● ALERT #2026-MK-001 SEVERITY: HIRE STATUS: TRIAGED
True Positiveverified
Alert closed — the signal is real. Mahmoud ("Michael") Al Kurdi: Security+ certified SOC analyst & detection engineer with eight years of federally regulated security operations behind him and a habit of doing the work in public. Detections, benchmarks, automation — all of it auditable, because verified beats claimed.
title: Verified Detection Engineer Activity
id: MK-2026-001
status: stable
logsource: { product: career, service: public_evidence }
detection:
selection:
background: "8 years federally regulated security operations"
certification: "CompTIA Security+ ce (SY0-701)"
education: "B.S. Information Technologies — Cybersecurity · Summa Cum Laude · 3.96 GPA"
public_evidence: [AgentForge, ATT&CKLens Benchmark, detection projects]
practices: [acceptance_tests, scorecards, safety_rules, reproducible_runs]
condition: selection
falsepositives: [none observed] # check the repos yourself
level: high
Section 01 // Capability profile
Built for the
SOC floor.
The projects are receipts. This is what you're actually hiring.
Detect &
triage
Alert triage, log analysis, authentication and DNS investigations, evidence review — with escalation notes written so the next analyst doesn't have to redo the work.
Build &
automate
Python, Node, PowerShell, Bash. If analyst work repeats, it becomes a script, a harness, or a runbook — the same way my public tooling is built.
Perform under
scrutiny
Eight years of aviation security operations — CBP badge endorsement, recurrent incident-response training, and documentation that had to survive federal audits.
Section 02 // The receipts
Case files,
not claims.
Don't take the capability profile on faith — run the evidence. Public, reproducible, defensive by design.
Agent
Forge
One spec, many agents. A configuration framework that compiles a single canonical posture into platform-native files for Claude Code, Codex, Gemini CLI, Cursor, Aider, and generic workspaces — with round-trip tests, a doctor CLI, and a readiness runbook as proof.
Open file →ATT&CKLens
Benchmark
Can AI coding agents build secure, uncertainty-aware, MITRE ATT&CK-aligned defensive tooling? Seven agents. Identical specs. Prompt-injection challenges, rubric scoring, and a fully reproducible harness — first defensive-security benchmark in the AgentForge suite.
Open file →Section 03 // Signal history
The trail
so far.
-
2015 — 2023
Aviation Security Operations · American Airlines
Eight years as crew chief in federally regulated operations — CBP badge endorsement, recurrent incident-response training, and a daily diet of access control, identity validation, and documentation that had to be right the first time.
-
Jan 2025
CompTIA Security+ ce earned
SY0-701, valid through January 2028.
-
Dec 2025
B.S. Information Technologies — Cybersecurity
Southern New Hampshire University. Summa Cum Laude, 3.96 GPA, Alpha Sigma Lambda honor society.
-
2025 — 2026
AgentForge & ATT&CKLens shipped
Framework published to npm; benchmark published with scorecards, raw outputs, logs, and a final report. The portfolio became the proof.
Section 04 // Next action
Close this alert
with a conversation.
Open to SOC Analyst, Cybersecurity Analyst, Detection Engineering, Incident Response, and Security Automation roles. Charlotte, NC or remote.