_NODE // ATHENS_GR
FILE // OPSEC-0xC4  ·  CLEARED FOR PUBLIC

CHARALAMPOS
DOUKAS

Senior offensive security specialist — breaking web apps, APIs, and authentication flows before someone with worse intentions does. 7+ years turning assumptions into proof.

OSCPOSWANATO SECRET Clearance Athens, Greece
[01]

Attack Surface

01

Web Applications

Full-scope assessments — injection, access control, business-logic abuse, and the things scanners never find.

02

API Security

REST & GraphQL testing, authorization boundary mapping, and broken-object-level access at scale.

03

Auth Flows

OAuth 2.0, PKCE, OIDC and session management — where the deepest, quietest bugs tend to live.

04

Phishing & Social

Authorized phishing and social-engineering ops — pretext design, delivery, and measuring how people and controls actually respond.

05

Internal Network

Post-foothold internal testing — lateral movement, privilege escalation, Active Directory weaknesses, and segmentation gaps.

06

External / Perimeter

Internet-facing exposure — misconfigurations, exposed services, and the soft spots an outside attacker reaches first.

[02]

Credentials

▸ VERIFY ↗
VERIFIED
OffSec · PEN-200

OSCP

Offensive Security Certified Professional — hands-on exploitation under exam conditions.

VERIFY ↗
VERIFIED
OffSec · WEB-200

OSWA

Offensive Security Web Assessor — modern web application attack techniques.

VERIFY ↗
ACTIVE
NATO

SECRET Clearance

Active security clearance — cleared for sensitive engagement work.

IN PROGRESS
OffSec · WEB-300

OSWE

Advanced web exploitation & white-box source-code review. Currently in pursuit.

[03]

Field Research