MAAB.
Available for strategic security leadership & consulting

Mirza Asad

Ahmed Baig

Senior Manager — Cybersecurity & AI Security

7+ years bridging offensive security, enterprise risk governance, and the frontier of AI security research — protecting the organisations and systems that matter.

GRC · ISMSPenetration TestingLLM SecurityAI Risk
Scroll
01
About

A leader forged in operational reality.

I am a Senior Cybersecurity Manager with over 7 years of experience spanning offensive security, enterprise risk governance, and cutting-edge AI security research.

My career began hunting threats in the SOC, advanced through complex penetration testing engagements, and evolved into executive leadership — orchestrating comprehensive security postures across enterprise environments and regulated industries.

Today, my core research focus is AI Security — identifying prompt injection vectors in production LLMs, quantifying risks in AI supply chains, and building secure integration frameworks for the next generation of enterprise AI systems.

7+
Years Experience
50+
Security Audits
3
Languages
MA
Professional Portrait
02
Experience

Career Trajectory.

Senior Manager – Cyber Security

Level 3 BOS

2026 – Present

Leading cyber security operations, GRC implementation, and AI security research initiatives.

Senior Penetration Tester

Risk Associates

2025 – 2026

Conducted advanced penetration testing for web, mobile, API, and network environments.

AI Security Researcher

Independent / Stealth

2023 – 2024

Researched LLM vulnerabilities, prompt injection attacks, and AI integration security.

Cyber Security Engineer

The Horizon Tech

2022 – 2023

Implemented DevSecOps pipelines and automated security testing.

SOC Analyst

Intellectsols

2018 – 2022

Monitored SIEM alerts, incident response, and threat hunting.

03
Projects

Impact Portfolio.

Offensive security tooling, GRC automation, and AI vulnerability research — built to solve real enterprise challenges.

AI Security

LLM Security Audit Framework

An automated framework for identifying prompt injection and data exfiltration vulnerabilities in Large Language Models.

PythonOpenAI APIPytestDocker
Cloud

Enterprise GRC Dashboard

A centralized dashboard for tracking ISO 27001, SOC2, and PCI DSS compliance across multi-cloud environments.

Next.jsTypeScriptAWSPrisma
DevSecOps

Automated DevSecOps Pipeline

A CI/CD pipeline template that integrates SAST, DAST, and SCA scanning natively into GitHub Actions.

GitHub ActionsSonarQubeTrivyBash
04
Research

Thought Leadership.

Contributing to the global cybersecurity community through research, vulnerability disclosures, and published insights.

05
Skills

Core Competencies.

Governance & Compliance

  • ISO 27001
  • GRC
  • NIST
  • HIPAA
  • GDPR
  • PCI DSS

Offensive Security

  • Web Pentesting
  • Mobile Pentesting
  • API Security
  • Network Pentesting
  • LLM Pentesting

Cloud

  • AWS
  • Azure
  • Google Cloud

Security Operations

  • SIEM
  • Wazuh
  • Splunk
  • LogRhythm
  • SentinelOne

Automation

  • DevSecOps
  • CI/CD
  • AI Automation

Technical Proficiency

Security95%
Cloud90%
AI85%
DevSecOps88%
Programming80%
Networking92%
Operating Systems95%
06
Credentials

Certifications & Education.

Professional Certifications

CAP

ISC2

Completed

APISEC

APIsec University

Completed

SSCP

ISC2

Completed

RHCSA

Red Hat

Completed

AWS Security Specialty

AWS

Completed

CSSLP

ISC2

In Progress

ISO 27001 Lead Auditor

BSI

Completed

Google Cybersecurity Professional

Google

Completed

LogRhythm LESA

LogRhythm

Completed

Education

Bachelor of Software Engineering

Hamdard University

Professional Diploma

Aptech

07
Impact

Metrics & Impact.

0+

Years Experience

0+

Reported Vulnerabilities

0+

Security Assessments

0+

Penetration Tests

0+

Security Trainings

Languages

Urdu
Native
English
Professional
Polish
Conversational
08
Self-Defense

This site defends itself.

The portfolio runs its own deception stack — every probe below is a live mechanism answering hostile traffic right now.

Scanner Decoys

Fake admin, CMS and config paths answer with indistinguishable 404s. Each attacker gets a deterministic fingerprint, defeating scanner diffing.

Bot Tarpits

Known offensive tooling (sqlmap, Nikto, Burp, Nmap…) is served silent soft-404s on sensitive routes — it never reaches real application surface.

Behavioral Detection

Sliding-window rules score connection floods, sequential probing and auth abuse; findings are risk-ranked LOW → HIGH in real time.

Adaptive Response Budget

Deception replies are CSPRNG-selected and budget-capped per attacker. Once spent, the engine goes dark — log-only, zero signal leakage.

Hardened Auth & Sessions

Two-step admin login, scrypt password hashing, DB-backed revocable sessions, CSRF tokens, origin checks and constant-time comparisons.

Per-Request CSP Nonces

The edge proxy rotates a fresh nonce into the Content-Security-Policy of every response; inline scripts are stamped, violations are reported.

Live Threat Telemetry

ARMED
561

Events recorded

559

Last 24 hours

561

Last 7 days

25m ago

Last contact

Top probed paths

  • /admin/skills61
  • /admin/progress-skills52
  • /admin/certifications50
  • /admin/publications50
  • /admin/achievements45

Tooling observed

  • No tooling signatures captured.

Anonymized aggregates only — source addresses are never published.

08
Connect

Start a Conversation.

Open to strategic security leadership, AI security consulting, and meaningful research collaborations.

Contact

Prefer email for initial outreach — typically responded within 48 hours.

Phone

Email

LinkedIn

Location

Global · Remote

Send a Message