SYS_STATUS // ACTIVE: Open to security engineering, DevSecOps, and penetration testing roles

Rana Uzair
Ahmad

Penetration Testing SOC & Threat Hunting DevSecOps Gates Cloud Security

Cybersecurity & DevSecOps Engineer with 3+ years of experience conducting full-scope web/network penetration testing, building Linux security daemons, and hardening enterprise CI/CD deployment pipelines.

cortex_kernel_telemetry.sh ACTIVE
$ cortex inspect --candidate="Rana Uzair Ahmad"

STATUS: Available (100% Worldwide Remote / Relocation)

CURRENT_ROLE: Cybersecurity Engineer & Pentester @ ZeroxInnovation

PREV_ROLE: Digital Forensics & Security Engineer @ NCCS

EDUCATION: BS Cybersecurity — Air University Islamabad

CREDENTIALS: CompTIA PenTest+, CCEP, CSI Linux (17 Total)

STANDINGS: TryHackMe Top 3% · HackTheBox Top 800 (Level 54)

$ cat /etc/security_capabilities.conf
Python C / C++ Rust x86 ASM Wazuh SIEM Splunk Burp Suite Pro Docker / K8s Terraform
34+ Open Source Projects
Top 3% TryHackMe Global Rank
Top 800 HackTheBox Rank
3+ Yrs Hands-On Experience
Curated Arsenal

Featured Security Tools

34+ published open-source repositories — packet dissectors, Linux FIM daemons, SSH hardening, and SIMD tokenizers.

Explore all 34+ projects →
RCMS (Remote Control Management System) — project screenshot DEV 5

Ansible-like Infrastructure Management Platform

RCMS (Remote Control Management System)

Centralized infrastructure management platform similar to Ansible; orchestrates fleets of remote servers via YAML-based declarative configuration. Features JWT-based role authentication, real-time WebSocket monitoring, SSH tunneling via Paramiko, and a fully Dockerized React.js frontend.

PythonReact.jsDockerWebSocketParamiko
CortexCLI — project screenshot DEV

Custom Linux Shell in C with Google Gemini AI

CortexCLI

Custom Linux shell written in C with embedded Google Gemini AI. Implements low-level C systems programming including fork/exec process management, custom HTTP client, and a security filter layer for dangerous command detection.

CGemini AISystems ProgrammingPOSIX
CyberGuard Agent — project screenshot DEFENSIVE 4

C SIEM Agent for Event Correlation & Active Response

CyberGuard Agent

Lightweight C-based SIEM agent built during NCCS internship using inotify for real-time log parsing, network scanning, event correlation, and anomaly detection. Deployed into live government infrastructure at NCCS, Islamabad.

CInotifySIEMWazuhNetworking
NetSnoop — project screenshot OFFENSIVE 4

Advanced Packet Analyzer for Reconnaissance

NetSnoop

Advanced packet analyzer built with Scapy; supports 10+ protocols with real-time BPF filtering, PCAP export, and live traffic visualization. Built for network security monitoring and penetration testing reconnaissance.

PythonScapyMatplotlibNetworking
VortexTunnel — project screenshot DEFENSIVE

SSH Tunneling & Encrypted Channel Engine

VortexTunnel

A Python SSH tunneling tool for creating secure, encrypted communication channels with local, remote, and dynamic forwarding support.

PythonSSHNetworkingSecurity
SSHield — project screenshot DEFENSIVE 4

SSH Security Toolkit & Brute-Force Detector

SSHield

A Python toolkit for hardening SSH configurations, monitoring real-time access logs, and detecting brute-force authentication attacks.

PythonSSHSecurityHardening
Technical Capabilities

Core Domains & Expertise

From red-team offensive exploitation to blue-team SIEM telemetry and production DevSecOps pipeline automation.

Security Engineering & VAPT

OFFENSIVE
// CORE COMPETENCIES
  • Penetration Testing (Web & Network)
  • Red Team Operations & Adversary Emulation
  • SAST / DAST Scanning Automation
  • OWASP Top 10 & API Security Testing
  • Binary Exploitation & Reverse Engineering
  • Malware Analysis & DFIR Forensics
// KEY TOOLING & ARSENAL
Burp Suite ProMetasploitNmapSQLmapWiresharkGhidraBloodHoundImpacket
OWASP Top 10 · Active Directory · MITRE ATT&CK

DevSecOps & Infrastructure

CI/CD & CLOUD
// CORE COMPETENCIES
  • GitHub Actions & Jenkins CI/CD Pipelines
  • GitLab CI Security Gate Automation
  • Docker & Container Image Hardening
  • Ansible Automation & OS Baseline Hardening
  • Kubernetes RBAC & Calico Network Policies
  • Terraform IaC Security & Drift Detection
// KEY TOOLING & ARSENAL
GitHub ActionsDockerKubernetesTerraformTrivySemgrepTruffleHogFalco eBPF
Automated CI/CD Gates · Supply Chain Hardening

Security Operations & SIEM

DEFENSIVE / SOC
// CORE COMPETENCIES
  • Wazuh SIEM Deployment & Rule Tuning
  • Splunk Enterprise & Kibana Threat Analytics
  • C-based SIEM Agent Engineering (inotify FIM)
  • Threat Hunting & Incident Response Playbooks
  • Vulnerability Management & CVSS Prioritization
  • Threat Intelligence Integration (MISP/CTI)
// KEY TOOLING & ARSENAL
Wazuh SIEMSplunk EnterpriseElasticsearchSysmonSuricata IDSSigma RulesVolatility
Real-time FIM (inotify) · Threat Hunting Telemetry

Software & Security Tooling

SYSTEMS & CODE
// CORE COMPETENCIES
  • Python (Scapy, Paramiko, AsyncIO, Sockets)
  • C / C++ (POSIX, Linux inotify, Raw Sockets)
  • Rust & SIMD AVX2 Vectorization
  • x86 Assembly & Low-Level Reversing
  • Bash & PowerShell Security Scripting
  • REST API, GraphQL & WebSocket Integration
// KEY TOOLING & ARSENAL
PythonC / C++Rustx86 ASMRayon SIMDScapyFastAPIPOSIX APIs
34+ Published Security Repositories · SIMD 48.2 GB/s

Testing & API Vulnerability Automation

AUTOMATION
// CORE COMPETENCIES
  • Postman & REST Assured Automation
  • GraphQL & REST API Vulnerability Audits
  • CSRF / JWT / IDOR Exploit Automation
  • CVSS 3.1 Severity Scoring & Remediation Roadmaps
  • Automated Security Regression Test Suites
// KEY TOOLING & ARSENAL
PostmanREST AssuredNewman CLISwagger/OpenAPIPyTestJWT Debugger
End-to-End API Security & Broken Auth Verification

Cloud Defense & Kernel Systems

INFRASTRUCTURE
// CORE COMPETENCIES
  • AWS / Azure / GCP Security Posture Management
  • Linux Kernel & System Calls (eBPF Telemetry)
  • Network Segmentation & pfSense Firewall Hardening
  • Zero-Trust Mesh Networks (WireGuard / NetBird)
  • IAM Least Privilege & Cloud Identity Governance
// KEY TOOLING & ARSENAL
AWS SecurityAzureLinux KernelpfSenseWireGuardNetBirdCalico CNI
Zero-Trust Architecture · Kernel-Level Telemetry
Verified Credentials

8 Security Certifications

CompTIA PenTest+, Red Team Leaders CCEP, CSI Linux Certified Investigator, arcX CTI 101, Cisco CCNA, and more.

View all certificate PDFs →
CompTIA · Coursera
CompTIA PenTest+ Preparation Course Certificate
Oct 2025
Red Team Leaders
Certified Cybersecurity Educator Professional (CCEP)
Dec 2025
arcX
Cyber Threat Intelligence 101 (Foundation TIA)
Oct 2025
CSI Linux
CSI Linux Certified Investigator (CSIL-CI)
Oct 2025
CSI Linux
Introduction to Cyber Investigations
Oct 2025
OCSALY Academy · Udemy
Mastering Reverse Engineering & Malware Analysis (REMASM+)
Oct 2024
National Center of Cyber Security (NCCS)
Digital Forensics Internship Certificate
Sep 2024
Udemy
Web Application Security
2024
Technical Research

Latest Security Writeups

In-depth breakdowns on Active Directory attack chains, Kubernetes runtime defense, CI/CD security gates, and reverse engineering.

View all 33+ articles →
SYS_STATUS // AVAILABLE

Looking for a Security Engineer or DevSecOps Specialist?

Security Engineer, Penetration Tester, DevSecOps Practitioner, and Software Developer with 3+ years of hands-on experience spanning offensive security, CI/CD pipeline security, infrastructure automation, and full-stack security tool development. Author of 34+ open-source tools covering SIEM engineering, remote infrastructure management, SSH security, and network analysis. Ranked Top 3% TryHackMe globally and Top 800 HackTheBox (Professional Rank, Level 54). CompTIA PenTest+ Preparation Course Certified via Coursera with 17 total certifications.