Available for opportunities

Cybersecurity
Engineer.

>

Fresh graduate in Information Security & Assurance (CGPA 3.75) from USIM. Yayasan Peneraju scholar. Hands-on in offensive security, blue team, and building real tools. Currently a Helpdesk Support Engineer at VSTECS KU, actively pursuing red team & SOC roles.

3.75
CGPA
12+
Certifications
7+
CTF Events
82%
eJPT Score
01 // about

Who I Am

I'm a cybersecurity professional with a focus on offensive security and detection engineering. Fresh graduate from Universiti Sains Islam Malaysia (USIM) with a Bachelor in Information Security and Assurance, graduating with a CGPA of 3.75 and multiple Dean's Awards.

I operate across both ends of the security spectrum — from penetration testing web apps and internal networks, to building AI-powered SOC pipelines and SIEM detection rules from scratch. I don't just study security theory; I build, simulate, and break things in real lab environments.

As a Yayasan Peneraju scholar, I completed the Peneraju Teknologi SPRINT Certified Cybersecurity Engineer program, sharpening both technical skills and professional discipline. Outside of security, I build tools — including an open-source MCP server (vaultbridge) used daily with Claude AI.

[EDU]
B.Sc. Information Security & Assurance Universiti Sains Islam Malaysia (USIM) · 2021–2025 · CGPA 3.75
[LOC]
Malaysia Open to remote & on-site opportunities
[SCH]
Yayasan Peneraju Scholar SPRINT Certified Cybersecurity Engineer programme
[LNG]
Languages Malay (Native) · English (Fluent) · Arabic (Conversational) · French (DELF A2)
02 // skills

Technical Arsenal

Offensive Security

Web Penetration Testing88%
Network Penetration Testing80%
Privilege Escalation78%
Burp Suite / SQLMap85%
Metasploit Framework80%

Blue Team / Detection

Wazuh SIEM85%
Suricata IDS78%
Detection Rule Engineering80%
MITRE ATT&CK Mapping82%
Threat Intelligence75%

Development & Scripting

Python82%
PowerShell / Bash75%
Web Dev (HTML/CSS/JS)78%
Flask / REST APIs72%
Git / GitHub80%

Infrastructure & Networking

Active Directory78%
Microsoft Azure72%
Firewall (Palo Alto)68%
Network Monitoring80%
Virtualization (VMware)82%
03 // experience

Work History

Nov 2025 – Present Full-time
Helpdesk Support Engineer
VSTECS KU Sdn Bhd
  • Monitor and triage daily support tickets across Microsoft, Azure, and network security domains
  • Diagnose Azure security alerts, perform initial incident triage within defined SLAs
  • Escalate complex incidents to Level 2 engineers; coordinate with technology vendors
  • Manage ticketing workflows via ManageEngine with full case documentation
  • Contribute to continuous service improvement through accurate reporting and knowledge sharing
Mar 2025 – Aug 2025 Internship
IT Services Intern — Network & Server Team
KPMG Malaysia
  • Monitored network and system performance; proactively identified and resolved infrastructure issues
  • Supported firewall configuration (Palo Alto exposure) and Active Directory administration
  • Automated daily network/server reporting using Python and PowerShell scripts — significantly reducing manual effort
  • Configured switches, supported backup operations, and ensured data integrity
  • Assisted users via ticketing system for network troubleshooting
04 // projects

What I've Built

Blue Team · AI
AI SOC Analyst — Home Lab

End-to-end AI-powered SOC environment on VMware. Wazuh 4.9.2 SIEM + Suricata IDS + Sysmon. Python/Flask middleware with a 6-touchpoint LLM pipeline (Groq). SOAR automation via Slack. 86%+ AI triage accuracy over 100+ analyst verdicts. Detected SSH brute force, Nmap recon, Mimikatz, and persistence attacks end-to-end.

WazuhSuricataPython FlaskLLMSOAR MITRE ATT&CKSysmon
Open Source · Tool
vaultbridge v1.1.0

Python MCP (Model Context Protocol) server that bridges Claude Desktop and Obsidian. Exposes 5 tools over stdio transport. Security-hardened v1.1.0 includes path traversal protection, audit logging, read-only mode, and auto-created notes. Used daily in production. Published under MIT license.

PythonMCPObsidian Open SourceClaude AISecurity
Certification · Pentest
Syntex Dynamics — eJPT Exam

Full black-box pentest against a simulated segmented network (DMZ + internal). Exploited Drupalgeddon2 (CVE-2018-7600), WordPress XML-RPC brute force + PHP web shell, anonymous FTP IIS shell upload. Pivoted via Metasploit autoroute + SOCKS5 proxy. SAM database dumped; hashes cracked. Score: 82%.

eJPTMetasploitPivoting CVE-2018-7600WordPressHashcat
Writeups / Labs
Hack The Box Writeups

Collection of machine and challenge writeups from Hack The Box. Documents enumeration, vulnerability analysis, exploitation paths, privilege escalation, and lessons learned from authorized lab environments.

Hack The BoxWriteupsEnumeration Privilege EscalationLinuxWindows
Writeups / Web Security
Hackviser Writeups

Structured notes and walkthroughs from Hackviser web security labs. Covers practical vulnerability discovery, exploitation methodology, remediation thinking, and repeatable learning notes across real-world web attack classes.

HackviserWeb SecurityOWASP SQLiXSSMethodology
Blue Team · SIEM
Wazuh SIEM Endpoint Monitor

Configured Wazuh agent on Windows to monitor folders for malicious files in real time. Integrated VirusTotal API for automated hash scanning. Deployed custom YARA rules for pattern detection. Validated detection pipeline with EICAR test files. Functional threat intelligence pipeline.

WazuhYARAVirusTotal Malware DetectionBlue Team
Certification · Web Security
CWSE — Web Security Expert

Certified Web Security Expert from Hackviser. Practical exploitation of XSS, SQLi (union-based, blind, NoSQL), IDOR, SSRF, SSTI, XXE, LFI/RFI, CSRF, race conditions, JWT weaknesses. CMS exploitation (WordPress, Joomla). Advanced WAF bypass techniques. End-to-end real-world web scenarios.

Burp SuiteSQLiXSS WAF BypassOWASPCWSE
Professional · Automation
Network Report Automation — KPMG

Designed and built Python and PowerShell scripts to automate daily network and server health reporting at KPMG Malaysia. Significantly reduced manual effort, improved consistency, and supported proactive infrastructure management. Delivered as part of the internship network and server team.

PythonPowerShellAutomation NetworkingReporting
05 // credentials

Certifications & CTFs

[★]
eJPT — Junior Penetration Tester
eLearnSecurity / INE · 2026
[★]
Certified Associate Penetration Tester (CAPT)
Hackviser · 2025
[★]
Certified Web Security Expert (CWSE)
Hackviser · 2025
[☁]
Microsoft Certified: Azure Fundamentals
Microsoft
[☁]
Microsoft 365 Certified: Fundamentals
Microsoft
[◈]
Rocheston CCE Level 1 & Level 2
Rocheston
[◈]
Google Cybersecurity Certificate
Google
[◈]
ISC2 Candidate
ISC2

CTF Competitions

Competition Ranking Year
AI Red Teaming CTF (Hack The Box)106th Worldwide2025
CODE COMBAT CTF35th (Group)2025
Holmes CTF (HTB – First All Blue CTF)760th Worldwide2025
3108 Bahtera Siber CTF207th Solo2025
University CTF (Tinsel Trouble)121st (Group)2025
IBOH 2025Qualifying Round2025
IGOH 2025Qualifying Round2025
06 // contact

Let's Connect

Open to Penetration Tester, SOC Analyst, Security Engineer, and Red Team roles. Feel free to reach out — I respond promptly.