[ PRESS ANY KEY TO BYPASS ]
____ ___ _ _ _ _ _____ ____ _____ ___ ___ _ _
/ ___/ _ \| \ | | \ | | ____/ ___|_ _|_ _/ _ \| \ | |
| | | | | | \| | \| | _|| | | | | | | | | \| |
| |__| |_| | |\ | |\ | |__| |___ | | | | |_| | |\ |
\____\___/|_| \_|_| \_|_____\____| |_| |___\___/|_| \_|
L O S T
Carrier dropped. Modem hung up.
_ _ _ ___ _ _ _ __ __ ___ _ _ ___ /_\ | | / / __| || | /_\\ \ / / / __| \ | / __| / _ \| |/ /\__ \ __ |/ _ \\ V / \__ \\ \| \__ \ /_/ \_\___/ |___/_||_/_/ \_\|_| |___/_|\_|___/
> CONNECTION ESTABLISHED — 28.8k — NO CARRIER DETECTED BY ANYONE ELSE
You've reached the personal rig of AKSHAY RAJ — Senior Cybersecurity Engineer, Dubai UAE. Four years across governance & risk, security operations, application security and incident response, inside regulated financial services.
Everything about me is on this machine, but most of it is encrypted. Tools:
======================================================= SENIOR SECURITY ENGINEER Interland Technology Services Pvt. Ltd. (Alfaris Group) Thiruvananthapuram, India Aug 2022 - Jun 2026 ======================================================= [01] GOVERNANCE, RISK & COMPLIANCE Led end-to-end ISO 27001 certification - ISMS scope, risk assessment and treatment, Statement of Applicability, control design and evidence - and owned SAMA and NCA compliance for a financial product. Translated regulatory clauses into measurable IT general controls, maintained as a control-to-requirement matrix. [02] AUDIT MANAGEMENT Managed internal audits, external ISO 27001 certification and recurring client-side regulatory audits by tier-1 bank customers (Al Rajhi Bank, D360 Bank, Vision Bank, ezbank (Ajlan), Bank of Jordan). >> 100% pass rate, zero critical findings. [03] SIEM ARCHITECTURE & SECURITY OPERATIONS Designed, deployed and operated a production Wazuh/ OpenSearch SIEM with high-volume ingestion (ClickHouse, Vector), Suricata IDS/IPS and Falco runtime detection, with TheHive for case management. Authored and tuned custom detection rules. Streamlined SOC workflows with Ansible Semaphore and GLPI. >> Mean time to detect reduced by 42%. [04] AI-DRIVEN SECURITY AUTOMATION Deployed and configured openappsec, an AI/ML-based web application firewall delivering automated, self-learning detection and blocking of OWASP Top 10 attacks with no manual rule tuning. Integrated LLM-based AI agents (including Hermes) for intelligent log analysis, anomaly detection and automated security checks inside CI/CD. [05] INCIDENT RESPONSE Owned incidents through the full lifecycle - detection, triage, containment, eradication, recovery - as senior escalation point, followed by root cause analysis and preventive control changes. Documented every incident to audit standard. [06] PENETRATION TESTING & VULN MANAGEMENT Performed web, API and network penetration testing against OWASP Top 10 - SQL injection, IDOR, SSRF, broken authentication, account takeover - with Burp Suite and Nmap. Integrated Trivy and Bearer into GitLab CI/CD. >> 1,200+ vulns to verified closure, 48h SLA. [07] DEVSECOPS & SECURE SDLC Built shift-left security pipelines in GitLab CI/CD - SonarQube (SAST), Trivy and Bearer as enforced gates across Java Spring Boot and Angular applications - with code-level review and developer coaching. [08] NETWORK, CLOUD & IDENTITY SECURITY Configured Fortinet and Palo Alto firewalls and an AI/ML WAF. Secured 30+ Kubernetes pods with Falco and container hardening. Implemented Zitadel SSO (OIDC/OAuth 2.0) across 15+ applications. Deployed Netbird Zero Trust segmentation. >> 95% of credential attack surface eliminated. [09] INFRASTRUCTURE MONITORING & ASSETS Deployed Zabbix and Grafana for unified visibility, and Snipe-IT for complete asset inventory and vulnerability mapping. [10] ENABLEMENT & STAKEHOLDER COMMS Ran security awareness and ISMS training across departments. Briefed engineering and business leadership by translating technical risk into business impact. -- EOF --
> 2 RECORDS — BOTH RESPONSIBLY DISCLOSED, BOTH REMEDIATED
| TARGET | UK Government Beverages Agency |
|---|---|
| VECTOR | Time-based blind SQL injection |
| YIELD | 30,000+ customer records |
| AGGRAVATING | Passwords stored in plaintext |
| DISPOSITION | Disclosed — remediation coordinated with the agency |
| TARGET | Noise India |
|---|---|
| VECTOR | Password reset flaw |
| YIELD | Full account takeover, any user |
| DISPOSITION | Reported to vendor — fixed |
> OPEN TO SENIOR SECURITY ROLES — UAE & WIDER GCC
On-site, hybrid or remote. Cybersecurity engineering, SOC leadership, application security, GRC.
Arrow keys or WASD. Eat the packets, don't hit the firewall.
Click to scan. Right-click (or long-press) to quarantine.
A 4-digit code guards the mainframe. Digits 0-9, no repeats. Per guess: ■ right digit right slot · □ right digit wrong slot.
> OPERATING THIS RIG
> DROP CARRIER?
This kills the connection and gives you an honest 1995 disconnect screen. There's a REDIAL button, don't panic.