May 2025 — present · Protech Group · Damascus, hybrid
Cybersecurity Specialist
Defense · Detection engineering
- Deployed and operate a Wazuh SIEM/XDR platform — custom rules, decoders and detection content including VMware/ESXi coverage — tuning alerts and triaging phishing and intrusion activity.
- Deployed and tuned a WAF alongside an automated endpoint malware pipeline (Sysmon, Wazuh, VirusTotal) with quarantine via Active Response and IOC logging.
- Set up Teleport for identity-based, audited infrastructure access, with honeypots and other deception and monitoring systems.
- Hardened infrastructure through legacy-service remediation, NetBox for IPAM/DCIM, and a segregated least-privilege SSH key architecture.
- Run scheduled full-scope penetration tests across web, mobile, API and infrastructure.
Sep 2025 — present · Independent
Cybersecurity Consultancy
Offense · Advisory
- Independent black-box penetration testing for high-value clients across web, mobile, API and infrastructure, under defined rules of engagement.
- Advising on security posture, hardening and incident-response readiness — translating technical findings into business-level risk for non-technical stakeholders.
Jan 2024 — May 2025 · XTech LLC · Damascus, on-site
Penetration Tester
Offense · Black-box
- Executed full-scope black-box adversary simulations, identifying critical risks for five top-tier banking and telecom clients including Al-Baraka Bank, ATB and Syriatel.
- Architected a modular testing framework that cut engagement setup time by roughly half, widened coverage and improved report consistency.
- Designed and delivered executive briefings for client C-level leadership, translating vulnerabilities into business impact and remediation roadmaps.
- Developed reconnaissance automation and custom exploit chains built for client-specific environments. Mentored junior testers through structured training.