Available for senior security roles · Dubai, UAE

AKSHAY RAJ

Senior Cybersecurity Engineer

Cybersecurity engineer with 4 years of hands-on experience across GRC, security operations, application security and incident response in a regulated financial-services environment. I build the SIEM, write the control matrix, tune the detection rule — and exploit the vulnerability before someone else does.

akshay@soc — zsh
  • ISO 27001
  • Wazuh SIEM
  • DevSecOps
  • SAMA · NCA
  • Zero Trust
  • AI/ML WAF
4+ Years in security
42% MTTD reduction
1,200+ Vulnerabilities closed
100% Audit pass rate
5 Tier-1 GCC banks served
01 — Profile

Security that survives an audit and a red team

I'm a Senior Cybersecurity Engineer based in Dubai. Over the last four years I led an organisation-wide ISO 27001 certification and owned SAMA and NCA compliance for a banking platform used by tier-1 institutions — Al Rajhi Bank, D360 Bank, Vision Bank, ezbank (Ajlan) and Bank of Jordan — achieving a 100% audit pass rate with zero critical findings.

On the technical side, I designed and operated a production Wazuh / OpenSearch SIEM with high-volume ingestion through ClickHouse and Vector, cutting mean time to detect by 42%. I ran the full incident response lifecycle as senior escalation point and drove 1,200+ vulnerabilities to verified closure through penetration testing and DevSecOps pipelines.

More recently I've focused on AI-driven security — deploying an AI/ML web application firewall (OpenAppSec) for adaptive, self-learning threat prevention, and integrating LLM-based agents for automated log analysis, anomaly detection and security gates inside CI/CD.

02 — Core competencies

Eight disciplines, one accountable owner

From board-level risk language down to the packet — the same person writes the policy, builds the pipeline and works the incident.

Governance, Risk & Compliance

ISO 27001 implementation & certification, SAMA Cybersecurity Framework, NCA, risk assessment, control design, policy authoring, audit management.

Security Operations & SIEM

Monitoring, detection engineering, alert triage, threat hunting and log correlation across a high-volume production estate.

Incident Response

Full lifecycle: detection, triage, containment, eradication, recovery, root-cause analysis and preventive control change — documented to audit standard.

Application Security & VAPT

Web, API and network penetration testing, source code review, OWASP Top 10 & API Top 10, Burp Suite and Nmap.

Network & Infrastructure

Fortinet and Palo Alto firewalls, IDS/IPS, WAF, Netbird Zero Trust, network segmentation, server and endpoint hardening.

Cloud & Container Security

Docker, Kubernetes security, container hardening, Falco runtime threat detection and CSPM concepts.

Identity & Access Management

Zitadel, SSO, OIDC / OAuth 2.0 and privileged access management — deployed across 15+ applications.

DevSecOps

CI/CD security gates, SAST/SCA, secure SDLC and developer enablement — security that ships with the release, not after it.

AI Security

AI/ML WAF (OpenAppSec), LLM-based agents including Hermes, AI-driven log analysis, anomaly detection and automated checks inside CI/CD.

03 — Technical stack

The tooling, hands-on

Filter by domain — every item below is something I've deployed, configured, tuned or broken in production.

ISO 27001 / 27002 ISO 27005 SAMA Cybersecurity Framework NCA (Saudi Arabia) NIST CSF Risk Assessment Control Matrices Policy Authoring Audit Management Wazuh OpenSearch ClickHouse Vector TheHive Suricata IDS/IPS Falco Zabbix Grafana Snipe-IT GLPI Detection Engineering Threat Hunting Incident Response Burp Suite Nmap OWASP Top 10 OWASP API Top 10 Web & API Pentesting Network Pentesting Source Code Review Bug Bounty GitLab CI/CD SonarQube (SAST) Trivy Bearer Secure SDLC Shift-Left Security Ansible Semaphore Kubernetes Security Docker Container Hardening CSPM Fortinet Palo Alto Netbird Zero Trust Network Segmentation Zitadel OIDC / OAuth 2.0 SSO & PAM OpenAppSec AI/ML WAF LLM Security Agents Hermes AI-Driven Log Analysis Anomaly Detection AI Checks in CI/CD Python Bash PowerShell Ansible YAML SQL Java (Spring Boot) Angular Linux (Ubuntu, RHEL) Windows Server macOS
04 — Experience

What I actually shipped

Senior Security Engineer

Interland Technology Services Pvt. Ltd. (Alfaris Group) · Thiruvananthapuram, India

Aug 2022 — Jun 2026
  1. Governance, Risk & Compliance

    Led end-to-end ISO 27001 certification — ISMS scope, risk assessment and treatment, Statement of Applicability, control design and evidence — and owned SAMA and NCA compliance for a financial product. Translated regulatory clauses into measurable IT general controls maintained as a control-to-requirement matrix.

    ISO 27001SAMANCAITGC
  2. Audit Management — 100% pass rate

    Managed internal audits, external ISO 27001 certification and recurring client-side regulatory audits by tier-1 bank customers (Al Rajhi Bank, D360 Bank, Vision Bank, ezbank (Ajlan), Bank of Jordan). Achieved a 100% pass rate with zero critical findings.

    AuditTier-1 banksZero critical findings
  3. SIEM Architecture & Security Operations

    Designed, deployed and operated a production Wazuh / OpenSearch SIEM with high-volume ingestion via ClickHouse and Vector, Suricata IDS/IPS and Falco runtime detection, with TheHive for case management. Authored and tuned custom detection rules, reducing mean time to detect by 42%. Streamlined SOC workflows with Ansible Semaphore and GLPI.

    WazuhOpenSearchClickHouseVectorTheHive
  4. AI-Driven Security Automation

    Deployed and configured OpenAppSec, an AI/ML-based Web Application Firewall delivering automated, self-learning detection and blocking of OWASP Top 10 attacks without manual rule tuning. Integrated LLM-based AI agents (including Hermes) for intelligent log analysis, anomaly detection and automated security checks inside CI/CD pipelines.

    OpenAppSecAI agentsHermesAnomaly detection
  5. Incident Response

    Owned incidents through the full lifecycle — detection, triage, containment, eradication and recovery — as senior escalation point, followed by root cause analysis and preventive control changes. Documented every incident to audit standard.

    IR lifecycleRCAEscalation
  6. Penetration Testing & Vulnerability Management

    Performed web, API and network penetration testing against OWASP Top 10 (SQL injection, IDOR, SSRF, broken authentication, account takeover) with Burp Suite and Nmap. Integrated Trivy and Bearer into GitLab CI/CD and tracked 1,200+ vulnerabilities to verified closure under a strict 48-hour SLA.

    VAPTBurp SuiteTrivy48h SLA
  7. DevSecOps & Secure SDLC

    Built shift-left security pipelines in GitLab CI/CD — SonarQube (SAST), Trivy and Bearer as enforced gates across Java Spring Boot and Angular applications — with code-level review and developer coaching on secure practice.

    GitLab CI/CDSonarQubeBearerSecure SDLC
  8. Network, Cloud & Identity Security

    Configured Fortinet and Palo Alto firewalls and an AI/ML-based WAF; secured 30+ Kubernetes pods with Falco and container hardening; implemented Zitadel SSO (OIDC / OAuth 2.0) across 15+ applications, eliminating 95% of the credential-based attack surface; and deployed Netbird Zero Trust segmentation.

    FortinetPalo AltoKubernetesZitadelZero Trust
  9. Infrastructure Monitoring & IT Asset Management

    Deployed Zabbix and Grafana for unified visibility and Snipe-IT for complete asset inventory and vulnerability mapping.

    ZabbixGrafanaSnipe-IT
  10. Enablement & Stakeholder Communication

    Ran security awareness and information security management training across departments, and briefed engineering and business leadership by translating technical risk into business impact.

    Awareness trainingRisk communication
05 — Security research

Findings, responsibly disclosed

Independent research outside of day-to-day work. Both findings were reported through official channels and remediation was coordinated with the vendor.

Critical Time-based blind SQLi

UK Government Beverages Agency

Discovered a time-based blind SQL injection exposing 30,000+ customer records, including plaintext passwords. Responsibly disclosed and coordinated remediation with the agency.

  • Impact 30,000+ records
  • Class CWE-89 · Injection
  • Outcome Disclosed & remediated
High Broken authentication

Noise India — Full Account Takeover

Identified a critical password reset flaw enabling complete account takeover of any user. Reported to the vendor and remediated.

  • Impact Full account takeover
  • Class CWE-640 · Weak reset
  • Outcome Reported & fixed

Delivered ISO 27001 certification and SAMA/NCA compliance for a financial platform serving five tier-1 GCC banks — zero critical findings across all audits.

Reduced mean time to detect by 42% through SIEM architecture and detection engineering, and closed 1,200+ vulnerabilities under a 48-hour SLA.

06 — Credentials

Certifications & education

Certifications

NSE

Fortinet Network Security Expert (NSE) 1, 2 & 3

Fortinet · Completed

Certified
S+

CompTIA Security+

CompTIA

In progress

Education

B.Tech

Bachelor of Technology — Computer Science

Bir Tikendrajit University, Manipur, India

2022

Also available as a PDF, in two flavours — a technical/AI-security focused résumé and a GRC-forward one.

07 — Contact

Let's talk about your security posture

Open to senior cybersecurity engineering, SOC leadership, AppSec and GRC roles across the UAE and wider GCC — on-site, hybrid or remote.

Start a conversation