Riyadh · Cybersecurity

Ahmad Alassaf

Cybersecurity professional: offensive security programmes, vulnerability management, and regulatory assurance.

Senior Cybersecurity Analyst with an MSc in Cyber Security and seven years across government and sovereign-fund environments. Experience spans planning and delivering penetration-testing and vulnerability-management programmes, attack simulation and phishing exercises, and alignment with National Cybersecurity Authority requirements and external audits.

7+Years in offensive security
8Professional certifications
2Languages · Arabic, English
KSARiyadh based

Profile

I help organisations understand and reduce their real exposure. My work combines hands-on offensive security with the programme discipline that turns findings into measurable risk reduction: scoping and planning assessments, running vulnerability-management cycles, exercising people and detection controls, and presenting results in terms that engineers, executives, auditors, and regulators can act on.

LocationRiyadh, Saudi Arabia
Current roleSenior Cybersecurity Analyst
EducationM.Sc. Cyber Security · Saudi Electronic University
EducationB.Sc. Computer Engineering · University of Hail

Areas of practice

  • Penetration-testing programme planning and delivery across networks, web applications, and APIs, including scoping, scheduling, third-party assessor coordination, and remediation tracking.
  • Vulnerability-management programme design and operation: asset coverage, risk-based prioritisation, ownership, and closure metrics.
  • Attack simulation and phishing exercises that measure detection, response, and user awareness against realistic scenarios.
  • Regulatory and audit assurance: alignment with National Cybersecurity Authority controls, evidence preparation, and coordination with internal and external auditors.
  • Governance: security policy and procedure writing, budgeting for assessment and tooling programmes, and executive reporting.

Experience

Two long-tenure roles in high-assurance environments, both centered on offensive security and validation.

  1. Dec 2020 – PresentPublic Investment Fund

    Senior Cybersecurity Analyst

    Cyber security defense and exploitation

    • Plan and deliver the annual penetration-testing programme for networks, web applications, and APIs, including scope, scheduling, and third-party assessor coordination.
    • Operate the vulnerability-management programme: coverage, risk-based prioritisation, remediation ownership, and closure reporting to leadership.
    • Design and run attack-simulation and phishing exercises to measure detection, response, and awareness.
    • Support regulatory alignment with National Cybersecurity Authority controls and prepare evidence for internal and external audits.
    • Draft security policies and procedures and contribute to budgeting for assessment and tooling initiatives.
    • Perform benchmark compliance checks against hardening baselines.
  2. Feb 2019 – Nov 2020Ministry of Foreign Affairs

    Senior Information Security Engineer

    Application and infrastructure security assessment

    • Conducted network, web application, and API vulnerability assessments and penetration tests (black, gray, and crystal box).
    • Led compromise assessments and web application firewall request audits for internet-facing services.
    • Reported findings with business impact and remediation guidance to application owners and management.

Selected work

Public summaries of independent projects. Client work, internal systems, and implementation details are deliberately excluded. Longer write-ups are on the blog.

Security · Machine learning

TrustedChain

Threat-intelligence service that classifies domains, IPs, and hashes against a large curated IOC feed, with model-assisted and retrieval-augmented modes. Built around precision, analyst triage cost, and explainability rather than raw accuracy.

Detection engineeringIOC feedsAPI product
Security monitoring

SIEM and hardening program

Self-hosted SIEM with file-integrity monitoring, threat-intel enrichment, and custom detection rules across cloud and on-premise hosts, paired with a hardening and backup-verification routine for production services.

SIEMFIMIncident readiness
IoT · Edge AI

Edge video analytics

On-premise camera analytics on Raspberry Pi with hardware-accelerated inference, local-only processing, and event-driven home-automation integrations. Reliability engineering for real hardware, not demos.

Raspberry PiComputer visionMQTT
AI systems

Agent operating model

Multi-agent workflows for operations and research with separated roles for planning, execution, review, and follow-up. Bounded tool access, human-in-the-loop for sensitive actions, and audit-friendly execution paths.

OrchestrationLeast privilegeObservability
Product · Data

Real-estate valuation platform

Bilingual valuation platform for licensed appraisers with an automated market-comparables engine built on public deed data and daily listing feeds, signed PDF reports, and a data-quality dashboard.

Next.jsPostGISData pipelines
IoT · SaaS

Smart-building device platform

Multi-tenant device-management platform for smart buildings: one dashboard for locks, switches, and sensors across many properties, with remote control, live status, per-unit energy tracking, and an API for automation.

Smart buildingsMulti-tenantDevice API

How an engagement runs

Scoped, authorized, and evidence-driven from the first call to the last retest.

01

Scope and rules

Clear targets, authorization, windows, and escalation contacts before anything is touched.

02

Assess and exploit

Manual testing first. Tools support the work, they do not replace it. Impact is demonstrated safely.

03

Report for two audiences

Reproducible technical findings for engineers, business-risk framing for leadership.

04

Fix and retest

Remediation guidance, then verification that the fix actually closes the gap.

Certifications

Offensive-security credentials, most demanding first.

OSCE

Offensive Security Certified Expert

Offensive Security

GXPN

GIAC Exploit Researcher and Advanced Penetration Tester

GIAC / SANS Institute

OSCP

Offensive Security Certified Professional

Offensive Security

GPEN

GIAC Penetration Tester

GIAC / SANS Institute

GWAPT

GIAC Web Application Penetration Tester

GIAC / SANS Institute

eCPPT

Certified Professional Penetration Tester

eLearnSecurity

eJPT

Certified Junior Penetration Tester

eLearnSecurity

EMC

Cloud Infrastructure and Services

EMC Academic Associate

Education

Completed 2026Master in Cyber Security

Saudi Electronic University, Riyadh

Jan 2017Bachelor of Computer Engineering

University of Hail, Saudi Arabia

Skills

LinuxWindowsmacOSPythonPHPJavaScriptSQLVMwareVirtualBoxWeb & API testingNetwork testingAdversary emulationVulnerability managementNCA ECC alignmentAudit coordinationPolicy & procedure writingSecurity budgetingExecutive reporting

Recommendation

“Professional in delivering tasks, structured thinking, well understanding of environment, multi-tasking, out of the box thinker, result oriented and professional.”

Public recommendation excerpt visible on LinkedIn.