Skip to content
View imraneggy's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report imraneggy

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
imraneggy/README.md
Typing SVG

Profile Views   CISM   Experience   Open to Work


About Me

AI Security Engineer and Cloud Security Architect with 7+ years in enterprise cybersecurity — spanning XDR deployment, Zero Trust architecture, CNAPP governance, and AI platform engineering.

I design and build production AI-powered cybersecurity platforms at $0 cloud cost using local LLMs, edge computing, and agentic AI orchestration. Five production platforms shipped. Zero vendor lock-in.

Role AI Security Engineer · Cloud Security Architect
Certifications CISM · OCI Multicloud Architect · OCI Gen AI Professional · OCI AI Foundations · AZ-900 · Cisco Ethical Hacker · Cisco Cybersecurity Analyst · Cisco Network Defense · Cisco Endpoint Security · CWHH · C-WAST
Education M.Sc. Cyber Forensics & Information Security
Specialisation XDR · CNAPP · Zero Trust · CTEM · AI Red Teaming · DevSecOps · GRC Automation
Frameworks NIST CSF 2.0 · ISO 27001:2022 · MITRE ATT&CK · CIS v8 · OWASP · NESA · GDPR · NIS2 · DORA

Key Achievements

Capability Impact Details
AI Security Platforms $200K+/yr saved Built autonomous pentest platform replacing commercial VAPT — Dockerized, hardened, governance-ready
XDR Deployment 45% faster MTTD Unified endpoint, network, email, and cloud telemetry with automated correlation
SOAR Automation 50% less triage Playbook-driven response with MITRE ATT&CK mapping
Cloud Security (CNAPP) 30% fewer CVEs Multi-cloud posture management with custom compliance queries mapped to CIS v8
Zero Trust Architecture 50% fewer breaches Conditional Access + PAM + ZTNA across hybrid infrastructure
DevSecOps 70% less drift Shift-Left security embedded in CI/CD pipelines
Attack Surface Management 60% more visibility Discovered 320+ shadow IT assets across enterprise environments
ISO 27001 Certification Zero non-conformities Led full certification cycle — policy authoring through external audit
Best Performer FY 2022-2023 Recognised for exceptional contributions to cybersecurity excellence and innovation
Phishing Response 40% faster SLA AI-powered email security analytics and automated SOAR incident response
Alert Noise Reduction 35% less noise Intelligent XDR detection rule tuning improving SOC analyst productivity
Attack Surface Reduction 20% reduced Comprehensive VAPT identifying and remediating OWASP Top 10 vulnerabilities

Core Expertise

Security Operations & Architecture

  • XDR/EDR — Unified telemetry across endpoint, network, email, cloud (Trend Micro Vision One)
  • CNAPP — Cloud-native posture management with custom compliance policies (Palo Alto Prisma Cloud)
  • Zero Trust — Conditional Access, PAM governance, ZTNA, micro-segmentation
  • SOAR — Automated playbooks with MITRE ATT&CK correlation
  • SIEM — Cross-layer detection engineering, alert tuning, false positive reduction
  • NAC — Network access control and micro-segmentation at enterprise scale (FortiNAC)
  • ASM — Attack surface discovery, shadow IT identification, exposure management
  • VAPT — Vulnerability assessment and penetration testing (Burp Suite, Nmap, Nuclei, SQLMap)

AI Engineering & Platform Development

  • Local LLMs — llama.cpp, Ollama, GGUF model deployment on edge hardware
  • Agentic AI — Multi-agent orchestration with LangChain, LangGraph, ReAct patterns
  • RAG Pipelines — ChromaDB vector search for policy/compliance knowledge retrieval
  • Edge AI — NVIDIA Jetson deployment for air-gapped, offline-capable inference
  • Full-Stack — Python (FastAPI, Flask), React 18, PostgreSQL, Redis, SQLite
  • Docker & DevSecOps — Container hardening, CI/CD security, Shift-Left practices
  • Multi-Cloud — AWS, Azure, OCI, GCP — architecture, security, and governance
  • GRC Automation — ISO 27001, NIST CSF, CIS v8, OWASP, NESA, GDPR, NIS2, DORA
  • AI-Assisted Dev — Claude Code, OpenAI Codex, Google AI Studio, NotebookLM
  • Testing & Automation — Playwright E2E, Selenium CDP, pytest, CI/CD pipelines

Flagship AI Security Projects

1. Autonomous Penetration Testing Platform

Edge-deployed AI pentest platform — production Docker deployment with full security hardening

┌──────────────────────────────────────────────────────────────────────────┐
│  MISSION   AI-orchestrated autonomous pentesting + governance reporting │
├──────────────────────────────────────────────────────────────────────────┤
│  AI Core   Local llama.cpp (Qwen2.5-3B GGUF) + OpenAI analysis        │
│  Hardware  NVIDIA Jetson Orin Nano 8GB — fully air-gapped, edge-native │
│  Deploy    Docker Compose — non-root container, hardened, single cmd   │
│  Tools     Katana · Nikto · Nuclei · SQLMap · Nmap — AI-orchestrated   │
│  Backend   Python FastAPI · Uvicorn · SQLite · CPU/RAM-aware dispatch  │
│  Frontend  Vanilla HTML/CSS/JS · admin controls · bulk CSV/TXT import  │
│  Reports   Executive · Technical · Compliance (ISO 27001 · SOC 2 ·     │
│            NIST CSF · OWASP · CIS · UAE-IA · NESA)                     │
│  Security  Login rate limiting · nmap script whitelist · XSS hardened  │
│            Step-up auth (all users) · CSP · CORS · audit trail export  │
│            Non-root container · cap_drop ALL · read-only filesystem    │
│            Auto-generated admin password · no hardcoded credentials    │
├──────────────────────────────────────────────────────────────────────────┤
│  IMPACT    100% offline-capable · governance-ready · zero vendor cost  │
└──────────────────────────────────────────────────────────────────────────┘

Python FastAPI Docker SQLite OpenAI llama.cpp NVIDIA


2. AI Cybersecurity Intelligence Dashboard

Local-first C-Suite intelligence platform — $0 cloud LLM cost

┌──────────────────────────────────────────────────────────────────────────┐
│  MISSION   AI-powered executive cyber intelligence + SOC operations     │
├──────────────────────────────────────────────────────────────────────────┤
│  AI Core   Ollama local LLM (llama3.2:1b) + grounded prompt pipeline   │
│  Agents    Hybrid agentic orchestration — context/draft/finalize/       │
│            policy/verification with optional LangChain composition      │
│  Frontend  React 18 + GeoPulse Atlas (Leaflet) + KPI snapshots +       │
│            30-day AI intel chat + Spline 3D splash UX                   │
│  Backend   Python Flask · SQLAlchemy · PostgreSQL · Redis               │
│  Workflow  Admin curation → AI draft → Telegram edit → publish          │
│  Integr.   MCP fetch proxy · n8n automation · Docker Compose · Nginx   │
├──────────────────────────────────────────────────────────────────────────┤
│  IMPACT    $0 cloud cost · privacy-preserving · daily C-suite briefings│
└──────────────────────────────────────────────────────────────────────────┘

React Flask PostgreSQL Redis Ollama Docker Nginx


3. ARIA — AI IT Policy Manager

Multi-agent GRC automation platform — RAG-powered compliance governance

┌──────────────────────────────────────────────────────────────────────────┐
│  MISSION   Automated IT policy generation, review, and compliance      │
│            governance for enterprise organisations                      │
├──────────────────────────────────────────────────────────────────────────┤
│  AI Core   Ollama local LLM + ChromaDB RAG (vector similarity search)  │
│  Agents    3 specialised agents — ARIA Expert · Policy Writer ·         │
│            Compliance Auditor (LangChain multi-agent orchestration)     │
│  Backend   Python FastAPI · Uvicorn · ChromaDB · LangChain             │
│  Frontend  React 18 + real-time streaming chat + policy editor          │
│  Coverage  UAE NESA · ISO 27001:2022 · UAE PDPL · NIST CSF 2.0 ·       │
│            CIS v8 · GDPR · NIS2 · DORA · OWASP                        │
│  Output    Policy drafts · compliance scorecards · gap analysis         │
├──────────────────────────────────────────────────────────────────────────┤
│  IMPACT    Automated GRC governance · audit-ready output · $0 cost     │
└──────────────────────────────────────────────────────────────────────────┘

FastAPI React ChromaDB LangChain Ollama


5. AI Job Application Bot

Autonomous multi-platform job application system — 14 platforms, 10 auto-apply plugins, dual browser engines

+--------------------------------------------------------------------------+
|  MISSION   Autonomous job discovery, AI matching, and application        |
+--------------------------------------------------------------------------+
|  AI Core   Ollama (primary) + Anthropic Claude (fallback) + spaCy NLP   |
|  Matching  spaCy NLP + scikit-learn skill matching (0-100 scoring)      |
|  Q and A   3-tier: Deterministic then Template then LLM                 |
|  Scrapers  14 platforms: LinkedIn, SEEK, JobsDB, Indeed, Bayt,          |
|            NaukriGulf, Glassdoor, Greenhouse, Lever, Dice,               |
|            Monster, Google Jobs, JapanDev                                |
|  Apply     10 auto-apply plugins with Playwright + Selenium CDP         |
|  Stealth   Anti-detection: fingerprint rotation, human simulation,      |
|            80-250ms typing, 8-25 min random delays between applies      |
|  Frontend  React 18 + Vite + TypeScript + Tailwind dashboard            |
|  Backend   FastAPI + SQLAlchemy + APScheduler + Streamlit monitoring    |
|  Control   Telegram bot: /status /applied /pause /resume /help          |
|  Security  AES-256 encrypted credentials, per-platform session mgmt    |
|  Testing   8 pytest suites: DB, matcher, Q and A, cover letter, e2e    |
|  Regions   6: Australia, Singapore, Canada, GCC, US, Japan              |
+--------------------------------------------------------------------------+
|  IMPACT    42K LOC, zero cloud cost, regional cover letter generation   |
+--------------------------------------------------------------------------+

Python Playwright Selenium Ollama Anthropic spaCy React Vite FastAPI Telegram


Tech Stack

Cybersecurity Platforms

Vision One XDR Prisma Cloud FortiNAC Arcon PAM Burp Suite Nmap Nuclei SQLMap

AI / LLM / Agentic AI

Claude AI OpenAI Ollama LangChain LangGraph ChromaDB spaCy NVIDIA Anthropic scikit-learn

Cloud Security

AWS Azure OCI GCP

Development & Infrastructure

Python React Flask FastAPI Docker Kubernetes PostgreSQL Redis Terraform n8n Nginx Playwright Selenium Vite Streamlit

Compliance & Governance

ISO 27001 NIST MITRE CIS OWASP UAE NESA GDPR NIS2 DORA


Certifications

Certification Issuer Year
CISM — Certified Information Security Manager ISACA 2026
☁️ OCI Generative AI Professional Oracle 2025
☁️ OCI Multicloud Architect Professional Oracle 2025
🤖 OCI AI Foundations Associate Oracle 2025
☁️ OCI Foundations Associate Oracle 2025
🪟 AZ-900 — Azure Fundamentals Microsoft 2024
🔓 CWHH — Certified White Hat Hacker (L1 & L2) 2023
🔓 C-WAST — Certified Web Application Security Tester 2023
📋 ISMS Trained Auditor — ISO/IEC 27001:2022 2022
🌐 CCNA — Cisco Certified Network Associate Cisco 2021

GitHub Statistics

GitHub Streak
Contribution Activity

Philosophy

"The best security system is one that is invisible, intelligent, and costs nothing to run. AI is the key that makes all three possible — simultaneously."


Connect

GitHub


CISM · M.Sc. Cyber Forensics & Information Security


Popular repositories Loading

  1. imraneggy imraneggy Public

    AI Security Engineer | Cloud Security Architect | CISM | 7+ Years Enterprise Security | XDR | CNAPP | Zero Trust | DevSecOps | AI Platform Builder | Open to Opportunities

  2. claude-plugins-official claude-plugins-official Public

    Forked from anthropics/claude-plugins-official

    Official, Anthropic-managed directory of high quality Claude Code Plugins.

    Python

  3. awesome-claude-skills awesome-claude-skills Public

    Forked from travisvn/awesome-claude-skills

    A curated list of awesome Claude Skills, resources, and tools for customizing Claude AI workflows — particularly Claude Code

  4. awesome-claude-skillss awesome-claude-skillss Public

    Forked from ComposioHQ/awesome-claude-skills

    A curated list of awesome Claude Skills, resources, and tools for customizing Claude AI workflows

    Python

  5. claude-code-templates claude-code-templates Public

    Forked from davila7/claude-code-templates

    CLI tool for configuring and monitoring Claude Code

    Python

  6. aria-policy-manager aria-policy-manager Public

    ARIA — AI-Powered IT Policy Manager | Multi-agent RAG system for enterprise GRC governance | FastAPI + React + ChromaDB + LangChain + Ollama

    TypeScript