Skip to content
View imraneggy's full-sized avatar
🎯
Focusing
🎯
Focusing

    Block or report imraneggy

    Block user

    Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

    You must be logged in to block users.

    Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
    Report abuse

    Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

    Report abuse
    imraneggy/README.md
    Typing SVG

    Profile ViewsCISMExperienceOpen to Work


    About Me

    AI Security Engineer and Cloud Security Architect with 8+ years in enterprise cybersecurity — spanning XDR deployment, Zero Trust architecture, CNAPP governance, and AI platform engineering.

    I design and build production AI-powered cybersecurity platforms at $0 cloud cost using local LLMs, edge computing, agentic AI orchestration, and serverless edge primitives. Six production AI security platforms shipped solo — spanning multi-VM on-prem SOC, autonomous pentest (x86 + Jetson edge), agentic GRC, multi-agent personal AI, and serverless security awareness — plus a public Android fintech project. Zero vendor lock-in. Consistent multi-agent + policy-gate architecture pattern proven across enterprise, edge, and personal-scale deployments.

    RoleAI Security Engineer · Cloud Security Architect · Production AI Platform Architect
    CertificationsCISM · CISSP (In Progress) · OCI Multicloud Architect · OCI Gen AI Professional · OCI AI Foundations · AZ-900 · Cisco Ethical Hacker · Cisco Cybersecurity Analyst · Cisco Network Defense · Cisco Endpoint Security · CWHH · C-WAST
    EducationM.Sc. Cyber Forensics & Information Security — First Class (76%)
    SpecialisationXDR · CNAPP · Zero Trust · CTEM · Purple Teaming · ITDR & Non-Human Identity Security · AI-SPM · Agentic AI Security · Multi-Agent Orchestration · Voice AI · Edge Compute · Serverless Security · AI Red Teaming · DevSecOps · GRC Automation
    FrameworksNIST CSF 2.0 · ISO 27001:2022 · ISO/IEC 42001:2023 (AI Management System) · MITRE ATT&CK · CIS v8 · OWASP · MASVS L1 · GDPR · NIS2 · DORA · SAMA · EU AI Act
    LanguagesEnglish (Professional) · Tamil (Native) · Hindi (Conversational) · Arabic (Basic)

    Key Achievements

    CapabilityImpactDetails
    AI Security Platforms$200K+/yr savedBuilt autonomous pentest platform replacing commercial VAPT — Dockerized, hardened, governance-ready
    XDR Deployment45% faster MTTDUnified endpoint, network, email, and cloud telemetry with automated correlation
    SOAR Automation50% less triagePlaybook-driven response with MITRE ATT&CK mapping
    Cloud Security (CNAPP)30% fewer CVEsMulti-cloud posture management with custom compliance queries mapped to CIS v8
    Zero Trust Architecture50% fewer breachesConditional Access + PAM + ZTNA across hybrid infrastructure
    DevSecOps70% less driftShift-Left security embedded in CI/CD pipelines
    Attack Surface Management60% more visibilityDiscovered 320+ shadow IT assets across enterprise environments
    ISO 27001 CertificationZero non-conformitiesLed full certification cycle — policy authoring through external audit
    Best PerformerFY 2022-2023Recognised for exceptional contributions to cybersecurity excellence and innovation
    Phishing Response40% faster SLAAI-powered email security analytics and automated SOAR incident response
    Alert Noise Reduction35% less noiseIntelligent XDR detection rule tuning improving SOC analyst productivity
    Attack Surface Reduction20% reducedComprehensive VAPT identifying and remediating OWASP Top 10 vulnerabilities

    Core Expertise

    Security Operations & Architecture

    • XDR/EDR — Trend Micro Vision One + Microsoft Defender XDR (MDE/MDO/MDI/MDCA), unified endpoint/network/email/cloud telemetry
    • SIEM & SOC Automation — Microsoft Sentinel (KQL, analytics & automation rules, UEBA) within Unified SecOps · SOC L2/L3 incident response
    • AI-Assisted SOC — Microsoft Security Copilot–driven agentic triage & incident summarisation
    • CNAPP — Cloud-native posture management with custom compliance policies (Palo Alto Prisma Cloud)
    • Zero Trust & ITDR — Conditional Access, PAM governance, ZTNA, micro-segmentation, Non-Human Identity Security
    • SOAR & Purple Teaming — Automated playbooks with MITRE ATT&CK correlation and adversary-emulation validation
    • NAC — Network access control and micro-segmentation at enterprise scale (FortiNAC)
    • CTEM/ASM — Continuous threat exposure & attack surface management, shadow IT discovery
    • VAPT — Vulnerability assessment and penetration testing (Burp Suite, Nmap, Nuclei, SQLMap)

    AI Engineering & Platform Development

    • Local LLMs — llama.cpp, Ollama, GGUF model deployment on edge hardware
    • Agentic AI — Multi-agent orchestration with LangChain, LangGraph, ReAct patterns
    • RAG Pipelines — ChromaDB/Qdrant vector search for policy/compliance knowledge retrieval
    • Edge AI — NVIDIA Jetson deployment for air-gapped, offline-capable inference
    • AI-SPM & AI Red Teaming — OWASP LLM Top 10, prompt-injection defence, LLM guardrails (NeMo/Llama Guard)
    • AI Governance — EU AI Act readiness, ISO/IEC 42001:2023 AI Management System, NIST AI RMF
    • Full-Stack — Python (FastAPI, Flask), React 18, PostgreSQL, Redis, SQLite
    • Docker & DevSecOps — Container hardening, CI/CD security, Shift-Left practices, supply-chain (SLSA/SBOM/AIBOM)
    • Multi-Cloud — AWS, Azure, OCI, GCP, Cloudflare — architecture, security, and governance
    • Cryptography — Post-Quantum Cryptography (FIPS 203/204/205) readiness
    • AI-Assisted Dev — Claude Code, OpenAI Codex, Google AI Studio, NotebookLM

    Now

    • 🚀 Shipping Transfer Rate (personal R&D, MIT licensed, live on Google Play + F-Droid) — Android remittance + precious-metals rate aggregator · 13 verified providers across 10 currency corridors vs. a live Google Finance mid-market benchmark · gold & silver "what this buys" purchasing calculator · ~3.4 MB universal APK, zero native deps · Releases · Technical report
    • 📡 Shipping CyberBriefs — Serverless security-awareness distribution · multi-LLM fallback · Cloudflare Worker Telegram approval webhook · Instagram Graph API idempotent publish · $0/month
    • 🛠 Maintaining 6 production AI security platforms in private repos (multi-VM on-prem SOC · autonomous pentest x86+Jetson edge · agentic GRC · CISO threat intel · multi-agent cloud+on-device assistant) — code walkthroughs + live demos available on request
    • 🎯 Open to: Senior AI Security Engineer / Cloud Security Architect / GenAI Security roles — Remote (Global) & Relocation
    • 🌏 Locations: UAE (immediate joiner) · GCC · Singapore · Australia · Canada · Germany · Netherlands · USA — H-1B / EU Blue Card / GCC / SG EP sponsorship welcome

    Languages

    • English — Professional working proficiency
    • Tamil — Native
    • Hindi — Conversational
    • Arabic — Basic (UAE workplace)

    Flagship AI Security Projects

    1. SOC-PC1 — Production On-Prem AI Security Platform

    Single-host enterprise SOC platform — 4-VM micro-isolated, AI-orchestrated, $0 cloud cost

    ┌──────────────────────────────────────────────────────────────────────────┐
    │ MISSION On-prem SOC operations + autonomous pentest at enterprise │
    │ scale, fully air-gapped scan plane, zero vendor licensing │
    ├──────────────────────────────────────────────────────────────────────────┤
    │ Hardware HP DL380p Gen8 — 48 vCPU / 251 GB RAM / single-host KVM │
    │ Topology 4 VMs on libvirt mgmt-net + dedicated air-gap subnet │
    │ vm-pentest · vm-ops · vm-edge · vm-cyberdash │
    │ Edge Caddy reverse proxy → 5 vhosts · Authelia 2FA TOTP + │
    │ group-based ACL · WireGuard remote access │
    │ Compute 30+ services across 11 docker-compose stacks · │
    │ healthchecks · restart policies · 50 iptables FORWARD/INPUT │
    │ AI Stack LangGraph multi-agent observability with T0–T3 policy gates │
    │ qwen2.5:3b triage + qwen3-30b-a3b reason · age-encrypted env │
    │ Pentest Nmap · Nikto · Nuclei · Sqlmap · Katana + MobSF · APKiD · │
    │ JADX · APKLeaks · trufflehog · lief — orchestrated dispatch │
    │ Data 692 production scans · pentest.db (SQLite WAL) · 346K CVE │
    │ records (NVD + CISA KEV + EPSS) · Qdrant RAG (OWASP corpus) │
    │ Observ. Prometheus · Alertmanager · Grafana · Loki · cAdvisor · │
    │ Telegram alerts · daily LLM-rendered digest │
    │ Reliable 10 systemd watchdogs (5-min sweep, idempotent) · │
    │ 38-section as-built v1.4 · 11-scenario operator runbook · │
    │ cockpit auto-recover · libvirt snapshot before risky ops │
    │ Security 15-min sliding session · MASVS rollup mobile compliance · │
    │ air-gapped scan-plane (iptables FORWARD/INPUT drops) · │
    │ role-based RBAC (admin / viewer / bot) │
    │ Backup Off-host backup → private GitHub (configs + 7.5 MB DB.gz) │
    ├──────────────────────────────────────────────────────────────────────────┤
    │ IMPACT Replaces commercial VAPT + SIEM stack · $0 cloud cost · │
    │ 33-component health-check green · documented runbook + │
    │ as-built v1.4 · DR-restorable from off-host backup (DB+cfg) │
    └──────────────────────────────────────────────────────────────────────────┘
    

    Linux MintKVMlibvirtCaddyAutheliaWireGuardPrometheusGrafanaLokiOllamaLangGraphQdrantMobSF


    2. Edge Pentest Appliance — NVIDIA Jetson AI Security Platform

    Field-deployable autonomous AI pentest platform — network + mobile APK security, 100% on-device inference, production Docker deployment with full security hardening

    ┌──────────────────────────────────────────────────────────────────────────┐
    │ MISSION AI-orchestrated autonomous pentesting + governance reporting │
    ├──────────────────────────────────────────────────────────────────────────┤
    │ AI Core Local llama.cpp (Qwen2.5-3B GGUF) + OpenAI analysis │
    │ Hardware NVIDIA Jetson Orin Nano 8GB — fully air-gapped, edge-native │
    │ Deploy Docker Compose — non-root container, hardened, single cmd │
    │ Network Katana · Nikto · Nuclei · SQLMap · Nmap — AI-orchestrated │
    │ Mobile androguard · apktool · APKLeaks · JADX — APK static analysis│
    │ Backend Python FastAPI · Uvicorn · SQLite · CPU/RAM-aware dispatch │
    │ Frontend Vanilla HTML/CSS/JS · admin controls · bulk CSV/TXT import │
    │ Reports Executive · Technical · Compliance · Mobile Assessment │
    │ ISO 27001 · SOC 2 · NIST CSF · OWASP · CIS · regional cybersecurity standards │
    │ Mobile OWASP MASVS L1 compliance · Mobile Top 10 (2024) mapping │
    │ Report Sectoral compliance · ISO 27001 framework cross-reference │
    │ Severity-coded finding cards · remediation roadmap · PDF │
    │ Security Login rate limiting · nmap script whitelist · XSS hardened │
    │ Step-up auth (all users) · CSP · CORS · audit trail export │
    │ Non-root container · cap_drop ALL · read-only filesystem │
    │ Auto-generated admin password · no hardcoded credentials │
    ├──────────────────────────────────────────────────────────────────────────┤
    │ IMPACT 53 FastAPI endpoints · ~25K LOC across 17 modules · │
    │ 5,059-LOC reporting engine · 22 governance templates · │
    │ 5 network + 4 mobile tools · 100% offline-capable · │
    │ air-gap fonts (IBM Plex, JetBrains Mono) · zero vendor cost │
    └──────────────────────────────────────────────────────────────────────────┘
    

    PythonFastAPIDockerSQLiteOpenAIllama.cppNVIDIAPlaywrightOWASP


    3. AI Cybersecurity Intelligence Dashboard

    Local-first C-Suite intelligence platform — $0 cloud LLM cost

    ┌──────────────────────────────────────────────────────────────────────────┐
    │ MISSION AI-powered executive cyber intelligence + SOC operations │
    ├──────────────────────────────────────────────────────────────────────────┤
    │ AI Core Ollama local LLM (llama3.2:1b) + grounded prompt pipeline │
    │ Agents Hybrid agentic orchestration — context/draft/finalize/ │
    │ policy/verification with optional LangChain composition │
    │ Frontend React 18 + GeoPulse Atlas (Leaflet) + KPI snapshots + │
    │ 30-day AI intel chat + Spline 3D splash UX │
    │ Backend Python Flask (2,804-LOC routes.py · 34 endpoints) · │
    │ 27 modules · 420 KB backend · SQLAlchemy · PostgreSQL · Redis│
    │ Bot Telegram (95 KB) — interactive editorial workflow │
    │ Workflow Admin curation → AI draft → Telegram edit → publish │
    │ Live Map Leaflet + Check Point ThreatMap stream · 64-point bezier │
    │ arcs · antimeridian handling · 8s refresh · live-only │
    │ Sources 20+ RSS feeds · SHA-256 dedup · EV/automotive scoring boost │
    │ Workflow 05:45 Asia/Dubai cron → Telegram preview → CISO approval → │
    │ top 5 surface on dashboard · 30-day retention · MCP server │
    │ Integr. n8n automation · Docker Compose · Nginx │
    ├──────────────────────────────────────────────────────────────────────────┤
    │ IMPACT $0 cloud cost · privacy-preserving · daily C-suite briefings│
    └──────────────────────────────────────────────────────────────────────────┘
    

    ReactFlaskPostgreSQLRedisOllamaDockerNginx


    4. ARIA — AI IT Policy Manager

    Multi-agent GRC automation platform — RAG-powered compliance governance

    ┌──────────────────────────────────────────────────────────────────────────┐
    │ MISSION Automated IT policy generation, review, and compliance │
    │ governance for enterprise organisations │
    ├──────────────────────────────────────────────────────────────────────────┤
    │ AI Core Ollama local LLM + ChromaDB RAG (vector similarity search) │
    │ Agents 4 specialised agents · 6 streaming SSE workflows │
    │ (chat · generate · finalize · revise · review · renew) │
    │ Autonomous Monitor — APScheduler 6-hour cycle · │
    │ 8 regulatory domains via DuckDuckGo │
    │ Backend Python FastAPI · Uvicorn · ChromaDB · LangChain │
    │ Frontend Next.js 16 + React 19 + TypeScript 5 + Tailwind CSS 4 │
    │ SSE streaming · token-by-token generation · inline editor │
    │ Coverage UAE NESA · ISO 27001:2022 · UAE PDPL · NIST CSF 2.0 · │
    │ CIS Controls v8 · ADDA · UAE Cybersecurity Law │
    │ Output Policy drafts · compliance scorecards · gap analysis │
    ├──────────────────────────────────────────────────────────────────────────┤
    │ IMPACT Automated GRC governance · audit-ready output · $0 cost │
    └──────────────────────────────────────────────────────────────────────────┘
    

    FastAPIReactChromaDBLangChainOllama


    5. EVA — Agentic Privacy-First AI Security Platform (Cloud + Edge)

    Dual-deployment multi-agent security platform — Cloudflare Workers cloud variant (6-provider LLM cascade, OAuth 2.0/OIDC + MCP client hardening) paired with an air-gapped, privacy-preserving on-device variant — 6 sub-agents · 17+ tools · 4-tier approval gate · encrypted at rest

    The on-device variant below is one half of a dual cloud-edge architecture. The companion cloud variant is a TypeScript / Cloudflare Workers AI security reference build featuring a 6-provider LLM cascade with automatic failover, OAuth 2.0/OIDC + MCP client hardening, and the same 4-tier policy-gate pattern — demonstrating architectural fluency from zero-egress edge to serverless cloud.

    ┌──────────────────────────────────────────────────────────────────────────┐
    │ MISSION Multi-agent personal AI platform with zero cloud egress, │
    │ voice-activated, encrypted at rest, mobile-accessible │
    ├──────────────────────────────────────────────────────────────────────────┤
    │ AI Core Ollama 72B Master Orchestrator routing to specialised agents│
    │ Agents 6 sub-agents (Code · Comms · File · Privacy · System · Web)│
    │ inheriting from BaseAgent abstract — same pattern proven │
    │ in the enterprise multi-VM SOC platform │
    │ Tools 17+ platform-aware tools — filesystem · shell · browser · │
    │ git · email · screenshot · clipboard · web search │
    │ Policy 4-tier approval gate (Auto → Notify → Confirm → Restricted)│
    │ directly parallel to enterprise T0–T3 policy engine │
    │ Memory ChromaDB vector store · long-term episodic memory · RAG │
    │ Vault SQLCipher AES-256 encrypted personal data store │
    │ Voice Wake-word ("Hey EVA") → Whisper STT → LLM → Piper TTS │
    │ Frontend React 19 + WebSocket bidirectional streaming · PWA mobile │
    │ Access Tailscale Zero Trust Network · cross-platform (Linux+Win) │
    ├──────────────────────────────────────────────────────────────────────────┤
    │ IMPACT Demonstrates Responsible AI deployment · zero-trust local- │
    │ first architecture · multi-agent orchestration pattern │
    │ portable from enterprise scale down to single-device │
    └──────────────────────────────────────────────────────────────────────────┘
    

    PythonFastAPIOllamaChromaDBSQLCipherReactWhisperPiperTailscale


    6. CyberBriefs — Serverless Security-Awareness Distribution Platform

    Public OSS · $0/month operating cost · multi-LLM provider abstraction · Cloudflare Worker edge approval webhook · Instagram Graph API idempotent publish

    ┌──────────────────────────────────────────────────────────────────────────┐
    │ MISSION Daily cybersecurity awareness content generation, human-in- │
    │ the-loop approval, and idempotent multi-platform publish │
    │ at near-zero ongoing cost │
    ├──────────────────────────────────────────────────────────────────────────┤
    │ Cron 2× daily via GitHub Actions scheduled workflows │
    │ (morning + evening) · pipeline tests · auto-deploy Worker │
    │ AI Core Multi-LLM provider abstraction layer · hot-swap across │
    │ OpenAI · Groq · HuggingFace · GitHub Models · Cloudflare AI│
    │ · Pollinations — no single-vendor lock-in │
    │ Approval Cloudflare Worker Telegram webhook · secret-token auth · │
    │ inline approval keyboards · idempotent publish guard │
    │ (replay/double-click safe) │
    │ Publish Instagram Graph API · single image + CAROUSEL_ALBUM (2–10 │
    │ slide carousel for 3–5× engagement uplift) │
    │ Storage Public GitHub repo (no-credit-card image hosting) · │
    │ optional Cloudflare R2 upgrade path │
    │ Content 100+ curated cybersecurity topics — 50+ days of fresh │
    │ content runway · composite-image generator with typography │
    │ Supply Third-party Actions pinned by full commit SHA │
    ├──────────────────────────────────────────────────────────────────────────┤
    │ IMPACT Demonstrates edge-native security-awareness scaling · zero-│
    │ vendor-cost content pipeline · directly applicable to │
    │ enterprise security-awareness programmes │
    └──────────────────────────────────────────────────────────────────────────┘
    

    CyberBriefs Public RepoPythonCloudflareGitHub ActionsTelegramInstagram


    Public Open-Source Repositories

    • transfer-rate — Transfer Rate Android app source (Kotlin · Jetpack Compose · Material 3 · 13 verified providers across 10 currency corridors · gold & silver purchasing calculator · ~3.4 MB zero-native-dep APK · $0 ops). MIT licensed, personal R&D, live on Google Play + F-Droid.
    • Cyberbriefs — Serverless cybersecurity awareness content engine (described above)

    Tech Stack

    Cybersecurity Platforms

    Vision One XDRMicrosoft SentinelDefender XDRSecurity CopilotPrisma CloudFortiNACArcon PAMBurp SuiteNmapNucleiSQLMap

    AI / LLM / Agentic AI

    Claude AIOpenAIOllamaLangChainLangGraphChromaDBspaCyNVIDIAAnthropicscikit-learn

    Cloud Security

    AWSAzureOCIGCP

    Development & Infrastructure

    PythonReactFlaskFastAPIDockerKubernetesPostgreSQLRedisTerraformn8nNginxPlaywrightSeleniumViteStreamlit

    Compliance & Governance

    ISO 27001NISTMITRECISOWASPRegional ComplianceGDPRNIS2DORAEU AI ActISO 42001Post-Quantum


    Certifications

    CertificationIssuerYear
    CISM — Certified Information Security ManagerISACA2026
    CISSP — Certified Information Systems Security ProfessionalISC2In Progress
    ☁️OCI Generative AI ProfessionalOracle2025
    ☁️OCI Multicloud Architect ProfessionalOracle2025
    🤖OCI AI Foundations AssociateOracle2025
    ☁️OCI Foundations AssociateOracle2025
    🪟AZ-900 — Azure FundamentalsMicrosoft2024
    🔓CWHH — Certified White Hat Hacker (L1 & L2)2023
    🔓C-WAST — Certified Web Application Security Tester2023
    🌐Certified Ethical HackerCisco
    🌐Certified Cybersecurity AnalystCisco
    🌐Certified Network Defense SpecialistCisco
    🌐Certified Endpoint Security SpecialistCisco
    📋ISMS Trained Auditor — ISO/IEC 27001:20222022

    GitHub Statistics

    GitHub Streak
    Contribution Activity

    Philosophy

    "The best security system is one that is invisible, intelligent, and costs nothing to run.AI is the key that makes all three possible — simultaneously."


    Connect

    GitHubLinkedInEmail


    CISM · M.Sc. Cyber Forensics & Information Security


    Popular repositories Loading

    1. imraneggy imraneggyPublic

      AI Security Engineer | Cloud Security Architect | CISM | 7+ Years Enterprise Security | XDR | CNAPP | Zero Trust | DevSecOps | AI Platform Builder | Open to Opportunities

    2. claude-plugins-official claude-plugins-officialPublic

      Forked from anthropics/claude-plugins-official

      Official, Anthropic-managed directory of high quality Claude Code Plugins.

      Python

    3. awesome-claude-skills awesome-claude-skillsPublic

      Forked from travisvn/awesome-claude-skills

      A curated list of awesome Claude Skills, resources, and tools for customizing Claude AI workflows — particularly Claude Code

    4. awesome-claude-skillss awesome-claude-skillssPublic

      Forked from ComposioHQ/awesome-claude-skills

      A curated list of awesome Claude Skills, resources, and tools for customizing Claude AI workflows

      Python

    5. claude-code-templates claude-code-templatesPublic

      Forked from davila7/claude-code-templates

      CLI tool for configuring and monitoring Claude Code

      Python

    6. awesome-agent-skills awesome-agent-skillsPublic

      Forked from VoltAgent/awesome-agent-skills

      Claude Code Skills and 1000+ agent skills from official dev teams and the community, compatible with Codex, Antigravity, Gemini CLI, Cursor and others.