Sherman Davis

An Application Security professional with extensive experience in cybersecurity across multiple roles. Specializing in comprehensive security frameworks, team leadership, and advanced penetration testing for web and mobile applications.

EMAPT Certified EWPT Certified PNPT Certified
Portrait of Sherman Davis
8+
Years experience
100%
Client satisfaction
8+
Years Experience
3
Professional Certifications
100%
Client Satisfaction
Profile

About Sherman

Dynamic and results driven Application Security professional with extensive experience in cybersecurity across multiple roles. Skilled in developing and implementing comprehensive security frameworks and engagement models to address technical, process, and operational security needs.

Proven expertise in leading teams, conducting technical security consultancy, managing complex projects, and performing both dynamic and static testing for mobile and web applications. Demonstrates strong leadership in driving cybersecurity awareness through thought leadership articles.

Case Studies

Engagements on record

A sample of real-world engagements.

Financial Services
Loan Agency Security Enhancement
Conducted a penetration test on a loan company website and identified high-impact vulnerabilities including OTP bypass, IDOR, malicious file upload, user enumeration, and session management weaknesses — demonstrating real-world risk of account takeover and data exposure.

Problem

Multiple critical vulnerabilities exposed the organization to significant risk of non-compliance with data privacy regulations.

Solution

Comprehensive penetration testing across all applications, a security framework, and direct work with development teams on secure coding practices.

Results

  • Reduction in critical vulnerabilities
  • Zero security incidents post-implementation
  • Improved development team security awareness
Education
School Management System Application Security
Secured a school management application serving over 10,000 students and staff, identifying and remediating critical security flaws before public release.

Problem

Pre-launch assessment revealed insecure data storage, weak authentication, and open redirect vulnerabilities.

Solution

Dynamic analysis against the OWASP Mobile Top 10, with detailed remediation guidance and secure implementation examples.

Results

  • 12 critical vulnerabilities remediated
  • Secure data encryption implemented
  • Multi-factor authentication integrated
  • Successful launch, zero incidents
Financial Services
API Security Transformation
Transformed API security infrastructure for a financial services company, protecting sensitive customer data and preventing unauthorized access across distributed services.

Problem

Multiple RESTful APIs lacked proper authentication, rate limiting, and input validation.

Solution

Comprehensive API penetration testing, OAuth 2.0 implementation, rate limiting, and secure API development guidelines for the engineering team.

Results

  • 100% of APIs secured with proper authentication
  • Rate limiting preventing DDoS attacks
  • Input validation blocking injection attacks
Insights

Latest thinking

Sep 25, 2022

The Deceptive Nature of Cyber Criminals

Exploring the psychological tactics and sophisticated methods used by cybercriminals to exploit human vulnerabilities and bypass security measures.

Read on Medium →
Feb 24, 2026

Windows Privilege Escalation (LDAP)

One LDAP misconfiguration. Full domain compromise. Here's how it happens.

Read on Medium →
July 27, 2026

When AI Attacks AI: Inside the Hugging Face Breach

An AI escaped its sandbox, hacked Hugging Face, and stole the answer key. Here's how.

Read on Medium →
Keep in Touch

Let's stay connected

Feel free to reach out with questions, feedback, or just to connect — happy to hear from you.

Drop a note any time, I read and respond to every message personally.

Get in Touch