SYSTEM_ONLINE — available for cloud security engagements

Youssef Chalghoumi

Cloud Security Engineer|AI Security Researcher

youssef@soc:~/profile — zsh

// whoami --verbose

Cloud Security Engineer.

Cloud Security Engineer specializing in secure cloud architecture, DevSecOps, and autonomous security systems. Experienced in building hardened AWS environments, scalable detection workflows, SOC automation platforms, and AI-driven security tooling designed for contextual threat analysis and remediation orchestration.

10+

Production security systems

Shipped across AWS, GitLab CI/CD, SOC tooling, and agentic AI platforms.

Multi-account

AWS Shield Advanced

Org-wide DDoS protection via Terraform + Firewall Manager + Route53 health checks.

Minutes → Seconds

MTTR reduction

Event-driven AWS incident response with Lambda + CloudWatch enrichment.

GraphRAG + MCP

Snock cloud agent

Autonomous attack-path investigation with deterministic LLM tool routing.

// core_competencies

Defensive depth across cloud, code, and AI.

Skills clustered by the operational surface they cover — from edge to model context.

Cloud & Infrastructure

AWS Shield AdvancedAWS WAFAWS FMSGuardDutyIAMLambdaTerraformDockerKubernetes

DevSecOps

GitLab CI/CDAnsibletfsecTrivySonarQubedetect-secretsn8nPythonBash

Agentic AI

GraphRAGVectorRAGMCP (Model Context Protocol)LangChainNeo4jChromaDBOllamaLLM Tool Routing

SecOps

Trend Micro XDRTheHiveMITRE ATT&CKSplunkElasticsearchGrafanaIncident Response

// trace --route experience

A timeline of shipped security.

From perimeter networking to autonomous cloud defense.

Cloud Security Engineer

Pwn & Patch

Feb 2024 — Present

  • Architected a hardened multi-account AWS Shield Advanced strategy through Terraform and Firewall Manager, with Route53 health checks for automated DDoS mitigation workflows.
  • Implemented hardened GitLab CI/CD pipelines integrating tfsec, Trivy, detect-secrets, and SonarQube — preventing insecure Terraform deployments before release.
  • Redesigned endpoint security posture for a major energy services provider through Trend Micro XDR detection and response tuning.
  • Automated cloud incident response through CloudWatch + AWS Lambda, materially reducing alert triage and MTTR.
  • Conducted AWS Well-Architected Reviews and CIS Benchmark audits, delivering actionable remediation roadmaps.
  • Built Snock — an autonomous cloud security AI agent (GraphRAG + VectorRAG + MCP) — to accelerate attack-path investigation and auto-generate Terraform remediation.

Network Security Intern

OneTech Business Solutions

Feb 2023 — Jun 2023

  • Deployed Fortinet SD-WAN with IPS, HA, and ADVPN for resilient inter-site connectivity.
  • Configured FortiManager and FortiAnalyzer for centralized policy management and monitoring.
  • Hardened Cisco ASA firewall policies to enterprise compliance baselines.

Cyber Security Intern

KEYSTONE Group

Dec 2022 — Jan 2023

  • Built a CTF-based cybersecurity training platform focused on penetration testing scenarios.
  • Supported internal red team simulations evaluating SOC response effectiveness.

Network Administrator Intern

TOPNET

Jan 2022 — Mar 2022

  • Deployed Zabbix + Azure Monitor for bandwidth, uptime, and network health tracking.
  • Created operational dashboards improving infrastructure visibility and incident tracking.

// ls ./projects --featured

Selected projects I've built & shipped.

A curated archive of production systems, research builds, and tooling I've engineered across cloud security, DevSecOps, and agentic AI. Click any card for the full case study.