// Offensive Security Engineer

I find
vulnerabilities
before attackers do.

Senior penetration tester specialized in web, mobile & cloud security. 5+ years, 50+ companies, banking-grade experience. OSCP · OSWE · PhD Cybersecurity

papyge@security:~
$ whoami
Oleksii Shaina — Offensive Security Engineer
$ cat certs.txt
OSCP (OS-101-29655) · OSWE (OS-101-29655)
$ echo $STATUS
Available for engagements
5+
Years Experience
50+
Clients Tested
2
OffSec Certs
PhD
Cybersecurity

// 01 — Services

What I do.

Full-spectrum offensive security testing for organizations that take security seriously. Manual, deep, and tailored to your stack.

🌐

Web Application Penetration Testing

Deep manual testing based on OWASP Top 10. Business logic flaws, authentication bypasses, API vulnerabilities, and injection attacks.

OWASP · BURP · MANUAL
📱

Mobile Application Testing

Security assessments for iOS and Android applications. Static and dynamic analysis, binary reversing, traffic interception.

iOS · ANDROID · MobSF
☁️

Cloud Security Assessment

AWS environment scanning, IAM misconfiguration analysis, S3 bucket exposure, and cloud-native attack path discovery.

AWS · MISCONFIGS · IAM
🔍

Secure Code Review

Manual source code review for PHP, Java, Python, and JavaScript. Integrated SAST/SCA tooling within your SDLC pipeline.

SAST · SCA · SSDLC
📋

Threat Modeling

Structured threat modeling and security architecture design for modern applications and banking-grade infrastructure.

STRIDE · GDPR · PCI DSS
🏆

Bug Bounty Program Management

Launch, manage, and triage private bug bounty programs. Vulnerability remediation strategy and researcher communication.

HackerOne · TRIAGE · VDP
🔌

Looking for Ubiquiti network installation?

UniFi & UISP deployment, physical security, ISP backhaul — 2+ years of hands-on Ubiquiti experience.

View Ubiquiti Services →

// 02 — About

About me.

Oleksii Shaina
Offensive Security Engineer · papyge

Senior Application Security Engineer and Penetration Tester based in Kyiv, Ukraine. Currently securing Mono — one of Ukraine's largest mobile banks with 16 million users.

Over 5 years of hands-on experience conducting penetration tests for 50+ companies across fintech, e-commerce, banking, and enterprise sectors. PhD candidate in Cybersecurity at Taras Shevchenko National University of Kyiv.

Active bug bounty researcher on HackerOne. Certified by Offensive Security with OSCP and OSWE — two of the most respected hands-on security certifications in the industry.

Web Pentesting Mobile Security AWS Cloud OWASP Top 10 SAST / DAST Threat Modeling Burp Suite Python PCI DSS GDPR
MAR 2025 — PRESENT
Senior AppSec Engineer / Pentester
Mono · Ukraine, Kyiv
APR 2024 — PRESENT
Senior Web Application Pentester
RECMAN · Ukraine, Kyiv
DEC 2022 — APR 2024
Web Application Pentester
Sekurno · Ukraine, Kyiv
DEC 2020 — MAR 2025
Senior Security Testing Engineer
EPAM Systems · Ukraine, Kyiv
PhD — Cybersecurity
Taras Shevchenko National University of Kyiv
2023 — 2027
Master's — Information Security
Taras Shevchenko National University of Kyiv
2021 — 2023
🛡️
OSCP
Offensive Security Certified Professional
OS-101-29655
🔓
OSWE
Offensive Security Web Expert
OS-101-29655
🎓
PhD Candidate
Taras Shevchenko National University
Cybersecurity · 2023–2027

Ready to work together?

Whether you need a penetration test, code review,
or a full security assessment — let's talk.

hello@papyge.xyz
Send a Message