// init profile.sh
I break systems before attackers do. Specializing in offensive security, penetration testing, and AI-powered security tooling — helping organizations discover and remediate vulnerabilities before they become incidents.
I'm a Cybersecurity Engineer specialized in offensive security, with a deep focus on penetration testing across Web, API, Mobile, and Cloud environments. I hold an Engineer's degree in Cybersecurity from ENSA Marrakech.
Beyond classic pentesting, I work at the intersection of AI and offensive security — building autonomous agents and automated tooling that push the boundaries of red teaming and vulnerability research.
I conduct security audits for international clients and lead R&D projects in offensive cybersecurity. Ranked in the Top 2% on TryHackMe globally.
Conducting application penetration tests (Web, API, Mobile) and Cloud security assessments for international clients. Delivering detailed technical reports with actionable remediation guidance.
Leading R&D in offensive cybersecurity, designing and implementing AI-powered autonomous agents for security automation. Developing intelligent workflows combining penetration testing with agentic frameworks.
Post-incident forensic analysis and damage assessment following a ransomware attack targeting a governmental institution. Delivered a comprehensive incident report with recovery and hardening recommendations.
Developed an AI-based intrusion detection system using machine learning to identify and classify network threats in real time. Researched and implemented anomaly detection models evaluated against benchmark datasets.
Intensive hands-on training in offensive and defensive cybersecurity, covering penetration testing techniques, security frameworks, and practical labs across web, network, and system environments.
Active participation in public and private bug bounty programs. Focused on web application vulnerabilities, API security flaws, and logic errors on major platforms using OWASP Top 10 and custom tooling.
Led a team designing and implementing a Zero Trust security architecture enhanced with artificial intelligence — integrating AI-driven access policies, continuous authentication, and automated threat response.
Developed an automated Linux hardening script following ANSSI security recommendations, reducing manual configuration effort while ensuring compliance with national cybersecurity standards.
Available for penetration testing engagements, security audits, bug bounty collaborations, and AI security R&D projects. Based in Morocco, working globally.
Start a Project