Open to SOC & Security Operations roles — Charlotte, NC · remote

Security operations,
proven in public.

I’m Mahmoud “Michael” Al Kurdi — a Security+‑certified analyst with eight years inside federally regulated aviation security at American Airlines, now building defensive tooling and reproducible AI‑agent benchmarks. Every claim on this page maps to a public repo, credential, or document.

CompTIA Security+ ce · SY0‑701 B.S. IT — Cybersecurity · Summa Cum Laude MITRE ATT&CK‑aligned defensive work
Verified credential

CompTIA Security+ ce

Exam SY0‑701 · continuing education

Holder
Mahmoud “Michael” Al Kurdi
Issued
Jan 7, 2025
Valid through
Jan 7, 2028
Degree
B.S. IT — Cybersecurity, SNHU
GPA
3.96 · Summa Cum Laude
Alpha Sigma Lambda — Sigma Psi chapter
8 yrs
Federally regulated security operations — American Airlines, CLT
3.96
GPA, B.S. Information Technologies — Cybersecurity, Summa Cum Laude
7
AI coding agents scored on a reproducible defensive-security benchmark
6
Agent adapter targets shipped in AgentForge — published to npm
About

The habits came first.
The tooling followed.

For eight years I ran aviation security operations at American Airlines in Charlotte — as a Crew Chief in a federally regulated environment, holding a security clearance with a CBP badge endorsement and supporting international flight operations under FAA, OSHA, IATA, and CBP requirements.

That work is where my instincts come from: identity validation, access control, recurrent incident‑response and safety training, and documentation precise enough to stand up to federal accountability. A SOC calls these alert triage, least privilege, and escalation notes. I called them Tuesday.

In January 2026 I completed a B.S. in Information Technologies with a cybersecurity concentration at Southern New Hampshire University — summa cum laude, 3.96 GPA — alongside CompTIA Security+ ce. Since then I’ve been building the proof in public: defensive tooling, log‑anomaly detection, and a reproducible benchmark that measures whether AI coding agents can build safe, MITRE ATT&CK‑aligned defensive tools.

Every claim maps to a public repo, a credential, or a document. If it can’t be verified, it isn’t on this page.

— the operating principle behind this portfolio

Target roles

  • SOC Analyst
  • Security Operations Analyst
  • Cybersecurity Analyst
  • Incident Response Analyst
  • Junior Detection Engineer
  • Security Automation

Working skill set

SOC & SecOps

  • Alert triage
  • Security monitoring
  • Incident documentation
  • Log analysis
  • Authentication events
  • DNS investigation
  • Remediation planning
  • Escalation notes

Cybersecurity

  • MITRE ATT&CK
  • Defensive security
  • Prompt‑injection resistance
  • Access control
  • Least privilege
  • Confidence scoring
  • “No Clear Mapping” handling

AI & Automation

  • AI coding‑agent evaluation
  • Reproducible benchmark design
  • Rubric‑based scoring
  • Prompt architecture
  • Safety rules
  • Automated reporting

Tools

  • Python
  • JavaScript / Node.js
  • PowerShell
  • Bash
  • Git / GitHub
  • pytest
  • Gradio
  • npm
  • JSON / YAML / Markdown
Projects

The receipts.
Public, tested, reproducible.

All security work here is defensive — detection, mitigation, and evaluation. Nothing offensive, ever.

AgentForge

One spec, many agents

npm · @kmitops/agentforge@0.3.1 MIT

A configuration framework for agentic AI coding assistants: author one project spec, compile it for six adapter targets — Claude Code, Codex, Gemini CLI, Cursor, Aider, and a generic fallback — so every agent works from the same governing rules.

  • Adapter round‑trip tests and install smoke tests keep every target honest
  • Doctor CLI and readiness runbook for verifying a working install
  • Published to npm with a live, browsable demo

AgentForge ATT&CKLens Benchmark

Can AI agents build safe defensive tooling?

Reproducible MIT

A reproducible, strictly defensive benchmark: seven AI coding agents each built MITRE ATT&CK‑aligned defensive tooling from the same spec, then were scored against a 100‑point rubric — ATT&CK mapping discipline, prompt‑injection resistance, evidence citation, uncertainty handling (“No Clear Mapping”), detection ideas, remediation guidance, and analyst follow‑up questions.

  • One branch per agent artifact — every result is inspectable
  • Harness re‑runs end‑to‑end via benchmark-all.ps1
  • Rubric rewards honesty: agents score points for admitting uncertainty
Cursor 100
Claude Code 98
Hermes Nemotron 98
Codex 96
Lovable Repaired 76
Mistral Vibe 75
Lovable Original 40

Seven agent artifacts, scored /100 against the published rubric. MITRE ATT&CK® is a registered trademark of The MITRE Corporation.

Vulnerability Management Mini Program

Track it, triage it, close it

A Python/Flask/SQLite dashboard for the vulnerability lifecycle: full CRUD, KPI cards, search and filtering, and severity states — the remediation-planning workflow of a vulnerability program in miniature.

Security Log Anomaly Detection

Rules + statistics for triage

Python, pandas, and NumPy applied to authentication and network logs: rule‑based checks layered with statistical detection to surface anomalies worth an analyst’s time — triage before tickets.

Resume

Eight years of accountability,
documented.

  1. Delivery Associate

    Fossa Logistics LLC (Amazon DSP) · Charlotte, NC

    Route-based logistics under time and accuracy pressure while completing certification and building the project portfolio below.

  2. Courier & Logistics Specialist

    USPS · Kannapolis, NC

    Federal mail handling — chain-of-custody discipline and procedural accuracy on every route.

  3. Aviation Security Operations Crew Chief

    American Airlines · Charlotte, NC

    Led crews in federally regulated operations supporting international flights under FAA, OSHA, IATA, and CBP requirements. Held a security clearance with CBP badge endorsement. Recurrent incident‑response and safety/security training; high‑accountability documentation, identity validation, and access control.

    Security clearance CBP badge endorsement Incident response training Access control

The full document

One page. Everything on it verifiable — same standard as this site.

Resume (PDF)

Education

B.S. Information Technologies — Cybersecurity concentration

Southern New Hampshire University · completed Dec 2025, conferred Jan 2026

Summa Cum Laude 3.96 GPA Alpha Sigma Lambda

Certification

CompTIA Security+ ce (SY0‑701)

Issued Jan 7, 2025 · valid through Jan 7, 2028

Available for full-time roles

Hiring for a SOC?
Let’s verify the fit.

Charlotte, NC — open to remote. Recruiters, hiring managers, and security engineers welcome; bring hard questions, I’ll bring receipts.