The Kurdi File

Case file № 26-0107 · Security Operations · Charlotte, NC

Mahmoud “Michael” Al Kurdi

The analyst walked in with eight years of federally regulated security operations and a spotless paper trail. Security+ certified. Summa cum laude. Builds defensive tooling — and benchmarks the AI agents that build it. Every claim in this file maps to a public repo, a credential, or a document.

  • CompTIA Security+ ce · SY0-701
  • B.S. IT — Cybersecurity · Summa Cum Laude
  • 8 yrs federal aviation security ops

Act I

The Profile.

Who he is, where he's been, and why the paper trail holds up.

Investigator's notes — filed 2026

Eight years on the concourse at Charlotte Douglas. From 2015 to 2023, Mahmoud “Michael” Al Kurdi ran aviation security operations as a crew chief for American Airlines — security clearance, CBP badge endorsement, international flight operations under FAA, OSHA, IATA, and CBP requirements. Recurrent incident-response and safety training, year after year. Identity validation. Access control. The kind of work where documentation isn't paperwork — it's the whole case.

Then the pivot, deliberate and on the record. January 2025: CompTIA Security+ ce (SY0-701), valid through January 2028. December 2025: the degree — B.S. Information Technologies, cybersecurity concentration, Southern New Hampshire University. Summa cum laude, 3.96 GPA, inducted into the Sigma Psi chapter of Alpha Sigma Lambda. He kept the lights on with logistics work at USPS and an Amazon DSP while he did it.

What he wants now is plain: a seat on a security operations team — alert triage, incident response, detection engineering, security automation. What he brings is in the exhibits below. Draw your own conclusions; the evidence is public.

Subject Dossier

Subject
Mahmoud “Michael” Al Kurdi
Last known location
Charlotte, NC — open to remote
Status
Available — full-time
Credential
CompTIA Security+ ce (SY0-701) · Jan 2025 – Jan 2028
Education
B.S. Information Technologies, Cybersecurity — SNHU · Summa Cum Laude, 3.96 GPA
Honors
Alpha Sigma Lambda, Sigma Psi chapter
Wanted for
SOC Analyst · Security Operations Analyst · Cybersecurity Analyst · Incident Response Analyst · Junior Detection Engineer · Security Automation

Known methods — skills on record

SOC / SecOps

  • Alert triage
  • Security monitoring
  • Incident documentation
  • Log analysis
  • Evidence review
  • Authentication events
  • DNS investigation
  • Remediation planning
  • Escalation notes

Cybersecurity

  • MITRE ATT&CK
  • Defensive security
  • Prompt-injection resistance
  • Access control
  • Least privilege
  • Security documentation
  • Confidence scoring
  • “No Clear Mapping” handling

AI / Automation

  • AI coding-agent evaluation
  • Reproducible benchmark design
  • Rubric-based scoring
  • Prompt architecture
  • Safety rules
  • Acceptance criteria
  • Automated reporting

Tools

  • Python · pytest
  • JavaScript · Node.js · npm
  • PowerShell · Bash
  • Git / GitHub
  • Gradio
  • HTML/CSS
  • Markdown · JSON · YAML

Act II

The Exhibits.

Evidence log. Four items entered into the record — all public, all reproducible.

Exhibit A

AgentForge

“One spec, many agents.”

A configuration framework for agentic AI coding assistants: write the spec once, deploy it to six adapter targets — Claude Code, Codex, Gemini CLI, Cursor, Aider, and a generic fallback. Published to npm as @kmitops/agentforge@0.3.1, MIT licensed.

Proof on file: adapter round-trip tests · install smoke tests · doctor CLI · readiness runbook · live demo

Exhibit B

AgentForge ATT&CKLens Benchmark

Seven agents interrogated. One rubric. Nobody walked.

A reproducible, strictly defensive cybersecurity benchmark asking one question: can AI coding agents build secure, uncertainty-aware, MITRE ATT&CK–aligned defensive tooling? Seven agent artifacts were graded against a 100-point rubric — ATT&CK mapping discipline, prompt-injection resistance, evidence citation, uncertainty handling (“No Clear Mapping”), detection ideas, remediation guidance, and analyst follow-up questions. One branch per agent; the harness re-runs on demand via benchmark-all.ps1. MIT licensed.

Interrogation ledger — scores out of 100

  1. Cursor100
  2. Claude Code98
  3. Hermes Nemotron98
  4. Codex96
  5. Lovable Repaired76
  6. Mistral Vibe75
  7. Lovable Original40

MITRE ATT&CK® is a registered trademark of The MITRE Corporation.

Exhibit C

Vulnerability Management Mini Program

Everything broken, on one board.

A Python/Flask/SQLite dashboard for tracking what's vulnerable and what's been fixed: full CRUD, KPI cards, search, filtering, and severity states.

Stack: Python · Flask · SQLite

Exhibit D

Security Log Anomaly Detection

The logs always talk. You just have to listen.

Rule-based and statistical detection in Python with pandas and NumPy, built for authentication and network anomaly triage.

Stack: Python · pandas · NumPy

Act III

The Record.

The history, in order. Nothing sealed, nothing redacted.

  1. 2025 — Present

    Delivery Associate

    Fossa Logistics LLC (Amazon DSP) · Charlotte, NC

  2. 2024 — 2025

    Courier & Logistics Specialist

    USPS · Kannapolis, NC

  3. 2015 — 2023

    Aviation Security Operations Crew Chief

    American Airlines · Charlotte, NC

    Federally regulated operations under FAA, OSHA, IATA, and CBP requirements. Security clearance with CBP badge endorsement; international flight operations. Recurrent incident-response and safety/security training. High-accountability documentation, identity validation, and access control — eight years of it.

Credential

CompTIA Security+ ce (SY0-701)

Issued January 7, 2025 · valid through January 7, 2028.

Education

B.S. Information Technologies — Cybersecurity

Southern New Hampshire University. Completed December 2025, conferred January 1, 2026. Summa Cum Laude, 3.96 GPA · Sigma Psi chapter of Alpha Sigma Lambda.

Pull the full record — PDF

One page. Typed. Signed off.

Epilogue

Close the Case.

The office is open. Charlotte, North Carolina — remote works fine. If you're building a security operations team and want an analyst whose claims come with receipts, the channels are on the right.

“Somewhere in your stack, an alert is waiting to be read properly.
He reads them properly.