
Ayman Abdul kareem
Verified Expert in Engineering
Security Architect and Developer
Dubai, United Arab Emirates
Toptal member since November 27, 2025
Ayman is a security architect, senior product security expert, and senior penetration tester with 8.5 years of experience securing applications and infrastructure. He currently drives initiatives in AI security, DevSecOps, cloud security, and security architecture. Ayman consistently bridges the gap between engineering and risk management to build resilient systems.
Portfolio
Experience
- VAPT - 9 years
- Penetration Testing - 9 years
- Infrastructure Security - 9 years
- Application Security - 9 years
- Secure Containers - 5 years
- Threat Modeling - 5 years
- Cloud Security - 4 years
Preferred Environment
Security Architecture, Threat Modeling, Product Security, Application Security, Penetration Testing, Infrastructure Security, Cloud Security, Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), Source Code Review
The most amazing...
...project I've worked on included security architecture, threat modeling, penetration testing, and cloud security for a major UAE bank, which enhanced resilience.
Work Experience
Security Architect, Senior Product Security Expert
Emirates NBD
- Led security implementation and reviews for genAI and cloud based use cases within the bank, ensuring robust protection against emerging threats.
- Worked closely with DevOps, development, and IT teams to integrate security practices into CI/CD pipelines, ensuring security was embedded throughout the development process without compromising speed or agility.
- Directed vulnerability management initiatives, prioritizing remediation efforts based on risk assessments, and collaborated with development teams to close security gaps efficiently.
- Ensured core applications adhered to relevant regulatory frameworks, conducted regular compliance assessments, and aligned security strategies with regulatory requirements.
- Executed thorough security reviews of back-end applications deployed in Azure infrastructure, leveraging components such as API Management, AppServices, Azure Cosmos DB, and OpenAI.
- Spearheaded threat modeling initiatives for a prominent US restaurant chain, analyzing and mitigating risks within their AWS cloud infrastructure to safeguard critical assets and customer data.
- Presented security initiatives as a primary security champion for multiple Agile squads, ensuring adherence to industry best practices.
- Conducted security reviews for the bank's core integration platform, conducting risk identification, impact analysis, and tracking to closure.
- Provided tailored patch support for identified risks, employing customized solutions scalable across diverse environments.
- Worked closely with product and engineering teams to prioritize and implement security features and controls, ensuring mitigation of identified risks.
Security Consultant
KPMG
- Reviewed and baselined network configurations, ensuring compliance with enterprise security policies, including ISO 27001 and NIST frameworks.
- Supervised user permissions across organizational systems, ensuring compliance with the principle of least privilege.
- Established continuous monitoring practices to detect and respond to emerging threats in cloud and on-premises environments.
- Crafted a comprehensive application security framework tailored to various software development lifecycle models, ensuring robust protection throughout the development process.
- Developed organizational policies, procedures, and guidelines, ensuring adherence to policy management frameworks, document control procedures, and version control systems.
- Implemented customized secure coding guidelines aligned with the organization's technology stack, enhancing resilience against emerging threats.
- Conducted engaging secure coding training sessions for developers, focusing on OWASP Top 10, SANS Top 25, and critical business logic vulnerabilities to promote a security-first mindset.
- Performed phishing simulations and social engineering awareness exercises, providing targeted training to enhance employee resilience against cyber threats.
- Led vulnerability assessment and penetration testing initiatives across diverse environments, covering servers, network devices, endpoints, web applications, and thick client applications using both automated and manual approaches.
- Supported the procurement team by evaluating proposals and identifying suitable vendors for network security solutions, including key management systems (KMS) and network access control (NAC), to strengthen overall infrastructure security.
Senior Security Analyst
Lucideus Technologies
- Conducted vulnerability assessment and penetration testing for a wide range of systems, including servers, network devices, and endpoints, employing both automated and manual methodologies.
- Specialized in Active Directory (AD) penetration testing, executing advanced test cases to uncover vulnerabilities leading to domain admin access, EDR bypass, and lateral traversal across systems.
- Led vulnerability assessment and penetration testing efforts for over 100 web applications and thick client applications, focusing on industry standards like OWASP Top 10 and SANS Top 25.
- Conducted security assessments for REST endpoints and SOAP web services, ensuring the integrity and resilience of critical APIs.
- Spearheaded Red Teaming assignments for prestigious clients in banking, financial institutions, and pharmaceuticals, simulating real-world attack scenarios to enhance defensive capabilities.
- Conducted wireless network penetration testing assessments, uncovering vulnerabilities in guest network implementations that could lead to unauthorized access to enterprise networks.
- Executed social engineering and physical security assessments within the financial sector, identifying weaknesses and recommending remediation strategies.
- Collaborated closely with clients to implement specific patches and remediation measures following security assessments, ensuring timely mitigation of identified vulnerabilities.
- Provided consulting services to companies across diverse sectors, offering tailored security solutions to meet their unique needs.
- Developed automation solutions for penetration testing controls, data exfiltration, and client-specific report generation, streamlining security processes and enhancing efficiency.
Security Consultant
Synopsys
- Conducted comprehensive vulnerability assessment and penetration testing across diverse platforms, including web applications, web services, web sockets, mobile applications (iOS and Android), and thick client applications.
- Led source code reviews for Java and JavaScript-based applications for a leading German multinational automotive corporation, ensuring code integrity and resilience against cyber threats.
- Spearheaded professional services assessments and managed technical projects for a prominent French multinational investment bank, focusing on web applications and thick client applications to enhance overall security posture.
- Developed Python scripts to automate manual processes during penetration testing and streamlined reporting, improving efficiency and the accuracy of assessments.
Experience
End-to-end Cloud Security Architecture and Threat Modeling Across AWS, APIs, and Applications
Application Security Framework, Secure Coding Guidelines, and Developer Training Program
Red Team Assessment for a Leading Bank in India
Comprehensive Offensive Security Assessment
The project involved performing secure code reviews to identify logic flaws, insecure patterns, and high-risk vulnerabilities early in the SDLC. Additionally, I conducted a comprehensive cloud configuration review to detect misconfigurations, privilege issues, and security gaps across IAM, networking, logging, and storage. The project delivered a complete vulnerability landscape and an actionable remediation roadmap.
Education
Bachelor's Degree in Computer Science
Visvesvaraya Technological University - India
Certifications
Certificate of Cloud Security Knowledge
Cloud Security Alliance
Oracle Cloud Infrastructure (OCI) Generative AI Certified Professional
Oracle
Microsoft Azure Security Engineer Associate (AZ- 500)
Microsoft
Offensive Security Certified Professional (OSCP)
Offensive Security
Skills
Libraries/APIs
Node.js, React
Tools
NMap, AWS IAM, OWASP Zed Attack Proxy (ZAP), Azure Key Vault
Paradigms
Penetration Testing, DevSecOps, Role-based Access Control (RBAC), Secure Code Best Practices
Platforms
Amazon Web Services (AWS), Azure, Google Cloud Platform (GCP), Kubernetes, AWS Lambda, Amazon EC2, Azure IaaS, Azure PaaS, Apache Kafka
Industry Expertise
Cybersecurity
Languages
Python, JavaScript, C, C++, GraphQL, Java, TypeScript
Frameworks
Next.js, OpenVAS
Storage
PostgreSQL, Database Management, Azure Active Directory, Microsoft Entra ID
Other
Product Security, Application Security, Infrastructure Security, Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), Source Code Review, VAPT, Security Architecture, IT Security, Security, AWS Secrets Manager, Web App Security, Network Segmentation, OWASP, Vulnerability Triage, Web Application Security (Web AppSec), Web Security, Mobile Security, Security Audits, White-hat Hacking, White-hat Security, Certified Ethical Hacker (CEH), OSCP, Security Engineering, AWS Cloud Architecture, Vulnerability Management, Ethical Hacking, Threat Modeling, Cloud Security, Secure Containers, Network Security, AI Security, Infrastructure as Code (IaC), Wordfence Security, AI Trust, Risk and Security Management (AI TRiSM), Data Encryption, SecOps, Cloud Infrastructure, Fintech, Microsoft Azure, Cloud Platforms, Access Control, Relational Database Services (RDS), SOC Compliance, Reporting, Reports, Software Engineering, Machine Learning, Data Structures, Security Automation, Red Teaming, Social Engineering, GRC, Azure Cloud Security, Artificial Intelligence (AI), Retrieval-augmented Generation (RAG), Generative Artificial Intelligence (GenAI), Training & Training Content Development, Kubernetes Security, CI/CD Pipelines, Wiz Cloud Security Platform, PCI, NIST, SOC 2, Identity & Access Management (IAM), Risk Management, GitHub Actions, Large Language Models (LLMs), FastAPI
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring