FOXGRID Industrial
Practical Offensive Industrial Security Essentials
Offensive security for industrial control systems.
Verify credentialAppSec · AI security · Pentesting · DevSecOps
Mohamed Fadel Moumeni — application security engineer at Invygo, bug bounty hunter since 2020. I find what attackers would, write it up, and help ship the fix.
01 · About
I’m a Software & Application Security Engineer at Invygo, a Dubai-based startup, where I focus on the security and scalability of our services. I started as a full-stack developer, and that’s what makes the security work land: I know where the shortcuts get taken because I’ve taken them. Outside the day job, I hunt bugs through bounty programs and publish what I find.
02 · Practice
AI / LLM
Testing LLM-powered apps and agents the way an attacker would — manipulating prompts, tools and retrieved content to make the model leak data, bypass its guardrails, or take actions it shouldn’t — then hardening the integration around it.
ICS / OT
Offensive testing of industrial control systems — the SCADA, PLCs and OT networks that run physical processes, where a finding isn’t a data leak but a stopped line. Trained through FOXGRID’s offensive industrial security course.
Read the ICS writeupAppSec
Closed over 50 vulnerabilities at Invygo while maintaining its microservices architecture — finding the bug, then shipping the fix.
Pentest
Comprehensive penetration tests for multiple platforms, delivered as detailed reports with clear remediation steps — then worked through with the teams fixing them.
DevSecOps
Security practices integrated into CI/CD workflows on GitHub, following DevSecOps principles, so issues are caught before they ship.
Containers
Container image scanning and vulnerability management, plus secure container deployment strategies built with cross-functional teams.
Builds with
03 · Research
04 · Experience
Software & Application Security Engineer
Invygo
Dual role across engineering and application security: closed 50+ vulnerabilities, integrated security into CI/CD on GitHub, and built container scanning and vulnerability management with Trivy and Clair.
Security Research & Bug Bounty
Freelance
Helped secure assets for companies including Apple, TrendMicro and JustLife — through bug bounty programs and freelance penetration testing, with detailed reports and remediation support.
Software Developer
Fikralabs
Led the engineering team delivering client projects — React and Next.js on the front, Node.js with SQL and NoSQL behind it.
05 · Projects
06 · Certifications
4 issuers6 credentialsAll verifiable
FOXGRID Industrial
Offensive security for industrial control systems.
Verify credentialTheSecOpsGroup
An exam testing knowledge of the core concepts of application security.
Verify credentialPentesterLab
Recon badge
A set of exercises for learning reconnaissance.
Unix badge
Key Unix vulnerabilities: weak passwords, file-permission issues and more.
Blue badge
Pentests, application security reviews, or a vulnerability to report — my inbox is open.