Subject profile // 02
The analyst
behind the alerts.
I'm Mahmoud — most people call me Michael. I spent eight years running aviation security operations for American Airlines in Charlotte: crew chief in a federally regulated environment, CBP badge endorsement, recurrent incident-response and safety training. The kind of job where access control, identity validation, and precise documentation aren't best practices — they're the floor.
That discipline is what I brought into cybersecurity. I finished my B.S. in Information Technologies (Cybersecurity concentration) at Southern New Hampshire University — Summa Cum Laude, 3.96 GPA — earned my CompTIA Security+ ce, and started building the kind of portfolio I'd want to review if I were the hiring manager: public, reproducible, and defensively framed.
The result is AgentForge and the ATT&CKLens Benchmark — projects with specifications, safety rules, acceptance tests, scorecards, and final reports. I don't ask anyone to take my word for it. I ship the evidence and the harness to re-run it.
- Identity
- Mahmoud ("Michael") Al Kurdi
- Base of operations
- Charlotte, NC · open to remote
- Credential
- CompTIA Security+ ce (SY0-701) · valid through Jan 2028
- Education
- B.S. Information Technologies — Cybersecurity, SNHU · Summa Cum Laude · 3.96 GPA · Alpha Sigma Lambda
- Target roles
- SOC Analyst · Cybersecurity Analyst · Detection Engineer · IR Analyst · Security Automation
- Operating mode
- Defensive only — detection & mitigation focus
Operating principles
How I work.
Not aspirations — these are patterns you can audit in the repos.
Evidence or it didn't happen
Every project ships with acceptance tests, scorecards, raw outputs, and logs. The ATT&CKLens repo keeps one branch per evaluated agent so anyone can re-run the harness and check the math.
Uncertainty is a feature
Good analysts say "No Clear Mapping" when the evidence doesn't support a call. My benchmark explicitly scores confidence handling, evidence citation, and analyst follow-up questions — because overconfident triage is how incidents get missed.
Defensive by default
All ATT&CK-mapped work here is framed for detection and mitigation. Safety rules and prompt-injection resistance are graded criteria in my benchmark, not afterthoughts.
Automate the repeatable
From adapter round-trip tests to a one-command benchmark harness, if a task will run twice, it gets a script, a runbook, and a checkpoint to roll back from.
Capability matrix
Loadout.
SOC / Security Operations
- Alert triage
- Security monitoring
- Incident documentation
- Log analysis
- Evidence review
- Authentication events
- DNS investigation
- Vulnerability awareness
- Remediation planning
- Escalation notes
Cybersecurity
- MITRE ATT&CK
- Defensive security
- Prompt-injection resistance
- Access control
- Least privilege
- Security documentation
- Confidence scoring
- "No Clear Mapping" handling
- Analyst follow-up questions
AI / Automation
- AI coding-agent evaluation
- Reproducible benchmark design
- Rubric-based scoring
- Agent workflow documentation
- Prompt architecture
- Safety rules
- Acceptance criteria
- Automated reporting
Programming / Tools
- Python
- Gradio
- JavaScript
- Node.js
- PowerShell
- Bash
- Git / GitHub
- Markdown
- JSON
- YAML
- HTML / CSS
- pytest
- npm
Want the full record?
The dossier has the complete work history, education, and certification detail — screen-readable and print-ready.