Skip to content
View RiadMoudjahed's full-sized avatar

Block or report RiadMoudjahed

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
RiadMoudjahed/README.md

👋 Hi, I'm Riad Moudjahed

AI Security Engineer building security frameworks for LLMs and RAG systems. I design end-to-end security programs for production AI systems—from red teaming and vulnerability assessment to operational controls, incident response, and compliance. Currently building complete RAG security engineering framework, 22 AI red team labs, ModelGuard ML scanner, and AI-powered security tools. Looking for remote AI Security Engineer opportunities.


🤖 AI Security Projects

🎯 AI Red Team Lab Series

Built 22 hands-on labs teaching LLM adversarial attacks across 4 difficulty tiers (Easy → Expert). Covers prompt injection, jailbreaking, model manipulation, guardrail bypasses, and advanced evasion techniques for GPT, Claude, and Llama models.

A comprehensive security analysis tool that scans AI/ML models for malicious code, backdoors, and security vulnerabilities. It uses advanced detection techniques including entropy analysis, pattern matching, and optional AI-powered deep analysis via local Ollama for 100% privacy.

Automated security auditing tool for Google Cloud AI/ML services. Scans Vertex AI models, AI Platform resources, and ML workflows for misconfigurations, policy violations, and security risks. Generates compliance reports aligned with cloud security best practices.

Automated network threat detection using Ollama LLMs + Scapy. Analyzes packet captures with AI to detect DDoS, port scans, and suspicious patterns. Tested on 11K+ packets — identified DDoS attack (56% traffic concentration), extracted IOCs automatically, generated actionable security reports.

Python tool combining Isolation Forest ML (92% accuracy, 67% fewer false positives) with Ollama LLM analysis for intelligent C2 detection. Processes 15K+ logs in <3 seconds, generates natural language threat reports explaining findings in SOC analyst terms.


🔧 Cloud & Traditional Security Projects

Comprehensive security assessment tool for Google Cloud Platform. Automates security audits across IAM, Compute Engine, Cloud Storage, networking, and logging configurations. Identifies misconfigurations, generates risk reports, and provides remediation recommendations aligned with CIS GCP benchmarks.

Enterprise-grade SOC infrastructure with VMware, pfSense, Wazuh SIEM. Real-world threat detection, network segmentation, SPAN port mirroring for forensic analysis. 35+ completed labs covering incident response, threat hunting, and SIEM rule creation.

15+ guided exercises teaching static/dynamic malware analysis with Ghidra, dnSpy, Wireshark. Custom keylogger sample for hands-on learning: hash identification, PE analysis, PCAP inspection, IOC extraction.

Live exploitation + mitigation demo for OWASP Top 10. Vulnerable vs. secure Python login systems showing parameterized queries and bcrypt authentication.

Full vulnerability management lifecycle: scanning, CVE prioritization (CVSS scoring), remediation planning for simulated infrastructure.


📊 Technical Arsenal

AI Security & Red Teaming
LLM Adversarial Attacks · Prompt Injection · Jailbreaking · Model Manipulation · OWASP LLM Top 10 · Adversarial ML

Cloud Security
Google Cloud Platform (GCP) · Cloud IAM · Cloud Security Posture Management · CIS Benchmarks · Cloud Audit Logging

AI/ML Development
Python (Scikit-learn, Pandas) · Ollama Integration · Isolation Forest · Scapy · Feature Engineering

Security Operations
Wazuh SIEM · Nessus · IDS/IPS · PCAP Analysis · Threat Hunting · Incident Response

Malware & Forensics
Ghidra · dnSpy · Binary Ninja · Autopsy · FTK Imager · Volatility · Wireshark · IOC Extraction

Development & Automation
Python · Bash · SQL · Secure Coding · API Integration · Security Tool Development

Frameworks
MITRE ATT&CK · NIST Cybersecurity Framework · OWASP Top 10 · OWASP LLM Top 10

Python PowerShell Bash Script PyTorch NumPy AWS Google Cloud


✍️ I Write About Security

📖 15 technical articles on Medium (570+ reads)

Recent posts:


🎓 Certifications

  • Google Cloud Cybersecurity Certificate (2026)
  • Securiti - AI Security & Governance (2025)
  • Google Cybersecurity Professional Certificate (2025)
  • IBM Cybersecurity Analyst Professional Certificate (2025)

📫 Let's Connect

Discord LinkedIn Medium

Open to: AI Security roles · SOC Analyst · Security Researcher · Remote opportunities (US/Europe/Middle East)


"Tawakkul, consistency, and passion — my formula for growth."


⚡ Quick Stats:
🤖 22 AI Red Team Labs | 🔍 Solved 35+ SOC Labs | 📝 15 Security Articles | 🛠️ 5+ Open-Source Tools


Pinned Loading

  1. SOC-Analyst-Projects SOC-Analyst-Projects Public

    Welcome 🙋‍♂️ Check my SOC Operations projects

    Python 1

  2. Keylogger_MalwareAnalysis_Lab Keylogger_MalwareAnalysis_Lab Public

    Hey 👋, This Lab was made by Riad Moudjahed, a friendly malware analysis lab. "README" contains everything you need.

    1

  3. AI-Powered-PCAP-Analyzer AI-Powered-PCAP-Analyzer Public

    Analyze PCAP files using ANY Ollama AI model (Llama, Mistral, Qwen, etc.), Detect DDoS attacks, port scans, and suspicious traffic patterns Identifies IOCs (IPs, ports, domains) automatically, Get …

    Python 2

  4. GCP-AI-Security-Auditor GCP-AI-Security-Auditor Public

    A tool that audits GCP environments hosting AI/ML workloads for security misconfigurations.

    Python 1