Skip to content
View ibrahimsaleem's full-sized avatar
🎯
Focusing
🎯
Focusing

Highlights

  • Pro

Block or report ibrahimsaleem

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ibrahimsaleem/README.md
header

Typing SVG

profile views

🧭 About Me

AI Security & Governance Engineer securing enterprise-scale LLM, GenAI, MCP, and agentic AI systems — and a solo founder shipping AI products end-to-end (HireEase, WarmNode).

9+ years of hands-on software development across self-directed projects, freelance work, startups, internships, research, and enterprise roles. I work across AI threat modeling, adversarial testing, red teaming, secure AI SDLC, AI governance, and runtime security controls — turning ad-hoc AI risk work into repeatable, measurable, auditable engineering.

Risk focus: prompt injection · jailbreaks · tool poisoning · sensitive data leakage · excessive agency · insecure MCP servers · unsafe RAG · missing runtime controls

» prompts        = untrusted input
» retrieved ctx  = assume poisoned
» agents         = least privilege
» tool use       = monitored at runtime
» every decision = auditable evidence

📊 Impact by the Numbers

Metric Result Where
AI use-case review & permit-to-operate 10–12 days → under 6 min (automated agentic review pipeline) AT&T
LangGraph governance pipeline audit 29 issues / 7 runs — incl. critical fail-open ("APPROVED" regardless of logic) AT&T
LLM red-team harness 415 adversarial prompts, full OWASP LLM Top 10, MITRE ATT&CK, CI regression gate AT&T
Enterprise AI security controls authored 42 controls / 9 categories (incl. voice-agent controls) AT&T
"Contact Us" GenAI automation 20+ hrs/week saved, 0 critical vulns, 50+ emails/day @ 95% accuracy NOV
Self-improving MUD report parsing 360× faster (8 min vs 2 days), 89–100% accuracy, 0 incidents NOV (SPE 2026)
LIMA pentest framework 95% success rate, 8+ hrs → 15 min UH (IEEE FMLDS 2025)
PentestThinkingMCP 90% accuracy / 50+ scenarios, HTB "Lame" in 3 min @ ~$0.03/run UH
PentestThinkingMCP in production ~10,000 monthly tool calls @ 99.99% reliability on Smithery · Claude / Cursor / VS Code OSS
SwitchLane cost-aware routing 40.5% cost reduction @ 100% pass rate (1,500-prompt benchmark) · 74.6% in live chat · ~1 ms routing OSS
LLM vs. expert pentesters benchmark 12/15 HTB boxes, ~95% cost reduction UH
HireEase / AplyEase (founder) 40,000+ applications processed · 300+ clients · applied to YC Founder
WarmNode (founder) Solo-built AI networking PWA · YC Fall 2026 application submitted Founder

💼 Experience

🛡️ AI Security & Governance Engineer — AT&T · Plano, TX (Hybrid) · Jan 2026 – Present
  • Designed and secured enterprise AI governance / permit-to-operate workflows for GenAI and agentic systems on Azure (Key Vault, Managed Identities, Defender for Cloud, Azure OpenAI).
  • Led a manual security audit of a 15-node LangGraph governance pipeline — uncovered 29 issues incl. a critical fail-open defect; delivered a peer-validated remediation plan.
  • Built a provider-agnostic LLM red-team harness — 415 adversarial prompts, OWASP LLM Top 10, MITRE ATT&CK scenarios, LLM-as-judge + canary detection, MAP-Elites landscape, CI regression gate; authored Sigma rules and monitored runs in Splunk ES.
  • Ran multi-phase adversarial testing / red teaming (250+ prompts) on advanced enterprise LLM & agentic systems pre-deployment.
  • Built privacy-preserving tokenization & masking for enterprise networking data (IPs, VLANs, infra metadata) preserving topology + semantics.
  • Authored 42 AI security controls / 9 categories feeding the supplier AI requirements framework; contributed to an enterprise agentic-security control plane (AI observability/telemetry, LangGraph workflow design) aligned with zero-trust, NIST AI-RMF, secure AI SDLC.
🤖 GenAI Data Scientist — NOV Inc. (National Oilwell Varco) · Houston, TX · Jun 2025 – Jan 2026
  • Contact Us AI Automation & Email Responder — AWS-hosted (Bedrock) routing engine grounded in indexed company content; threat-modeled against direct/indirect prompt injection & jailbreak per OWASP LLM Top 10 + Agentic AI Threat Modeling. 0 critical vulns, 100% compliance, 20+ hrs/week saved, 50+ emails/day @ 95% accuracy.
  • Self-Improving MUD Report Automation — 3-agent GenAI system (vendor detection → prompt optimization → extraction), Azure Document Intelligence OCR + Azure OpenAI GPT-4o/5, eval DB + job pipeline on Databricks. 89–100% accuracy, 360× speedup (8 min vs 2 days), 0 incidents. Published as "Self-Improving Generative AI Agents for Automated Daily Mud Report Parsing", IADC/SPE 2026 (DOI).
  • Secured MCP Server for Expression Language conversion — mitigated command injection (RCE), weak auth, missing rate limits, tool poisoning; fine-tuned a Code-Llama 8B model; enabled secure EL conversion for 5+ internal tools.
  • Consulted data scientists / automation engineers on secure agentic coding and tested their AI solutions.
🔬 Research Assistant – AI & Cybersecurity — University of Houston · Houston, TX · Sep 2024 – May 2025
  • Pioneered LIMA (first author) — LLM-driven, MCP-based penetration-testing framework; 95% success rate, 8+ hrs → 15 min.
  • Engineered PentestThinkingMCP — reasoning agents + Nmap / Metasploit / Burp Suite across 50+ scenarios (90% accuracy); secured with prompt-injection defenses, I/O validation, rate limiting. Live
  • Established a quantitative benchmark: Claude 3.5 outperformed expert pentesters on 12/15 HTB boxes (~$0.05/run). Authored IEEE FMLDS 2025 paper.
🌐 Software Engineer — Conceptech Solutions · Dubai, UAE (Remote) · Mar 2024 – Aug 2024
  • Led a small engineering team delivering secure, customized web solutions for clients with React.js, Angular.js, and vanilla JavaScript.
  • Worked directly with clients to translate requirements into resilient, performant applications — secure coding practices and threat modeling, owning delivery timelines end-to-end.
💻 Associate Software Engineer — Nagarro Software Pvt. Ltd. · Mar 2023 – Feb 2024
  • Built secure .NET Core (C#) / SQL Server backend + React frontend for a banking client — secure coding, input validation, SQLi prevention, query optimization (30%) across 25+ APIs.
  • Delivered secure REST APIs with JWT, RBAC, OWASP compliance — 1000+ daily requests, 99.9% uptime across 6+ apps.

🚀 Founder & Ventures

Two AI products I founded and build end-to-end — product strategy, AI architecture, full-stack delivery, and security.

HireEase  ·  AplyEase — Founder & AI Product Engineer · Nov 2024 – Present

AI-powered "done-for-you" job-application platform — automated résumé tailoring + ATS optimization + job matching, paired with trained human specialists who apply on the client's behalf through a real-time tracking dashboard.

  • 40,000+ job applications processed for 300+ clients. Applied to Y Combinator.
  • Full-stack TypeScript: React 18 / Vite / Tailwind / Radix + Express / Drizzle ORM / PostgreSQL, Passport + JWT + bcrypt, Zod schema shared across client & server.
  • Built the AI résumé-tailoring engine, a LaTeX → PDF pipeline, and a role-based (Client / Employee / Admin) employee-operations portal for application and payment tracking.
  • Public components: aplyease-backend · aplyease-frontend · aplyeasedash · hireeaseemployee

WarmNode (WarmNodeAI) — Founder & AI Engineer · Apr 2026 – Present

Privacy-focused AI relationship assistant — helps you find who in your network can help, why they matter, and what message to send. Own product strategy, AI architecture, and full-stack delivery.

  • Solo founder · YC Fall 2026 application submitted · pre-seed.
  • Mobile-first PWA: React / TypeScript / Vite + Node / Express / TypeScript, PostgreSQL (Supabase) / Drizzle ORM, custom secure JWT auth (no third-party provider).
  • Google Gemini for semantic contact categorization and natural-language network queries (graceful local-keyword fallback); CSV contact import and Apple Wallet pass (.pkpass) generation for shareable, privacy-conscious professional profiles.

Freelance / Conceptech Solutions — Client web delivery · 2024

Led a small team building secure customized web apps for clients (React / Angular), owning delivery end-to-end — see Experience above.

🚀 Featured Projects

📖 Full catalogue of all 62 repositories, categorised with context for each → PROJECTS.md

Project What it does Focus / Stack
PentestThinkingMCP 📌 AI-powered pentest reasoning engine (MCP server) for attack-path planning, CTF/HTB solving, automated workflows — ~10,000 monthly tool calls @ 99.99% reliability on Smithery, integrated across Claude, Cursor & VS Code MCP · Beam Search · MCTS · Metasploit/Nmap/Burp — IEEE paper
ClawProtect 📌 · paper Content-aware security proxy for AI agent gateways (prompt injection / PII / secrets detection), unified with an eBPF kernel monitor and egress firewall by a cross-layer event bus for adaptive response across app / network / kernel layers Go · Python · eBPF · Prometheus
SwitchLane · demo Cost-aware LLM request routing — a single classifier call (~1 ms, no dual model calls) picks one model per request. Benchmarked: 40.5% cost reduction at 100% task pass rate (3 configs, same 1,500 prompts, real token usage & API pricing); 74.6% savings in a live chat session Python · FastAPI · RouteLLM · llm-cost-aware-routing (validation)
Saleem Harness Actively-developed personal coding-agent CLI (saleem), plugin-based on the Cordis composability framework, with a default-on preventive tool-call safety guard that blocks unsafe tool executions before they run (not logging after the fact) TypeScript · pnpm workspace · plugin architecture
EncoderThinkingMCP 📌 MCP server guiding LLMs through encoder-decoder ML training via Beam Search + MCTS MCP · PyTorch/TensorFlow/Keras — IEEE Southwest 2026
TokenLess / TokenWatch 📌 Token-optimization hub + dependency-free local LLM cost-tracking library; packages reusable AI skill packs (token/cost tracking, context optimization, enterprise efficiency guidelines) that plug directly into Claude Code, Windsurf, MCP agents & Copilot Python · LiteLLM gateway · guardrails · prompt compression
UltraSearch 📌 Lightning-fast laptop-wide RAG search built on LEANN vector DB Python · Streamlit · Sentence Transformers · FAISS/HNSW
LLM Red-Team Library Provider-agnostic red-team harness — 415 adversarial/bias/hallucination prompts, MAP-Elites landscape, CI regression suite Python · OWASP LLM Top 10 · LLM-as-Judge
LocalRAGAgent Offline, privacy-preserving RAG pipeline Python · on-prem LLM
ML DDoS Detection ML-based network monitoring & DDoS detection Python · ML

🛠️ Current Work Streams

Active building threads — agent-security tooling, guardrails, and LLM cost control.

Work Stream What I'm building Stack
Compass (contributor) Team-built multiplayer AI agent platform with the Ward guardrail layer (screens external data / tool results, command policy, human-approval gates); I contribute on the guardrail / security side TypeScript · Fastify · Postgres · Slack Bolt · Lit
dsh-dashboard Local real-time observability dashboard for agent harnesses — token usage, cost, live tool calls, security-risk signals, straight from session logs Node.js · Express · SSE
mcp-security-lab Runnable lab with 7 intentional MCP-server vulnerabilities + fixed versions + working exploits, with a live WebSocket exploit dashboard Python · FastMCP · Uvicorn

📚 Research

Paper Venue Status
LIMA: Leveraging Large Language Models and MCP Servers for Initial Machine Access — first author · Paper IEEE FMLDS 2025 ✅ Published
Self-Improving Generative AI Agents for Automated Daily Mud Report Parsing — second author · DOI: 10.2118/230772-MS IADC/SPE International Drilling Conference & Exhibition, 2026 ✅ Published
EncoderThinkingMCP: Guided Encoder-Decoder Model Development via MCP — w/ T. Banerjee IEEE Southwest 2026 🧪 Experiment phase
Agentic Lean Embedding System for Vulnerability Discovery — lead researcher — 🔬 Active research
Auto ARC: AI-Powered Floor Plan Generation for Architectural Workflow Optimization — w/ M. Raza IEEE SoutheastCon 2026 📝 To be submitted

🎓 Education

Institution Degree Detail
University of Houston M.S. Cybersecurity · Expected May 2026 GPA 3.98/4.0 · $16K scholarship
Rajiv Gandhi Proudyogiki Vishwavidyalaya B.Tech, Computer Science Engineering July 2023

Coursework: Network Security · Secure Enterprise Computing · Cryptography · Data Analysis for Cybersecurity · Cybersecurity Risk Management · Secure Software Design

🧰 Tech & Tooling


AI Security & Testing

Prompt Injection Defense Jailbreak Testing AI Red Teaming MCP Security Secure RAG MAP-Elites / Quality-Diversity AI Observability (OTel / Arize) Data Poisoning Mitigation

Governance & Frameworks

OWASP Top 10 for LLMs OWASP Agentic AI Threat Modeling NIST AI-RMF ISO/IEC 42001 Secure AI SDLC AI Lifecycle Mapping

Security Tooling

Burp Suite Metasploit Nmap Wireshark Splunk ES Sigma Rules Cortex XSOAR / XSIAM Semgrep GitLeaks Trivy Prisma AIRS

AI / LLM Stack

LangChain LangGraph MCP Hugging Face Ollama / Llama Google Gemini Anthropic API Azure OpenAI Azure AI Foundry Azure AI Search Azure Document Intelligence Databricks RouteLLM LiteLLM

Cloud & Full-Stack

AWS (EC2 · Lambda · Bedrock · SES) Azure (Key Vault · Managed Identities · Defender for Cloud) React / Vite Node · Express .NET Core Angular PostgreSQL · Supabase · Drizzle ORM Docker · Kubernetes Terraform GitLab CI/CD

Certifications: OWASP Top 10 for LLMs · Microsoft Certified: Azure AI Engineer Associate · Azure AZ-900 · Azure AI-900 · ISC2 CC · Fortinet NSE 1–3 · Security+ (in progress)

🔐 How I Think About AI Security

flowchart LR
    U[Untrusted Prompt] --> G{Guardrail Layer}
    R[Retrieved Context<br/>assume poisoned] --> G
    G -->|filtered| A[Agent<br/>least privilege]
    A --> T{Tool Broker}
    T -->|scoped + rate-limited| X[Tools / MCP Servers]
    A --> O[Observability<br/>telemetry + canaries]
    T --> O
    O --> P[Permit-to-Operate<br/>audit + evidence]
Loading

📈 GitHub Activity

contribution snake

🤝 Connect

Building secure AI systems means controlling what the model can see, what the agent can do,
what the tools can access, and what the enterprise can prove afterward.

Pinned Loading

  1. PentestThinkingMCP PentestThinkingMCP Public

    A systematic, AI-powered penetration testing reasoning engine (MCP server) for attack path planning, CTF/HTB solving, and automated pentest workflows. Features Beam Search, MCTS, attack step scorin…

    JavaScript 38 8

  2. ClawProtect ClawProtect Public

    Go 1

  3. TokenLess TokenLess Public

    Python 1

  4. CareerPathAgent CareerPathAgent Public

    🤖 AI-Powered Career Certification Roadmap Agent | Personalized learning paths for Cybersecurity, Data Science & AI Engineering with interactive SVG tutorials | Built with Flask + Google Gemini AI

    Python 2

  5. saleem-coding-agent saleem-coding-agent Public

    Saleem Harness — a personalized coding agent

    TypeScript

  6. switchlane switchlane Public

    Cost-aware LLM request routing with a live chat UI showing per-message and session cost savings, powered by RouteLLM

    Python