How I got here.
Eight years in security, the last few on offense. From a cybersecurity intern in Karachi to Attack Automation Engineer on IBM's Randori HOC team in Dublin. The longer story is below - happy to bore you with the details.

I've spent eight years in security - the last few on offense, first running pentests and now building the systems that think like attackers automatically. From a cybersecurity intern at Kore Digital in Karachi, through a Master's in Cybersecurity at the National College of Ireland (1:1 honours, Dean's List), to my current role as Attack Automation Engineer on IBM's Randori HOC team in Dublin.
At IBM I write Python automation that simulates adversary techniques on the Randori Recon and Attack platforms, using IBM X-Force threat intelligence, with test environments on Docker, Kubernetes, and VMware.
Before IBM, I ran 150+ pentests at ML Labs across applications and network systems - building automated scripts and custom toolchains, and mentoring five junior testers.
If you're building adversarial-simulation infrastructure or pushing the boundaries of automated red teaming, I'd like to talk.
The tools in the kit.
Offensive
Engineering
From Karachi to Dublin - the long way.
I write Python automation that simulates adversary techniques on IBM Randori’s Recon and Attack platforms, informed by IBM X-Force threat intelligence. The test environments run on Docker, Kubernetes, and VMware.
150+ penetration tests across applications and network systems. I built automated scripts and custom toolchains for our testing, worked with development teams on secure coding and DevSecOps, mentored five junior testers, and presented findings and risk assessments to stakeholders.
Cryptography, forensics, malware analysis, and IT law. My capstone was a security assessment of EV charging infrastructure (OCPP and ISO 15118).
OWASP Top 10 security audits of web applications and databases, Python and PowerShell automation for security workflows, and security policy and wiki updates.
Designed secure database architectures for high-traffic web applications with SQL injection prevention and data-integrity controls. I also ran security assessments of internal systems, wrote Python scripts to automate vulnerability assessments, and ran regular security training for the team.
Configured firewalls and Snort IDS under the guidance of senior engineers, and documented security incidents.
Software development, data structures, DBMS, and systems design.
References on request.
I'd rather not publish testimonials here. Ask, and I'll put you in touch with people I've worked with.