I embed as a DevSecOps Resident Engineer — bringing structure and governance to real CI/CD pipelines, not just paper policy.
Riyadh, Saudi Arabia — DevSecOps & Application Security Consultant
01 — Approach
5+ years in application security — auditing, implementation, and automation across compliance reporting, secure development, and DevSecOps. I focus on embedding security into the SDLC and CI/CD pipeline itself, not bolting it on after, and on delivering measurable results in weeks, not quarters. I take on both project-based engagements and embedded/retained work, depending on what the problem actually needs.
02 — Services
See all →DevSecOps
SAST, DAST, and IAST tuning and administration wired directly into your SDLC and CI/CD pipeline — the same tool chain I run daily as a resident engineer, not a one-off audit.
Threat Modeling
Structured threat modeling for applications and cloud environments, mapped to real attack paths rather than a generic checklist.
Secure Code Review
Manual review layered on top of automated tooling — the pass that catches what SAST alone reports as clean but isn't.
Integration Security Review
Review of system-to-system trust boundaries and integration points — where two secure systems still create an insecure seam.
03 — Selected work
Full history →Elm — DevSecOps Resident Engineer
Oct 2024–PresentPrincipal Application Security Consultant, embedding security across the SDLC and CI/CD for cloud-native & on-prem environments. Engaged through AppSec, which placed me at Elm on an outsourced basis.
Fawry Banking & Payment Technology
Jan 2023–Jan 2024Team Lead, Application Security (FAST) — PCI ASV review, SSDLC planning, mobile/web/network/POS pentesting.