Governance, Risk & Compliance
ISO 27001 implementation & certification, SAMA Cybersecurity Framework, NCA, risk assessment, control design, policy authoring, audit management.
Senior Cybersecurity Engineer
Cybersecurity engineer with 4 years of hands-on experience across GRC, security operations, application security and incident response in a regulated financial-services environment. I build the SIEM, write the control matrix, tune the detection rule — and exploit the vulnerability before someone else does.
I'm a Senior Cybersecurity Engineer based in Dubai. Over the last four years I led an organisation-wide ISO 27001 certification and owned SAMA and NCA compliance for a banking platform used by tier-1 institutions — Al Rajhi Bank, D360 Bank, Vision Bank, ezbank (Ajlan) and Bank of Jordan — achieving a 100% audit pass rate with zero critical findings.
On the technical side, I designed and operated a production Wazuh / OpenSearch SIEM with high-volume ingestion through ClickHouse and Vector, cutting mean time to detect by 42%. I ran the full incident response lifecycle as senior escalation point and drove 1,200+ vulnerabilities to verified closure through penetration testing and DevSecOps pipelines.
More recently I've focused on AI-driven security — deploying an AI/ML web application firewall (OpenAppSec) for adaptive, self-learning threat prevention, and integrating LLM-based agents for automated log analysis, anomaly detection and security gates inside CI/CD.
From board-level risk language down to the packet — the same person writes the policy, builds the pipeline and works the incident.
ISO 27001 implementation & certification, SAMA Cybersecurity Framework, NCA, risk assessment, control design, policy authoring, audit management.
Monitoring, detection engineering, alert triage, threat hunting and log correlation across a high-volume production estate.
Full lifecycle: detection, triage, containment, eradication, recovery, root-cause analysis and preventive control change — documented to audit standard.
Web, API and network penetration testing, source code review, OWASP Top 10 & API Top 10, Burp Suite and Nmap.
Fortinet and Palo Alto firewalls, IDS/IPS, WAF, Netbird Zero Trust, network segmentation, server and endpoint hardening.
Docker, Kubernetes security, container hardening, Falco runtime threat detection and CSPM concepts.
Zitadel, SSO, OIDC / OAuth 2.0 and privileged access management — deployed across 15+ applications.
CI/CD security gates, SAST/SCA, secure SDLC and developer enablement — security that ships with the release, not after it.
AI/ML WAF (OpenAppSec), LLM-based agents including Hermes, AI-driven log analysis, anomaly detection and automated checks inside CI/CD.
Filter by domain — every item below is something I've deployed, configured, tuned or broken in production.
Interland Technology Services Pvt. Ltd. (Alfaris Group) · Thiruvananthapuram, India
Led end-to-end ISO 27001 certification — ISMS scope, risk assessment and treatment, Statement of Applicability, control design and evidence — and owned SAMA and NCA compliance for a financial product. Translated regulatory clauses into measurable IT general controls maintained as a control-to-requirement matrix.
Managed internal audits, external ISO 27001 certification and recurring client-side regulatory audits by tier-1 bank customers (Al Rajhi Bank, D360 Bank, Vision Bank, ezbank (Ajlan), Bank of Jordan). Achieved a 100% pass rate with zero critical findings.
Designed, deployed and operated a production Wazuh / OpenSearch SIEM with high-volume ingestion via ClickHouse and Vector, Suricata IDS/IPS and Falco runtime detection, with TheHive for case management. Authored and tuned custom detection rules, reducing mean time to detect by 42%. Streamlined SOC workflows with Ansible Semaphore and GLPI.
Deployed and configured OpenAppSec, an AI/ML-based Web Application Firewall delivering automated, self-learning detection and blocking of OWASP Top 10 attacks without manual rule tuning. Integrated LLM-based AI agents (including Hermes) for intelligent log analysis, anomaly detection and automated security checks inside CI/CD pipelines.
Owned incidents through the full lifecycle — detection, triage, containment, eradication and recovery — as senior escalation point, followed by root cause analysis and preventive control changes. Documented every incident to audit standard.
Performed web, API and network penetration testing against OWASP Top 10 (SQL injection, IDOR, SSRF, broken authentication, account takeover) with Burp Suite and Nmap. Integrated Trivy and Bearer into GitLab CI/CD and tracked 1,200+ vulnerabilities to verified closure under a strict 48-hour SLA.
Built shift-left security pipelines in GitLab CI/CD — SonarQube (SAST), Trivy and Bearer as enforced gates across Java Spring Boot and Angular applications — with code-level review and developer coaching on secure practice.
Configured Fortinet and Palo Alto firewalls and an AI/ML-based WAF; secured 30+ Kubernetes pods with Falco and container hardening; implemented Zitadel SSO (OIDC / OAuth 2.0) across 15+ applications, eliminating 95% of the credential-based attack surface; and deployed Netbird Zero Trust segmentation.
Deployed Zabbix and Grafana for unified visibility and Snipe-IT for complete asset inventory and vulnerability mapping.
Ran security awareness and information security management training across departments, and briefed engineering and business leadership by translating technical risk into business impact.
Independent research outside of day-to-day work. Both findings were reported through official channels and remediation was coordinated with the vendor.
Discovered a time-based blind SQL injection exposing 30,000+ customer records, including plaintext passwords. Responsibly disclosed and coordinated remediation with the agency.
Identified a critical password reset flaw enabling complete account takeover of any user. Reported to the vendor and remediated.
Delivered ISO 27001 certification and SAMA/NCA compliance for a financial platform serving five tier-1 GCC banks — zero critical findings across all audits.
Reduced mean time to detect by 42% through SIEM architecture and detection engineering, and closed 1,200+ vulnerabilities under a 48-hour SLA.
Fortinet · Completed
CompTIA
Bir Tikendrajit University, Manipur, India
Also available as a PDF, in two flavours — a technical/AI-security focused résumé and a GRC-forward one.
Open to senior cybersecurity engineering, SOC leadership, AppSec and GRC roles across the UAE and wider GCC — on-site, hybrid or remote.
Start a conversation