DWG NO.KM-2026-SEC REVC · 2026

Sheet 1 — General Arrangement · Issued for Recruitment

Name as shown on credentials

Mahmoud “Michael” Al Kurdi

Security Operations Analyst

Charlotte, NC · Open to remote · Available for full-time roles

CompTIA Security+ ce · SY0-701 B.S. IT — Cybersecurity · Summa Cum Laude 8 yrs federally regulated ops

Eight years running federally regulated aviation security operations for American Airlines — clearance held, incidents documented, access controlled. Now certified, degreed, and building public, testable defensive-security work. Every claim on this sheet maps to a repo, credential, or document.

Section A-A: layered defense model Engineering section drawing of four concentric defensive layers — perimeter, network, endpoint, and data core — annotated with item balloons and a diameter dimension. A A 1 2 3 4 Ø 390 — LAYERED DEFENSE SECTION A-A · SCALE: NTS
Fig. 01 — Analyst defense model · items per parts list
Parts list — Fig. 01
ItemLayerAnalyst function
1PERIMETERaccess control · identity validation · least privilege
2NETWORKDNS investigation · log analysis · security monitoring
3ENDPOINTauthentication events · alert triage · anomaly detection
4DATA COREevidence review · incident documentation · escalation notes

Detail A

General Notes — The Analyst

Scale: NTS

General notes — read in full before review

  1. Analyst completed eight years (2015–2023) of federally regulated aviation security operations as Crew Chief, American Airlines, Charlotte: security clearance with CBP badge endorsement; international flight operations under FAA, OSHA, IATA, and CBP requirements; recurrent incident-response and safety/security training.
  2. High-accountability documentation, identity validation, and access control were daily load-bearing conditions of that work — not electives.
  3. Credential: CompTIA Security+ ce (SY0-701), issued 2025-01-07, valid through 2028-01-07.
  4. Education: B.S. Information Technologies, Cybersecurity concentration — Southern New Hampshire University. Summa Cum Laude, 3.96 GPA. Alpha Sigma Lambda honor society, Sigma Psi chapter. Conferred 2026-01-01.
  5. All security work on this sheet is defensive — detection, triage, mitigation. No offensive tooling.
  6. Every claim on this drawing maps to a public repository, credential, or document. Verify before approval — the analyst would.

Designed use — target roles

SOC Analyst / Security Operations Analyst / Cybersecurity Analyst / Incident Response Analyst / Junior Detection Engineer / Security Automation

Schedule S-1 — materials of construction (skills)

MarkClassSpecification
S-01 SOC / SecOps alert triage · security monitoring · incident documentation · log analysis · evidence review · authentication events · DNS investigation · vulnerability awareness · remediation planning · escalation notes
S-02 Cybersecurity MITRE ATT&CK · defensive security · prompt-injection resistance · access control · least privilege · security documentation · confidence scoring · “No Clear Mapping” handling
S-03 AI / Automation AI coding-agent evaluation · reproducible benchmark design · rubric-based scoring · prompt architecture · safety rules · acceptance criteria · automated reporting
S-04 Tools Python · Gradio · JavaScript · Node.js · PowerShell · Bash · Git/GitHub · Markdown · JSON · YAML · HTML/CSS · pytest · npm

Detail B

Project Assemblies — The Receipts

Scale: NTS

AgentForge

DWG KM-PRJ-001 · REV 0.3.1

“One spec, many agents.” A configuration framework for agentic AI coding assistants: author one project specification, compile it to six adapter targets — Claude Code, Codex, Gemini CLI, Cursor, Aider, and a generic profile. Published to npm and proven in public.

Package
@kmitops/agentforge@0.3.1 — npm
Proof
adapter round-trip tests · install smoke tests · doctor CLI · readiness runbook · live demo
License
MIT

AgentForge ATT&CKLens Benchmark

DWG KM-PRJ-002 · TEST REPORT

A reproducible defensive cybersecurity benchmark asking one question: can AI coding agents build secure, uncertainty-aware, MITRE ATT&CK-aligned defensive tooling? Seven agent artifacts scored against a 100-point rubric — ATT&CK mapping discipline, prompt-injection resistance, evidence citation, uncertainty handling (“No Clear Mapping”), detection ideas, remediation guidance, and analyst follow-up questions.

Cursor 100
Claude Code 98
Hermes Nemotron 98
Codex 96
Lovable Repaired 76
Mistral Vibe 75
Lovable Original 40
Method
one branch per agent artifact · harness re-runs via benchmark-all.ps1 · rubric of 100
License
MIT

MITRE ATT&CK® is a registered trademark of The MITRE Corporation.

Vulnerability Management Mini Program

KM-PRJ-003

Dashboard for tracking vulnerabilities through their lifecycle: full CRUD, KPI cards, search, filtering, and severity states.

Stack
Python · Flask · SQLite
Function
CRUD · KPI cards · search · filtering · severity states

Security Log Anomaly Detection

KM-PRJ-004

Rule-based plus statistical detection over security logs, built for authentication and network anomaly triage.

Stack
Python · pandas · NumPy
Function
rule-based + statistical detection · auth & network anomaly triage

Detail C

Service Record & Certification

Scale: NTS
  1. 8 yr — federally regulated ops

    Aviation Security Operations Crew Chief

    American Airlines — Charlotte, NC

    • Federally regulated operations: security clearance with CBP badge endorsement.
    • International flight operations under FAA, OSHA, IATA, and CBP requirements.
    • Recurrent incident-response and safety/security training.
    • High-accountability documentation, identity validation, and access control.
  2. Logistics

    Courier & Logistics Specialist

    USPS — Kannapolis, NC

  3. Current

    Delivery Associate

    Fossa Logistics LLC (Amazon DSP) — Charlotte, NC

Certification plate

CompTIA Security+ ce

SY0-701 · Issued 01.07.2025 · Valid thru 01.07.2028

Education plate

B.S. Information Technologies — Cybersecurity

Southern New Hampshire University · Summa Cum Laude · 3.96 GPA
Alpha Sigma Lambda — Sigma Psi chapter · Conferred 01.01.2026

Document register
Doc no.TitleFormatIssue
DOC-01 Résumé — download PDF 2026
DOC-02 km-it-ops.github.io WEB LIVE

Detail D

Connection Detail

Scale: NTS
RFI-001 — Request for Interview STATUS: OPEN

The analyst is available for full-time roles — SOC, security operations, incident response, detection engineering, and security automation. Based in Charlotte, NC; open to remote.

Review the drawings, pull the repos, run the benchmark harness — then route questions through any connection point at right.

NOTE: All security content on this sheet is defensive — detection, triage, and mitigation. This drawing contains no offensive tooling.