Skip to content
AAAhtisham Ashraf
000

Security Practice

Security is architecture,not an afterthought.

A decade spent auditing, testing, defending and building systems — first as an auditor and penetration tester, later as the person accountable for an organisation’s security posture.

Certifications
CEH · CHFI · CND
Frameworks
ISO 27001 · NIST CSF · CIS · PCI DSS
Audit outcome
40+ critical vulnerabilities identified

Defence in depth

A conceptual model of layered security. Select a layer to see what it holds. This represents no specific deployment.

Edge & Perimeter

Traffic control, filtering and protective services in front of the platform.

Controls at this layer

  • Edge filtering
  • Rate control
  • DNS & routing policy

Practice areas

01

Security Leadership

Owning security posture at an organisational level: policy, governance, budget and the trade-offs between them. Security decisions are argued in business terms because that is where they are approved.

  • Security governance across engineering, infrastructure and operations
  • Technology policy and operating standards
  • Risk framed as business decisions rather than technical findings
  • Security integrated into vendor and procurement assessment

02

Application Security

Assessing and building applications with the trust boundaries drawn deliberately. Most application vulnerabilities are disagreements between components about who enforces what.

  • Application assessment across web and mobile surfaces
  • Authentication and authorisation design review
  • OWASP Top 10 as a baseline, not a ceiling
  • Secure development practice inside delivery

03

Cloud Security

Securing cloud estates where the perimeter is configuration rather than hardware. Misconfiguration is quieter than an application bug and frequently more expensive.

  • AWS and multi-environment security posture
  • Least-privilege access across infrastructure and data services
  • Storage and database exposure controls
  • Infrastructure hardening applied consistently across environments

04

Penetration Testing

Vulnerability analysis and controlled testing across applications, APIs and infrastructure, delivered as prioritised findings with remediation guidance engineering teams can act on.

  • Application, API and infrastructure testing
  • Vulnerability analysis and severity prioritisation
  • Traffic analysis and security monitoring
  • Findings paired with remediation guidance

05

API Security

When several clients share one backend, authorisation belongs in exactly one of them. API security work is mostly the discipline of keeping that true as the surface grows.

  • API authorisation and exposure review
  • Consistency across web, mobile and integration clients
  • Webhook and integration endpoint validation
  • Server-side credential handling

06

Network Security

Network architecture, firewall policy and segmentation across on-premise and cloud environments, with boundaries enforced at the network layer rather than by convention.

  • Network architecture and segmentation
  • Firewall policy design and management
  • Perimeter and remote access controls
  • Email security and organisational protection

07

Secure Development

Security positioned inside the delivery pipeline. If the secure path is slower than the insecure one, engineers will route around it — so the secure path has to be the fast one.

  • Secure code review across application codebases
  • Security checks inside CI/CD rather than after it
  • Secrets held outside code and version control
  • Environment separation through the promotion path

08

Vulnerability Management

Identification is the beginning. The work that matters is prioritisation, remediation tracking and reducing the window between a vulnerability existing and it being closed.

  • Assessment across application, cloud and infrastructure layers
  • Severity-based prioritisation
  • Remediation guidance and tracking
  • Delivery speed treated as a security control

09

Security Auditing

Structured audit engagements across application, protocol, code and infrastructure layers — including a blockchain platform audit that identified more than 40 critical vulnerabilities.

  • Full-surface audits rather than single-layer reviews
  • Blockchain, fintech and web platform engagements
  • Malware analysis and incident investigation
  • Digital forensics and disaster recovery

10

Governance

Working with recognised control frameworks because they give a technical position a shape non-technical stakeholders can evaluate and approve.

  • ISO 27001 information security management practices
  • NIST Cybersecurity Framework and CIS Controls
  • PCI DSS and GDPR principles
  • SOC 2 practices and applicable UAE requirements

Governance frameworks

ISO 27001
Information security management practices.
NIST Cybersecurity Framework
Identify, protect, detect, respond, recover.
CIS Controls
Prioritised technical safeguards.
PCI DSS
Payment data handling requirements.
GDPR Principles
Data protection and minimisation.
SOC 2 Practices
Operational and security controls.
UAE Security Requirements
Applicable local regulatory requirements.

Framework experience from security, infrastructure and governance work. Listed separately from personal certifications.

Certifications held

CEHCertified Ethical Hacker
EC-Council
CHFICertified Hacking Forensic Investigator
EC-Council
CNDCertified Network Defender
EC-Council

40+

Critical vulnerabilities identified

Historical security audit engagement — a blockchain platform assessed across its application, peer-to-peer layer, codebase and infrastructure. No vulnerability details, reproduction steps or exploit information are published.