Subject profile // 02

The analyst
behind the alerts.

I'm Mahmoud — most people call me Michael. I spent eight years running aviation security operations for American Airlines in Charlotte: crew chief in a federally regulated environment, CBP badge endorsement, recurrent incident-response and safety training. The kind of job where access control, identity validation, and precise documentation aren't best practices — they're the floor.

That discipline is what I brought into cybersecurity. I finished my B.S. in Information Technologies (Cybersecurity concentration) at Southern New Hampshire University — Summa Cum Laude, 3.96 GPA — earned my CompTIA Security+ ce, and started building the kind of portfolio I'd want to review if I were the hiring manager: public, reproducible, and defensively framed.

The result is AgentForge and the ATT&CKLens Benchmark — projects with specifications, safety rules, acceptance tests, scorecards, and final reports. I don't ask anyone to take my word for it. I ship the evidence and the harness to re-run it.

Identity
Mahmoud ("Michael") Al Kurdi
Base of operations
Charlotte, NC · open to remote
Credential
CompTIA Security+ ce (SY0-701) · valid through Jan 2028
Education
B.S. Information Technologies — Cybersecurity, SNHU · Summa Cum Laude · 3.96 GPA · Alpha Sigma Lambda
Target roles
SOC Analyst · Cybersecurity Analyst · Detection Engineer · IR Analyst · Security Automation
Operating mode
Defensive only — detection & mitigation focus

Operating principles

How I work.

Not aspirations — these are patterns you can audit in the repos.

PRINCIPLE // 01

Evidence or it didn't happen

Every project ships with acceptance tests, scorecards, raw outputs, and logs. The ATT&CKLens repo keeps one branch per evaluated agent so anyone can re-run the harness and check the math.

PRINCIPLE // 02

Uncertainty is a feature

Good analysts say "No Clear Mapping" when the evidence doesn't support a call. My benchmark explicitly scores confidence handling, evidence citation, and analyst follow-up questions — because overconfident triage is how incidents get missed.

PRINCIPLE // 03

Defensive by default

All ATT&CK-mapped work here is framed for detection and mitigation. Safety rules and prompt-injection resistance are graded criteria in my benchmark, not afterthoughts.

PRINCIPLE // 04

Automate the repeatable

From adapter round-trip tests to a one-command benchmark harness, if a task will run twice, it gets a script, a runbook, and a checkpoint to roll back from.

Capability matrix

Loadout.

SOC / Security Operations

  • Alert triage
  • Security monitoring
  • Incident documentation
  • Log analysis
  • Evidence review
  • Authentication events
  • DNS investigation
  • Vulnerability awareness
  • Remediation planning
  • Escalation notes

Cybersecurity

  • MITRE ATT&CK
  • Defensive security
  • Prompt-injection resistance
  • Access control
  • Least privilege
  • Security documentation
  • Confidence scoring
  • "No Clear Mapping" handling
  • Analyst follow-up questions

AI / Automation

  • AI coding-agent evaluation
  • Reproducible benchmark design
  • Rubric-based scoring
  • Agent workflow documentation
  • Prompt architecture
  • Safety rules
  • Acceptance criteria
  • Automated reporting

Programming / Tools

  • Python
  • Gradio
  • JavaScript
  • Node.js
  • PowerShell
  • Bash
  • Git / GitHub
  • Markdown
  • JSON
  • YAML
  • HTML / CSS
  • pytest
  • npm

Want the full record?

The dossier has the complete work history, education, and certification detail — screen-readable and print-ready.