Status: Secure Console Link Active

BUILDING SECURE ARCHITECTURES. ENGINEERING RESILIENT CODE.

Cybersecurity Engineer & Full-Stack Architect. Bridging the gap between robust infrastructure security, distributed systems, and modern, high-performance web applications.

The Narrative

How I entered the terminal

Growing up at the intersection of engineering and computing, I was always fascinated by how complex systems talk to each other—and how easily those channels can be compromised. This curiosity led me to Al Akhawayn University, where I earned my Bachelor of Science in Computer Engineering, cementing my foundation in low-level systems and network topologies.

During my academic and professional journey, I realized that building systems is only half the battle; securing them is where the real challenge lies. I shifted my focus towards cybersecurity, training myself to think like an adversary to construct stronger defenses. From designing custom DNS protocols with RSA/AES cryptography to validating complex remote rootkit attacks, I learned to navigate the lowest levels of system execution.

Today, I combine my engineering background with cybersecurity expertise to build AI-powered SOAR middleware, deploy distributed SOC architectures, and automate incident response using Python. I bridge the gap between secure system design and modern web deployment—leveraging tools like Next.js, Docker, Postgres, and Google Cloud Platform to engineer secure, resilient, and scalable digital environments.

identity_compile.sh
SECURE_SHELL: v2.4.1LOAD: 0.14 / 0.08

> ./identity_compile.sh

Compilation successful. Identity verified.
{
  "operator": "Taha Sakhi",
  "role": "Security Consultant",
  "education": "BS. Computer Engineering",
  "status": "Ready",
  "uptime": "00:00:00"
}
System: Debian 12Port: 3200

Core Competencies

Select an operational channel to dynamically filter projects and experiences below.

SOC Operations & Incident Response

Deploying multi-node Security Onion clusters, designing SOAR automated workflows, and analyzing threat intelligence using open-source SIEM solutions to minimize response latency.

Channel: 0xSOCSTANDBY
Cloud Observability & Hardening

Configuring central logging architectures, provisioning secure infrastructure via Google Cloud Platform & Azure, hardening systems, and implementing isolated containerization via Docker.

Channel: 0xCLOUDSTANDBY
Secure Full-Stack Engineering

Architecting robust, secure-by-design web platforms using Next.js, FastAPI, and Postgres, optimized for deployment via Vercel and secure API integration.

Channel: 0xDEVSTANDBY

Operational Records

System integrations, threat models, and software platforms developed by Taha.

Full-Stack DevID: CYBE-AEGIX
CybeAegix
  • Developed a containerized microservices app using FastAPI and React to aggregate vulnerability data from OpenCVE.
  • Built an enrichment engine using Google Pegasus-XSUM AI.
  • Engineered a many-to-many subscription model and RBAC system.
FastAPIReactPostgreSQLDockerGoogle Pegasus-XSUMOpenCVE
Review Case Study
Full-Stack DevID: SURFOOD-SAVE
Surfood Save
  • Engineered a highly concurrent platform deployed on GCP Cloud Run and Cloud SQL.
  • Developed an asynchronous FastAPI backend and a React Native mobile application.
  • Optimized geolocation queries using SQLAlchemy 2.0 with PostgreSQL GIN indexes.
GCP Cloud RunCloud SQLFastAPIReact NativePostgreSQL GINSQLAlchemy 2.0
Review Case Study
Cloud InfraID: SHADOW-WATCHER
Shadow Watcher
  • Designed an embedded C++ physical security system on Particle Photon fusing data from three LDRs and a PIR sensor.
  • Implemented an adaptive rolling baseline to dynamically compute sensor thresholds.
C++Particle PhotonIoTLDR SensorsPIR SensorRolling Baseline
Review Case Study
SOC OperationID: SECDNS-EXPLOIT-DEV
SECDNS
  • Developed a custom secure DNS protocol shifting from UDP to TCP.
  • Implemented an asymmetric RSA handshake coupled with AES-GCM for encrypted data payload integrity.
DNS ProtocolC LanguageTCPRSA HandshakeAES-GCM
Review Case Study
SOC OperationID: KERNEL-EXPLOIT-ANALYSIS
Remote Rootkit Attack Validation
  • Executed a full remote kill chain utilizing a CWE-78 web command injection to deliver a custom LKM rootkit.
  • Exploited the waitid() system call primitive (CVE-2017-5123).
Linux KernelLKM Rootkitwaitid()CVE-2017-5123CWE-78Kill Chain
Review Case Study
Full-Stack DevID: SECURITY-SIMULATION
Security Simulation Platform
  • Engineered a modular Demo Platform utilizing React 19 and Vite to simulate complex security scenarios.
  • Programmed a high-performance procedural 3D network topology globe using Three.js.
React 19ViteThree.jsWebGL3D Graphics
Review Case Study
Cloud InfraID: SECURE-ELK-STACK-ON-AZURE
Secure Elastic Stack on Azure
  • Architected an Observability pipeline deploying Elastic Stack on Azure VMs.
  • Enforced strict network security, node-to-node SSL/TLS encryption, and RBAC.
Elastic StackAzure VMsSSL/TLSRBACObservability
Review Case Study

Professional Trajectory

A chronological view of systems deployed and operations executed.

Cybersecurity Engineer

ITS, Al Akhawayn University

Jan 2024 - Present
  • Engineered a custom AI-powered FastAPI SOAR middleware integrating Groq LLMs (Llama 3.1/3.3), Alien Vault OTX, and VirusTotal for sub-second alert triage, multi-tiered threat enrichment, and autonomous Cortex XDR endpoint containment.
  • Implemented a PII Sanitization pipeline and SHA-256 behavioral caching.
  • Deployed a distributed Security Onion SOC architecture integrated with Palo Alto Cortex XDR, Entra ID, and M365 telemetry.
  • Implemented a centralized NOC using SolarWinds Observability for 250+ nodes.
  • Reduced MTTR by 60% by engineering tiered alert engines.
  • Authored 64 custom KQL detection rules and developed automated backend workflows to generate MITRE ATT&CK mappings.

Cybersecurity Consultant Intern

Innovatech Consulting

May 2025 - Sep 2025
  • Designed scalable, risk-based SOC architectures mapping business categories to tool-agnostic security controls.
  • Deployed an open-source baseline utilizing Wazuh, Security Onion, MISP, and Shuffle.
  • Enforced strict web and mail security policies including SSL/TLS inspection in Squid, and DKIM/SPF/DMARC in Rspamd.
  • Validated architectures through multi-stage attack simulations, achieving an 85% success rate in detecting memory-resident threats via custom Sigma rules.

SOC Analyst Intern

TECHSO GROUP

Jun 2024 - Sep 2024
  • Conceived and deployed an automated, 24/7 proactive CVE alerting system via OpenCVE APIs and PostgreSQL.
  • Developed Python backend scripts integrating NLP models to monitor NVD feeds.
  • Engineered a dynamic correlation engine utilizing SMTP and Jinja2 templating to deliver customized HTML security alerts.

Technical Trainer / Expert

Neurones Technologies & BCRG (Project)

Mar 2022 - May 2022
  • Delivered technical masterclasses to the Central Bank of the Republic of Guinea on the Allot ACG2000 communication gateway.
  • Trained engineering teams on Allot See, Allot Control, and Allot Secure.

Operational Arsenal

Technologies and tools mapped to my security and development pipelines.

> Security Operations

SIEMCortex XDRSecurity OnionSigma RulesVulnerability AnalysisCVENVD

> Observability & Analytics

Elastic StackSolarWindsGrafanaPrometheusELK

> DevOps & Full-Stack

PythonCDockerCI/CDAzureReactFastAPIPostgreSQL

Interactive CV Viewer

Preview or download my resume in French or English directly from the secure console.

Download PDF
PREVIEW INTERACTION ENABLED
SYSTEM_HIGHLIGHTS.TXTEN

Summary

Cybersecurity Engineer & SOC Consultant specializing in AI-driven incident response automation, secure-by-design integrations, and observability systems.

Core Skills

SIEM / SOARIncident AutomationNext.js / DockerPostgres / PythonGCP / Cloud Observability

Experience Highlights

Cybersecurity Engineer

ITS, Al Akhawayn University

Engineered AI SOAR, integrated Cortex XDR/Security Onion.

Cybersecurity Consultant Intern

Innovatech Consulting

Designed scalable SOC architectures, deployed Wazuh/MISP.

SOC Analyst Intern

TECHSO GROUP

Conceived 24/7 CVE alerting platform via OpenCVE API.

Technical Trainer / Expert

Neurones Technologies & BCRG

Delivered Allot ACG2000 communication gateway masterclasses.

Education

B.S. in Computer Engineering - Al Akhawayn University

Verification: Cryptographic Link ActiveSECURE

Establish Secure Link

Enter your credentials and transmission payload to initialize contact.

System Addresses

sakhitaha@gmail.com

Network Channels