Available for enterprise DevSecOps engagements

DevSecOps Engineer

Hossam Ibraheem

0x70ssAM · Riyadh, Saudi Arabia

I build the security layer inside CI/CD pipelines—integrating SAST, SCA, DAST, and IAST so vulnerabilities are addressed before production. Enterprise tooling. Kubernetes-native. Shift-left by default.

View projects Experience

3+
Years in DevSecOps
40%
Vulnerability reduction
5
Government clients
50+
Code flaws remediated

Profile

About me

I'm a DevSecOps Engineer with 3+ years of hands-on experience embedding security into the software delivery lifecycle at enterprise scale. Currently based in Riyadh, serving as Xacta Solutions' DevSecOps representative for BlackDuck—their global SCA/SAST technical partner.

My background spans both sides of the security fence: I started in penetration testing and CTF competitions, then moved into infrastructure and DevOps, and now work at the intersection—making CI/CD pipelines actually secure. I've led tooling implementations for national-level clients including NEOM, Jeddah Municipality, SWCC, the Ministry of Communications, and Royal Protocol through Zinad IT's OpenText partnership.

I hold CKS and CKA certifications, an eWPTX for web application penetration testing, and an RHCSA—covering both offense and defense. When I'm not hardening pipelines, I write in-depth technical guides and compete on HackTheBox and CyberTalents.

Current role
DevSecOps Engineer · Xacta Solutions, Riyadh
Education
B.Sc. Computer & Information Science · Mansoura University, 2022
Languages
Arabic (Native) · English (B2)
Specialty
CI/CD Security · SAST · SCA · DAST · IAST · Kubernetes Security
CTF
HackTheBox · CyberTalents · Portswigger · SYber CTF 2nd Place

Career

Experience

3+ years delivering enterprise-grade DevSecOps across government, defense, and critical infrastructure sectors in KSA and Egypt.
  1. Nov 2025 – Present

    DevSecOps EngineerCurrent role

    Xacta Solutions · Riyadh, KSA | BlackDuck Global Technical Partner

    • BlackDuck SCA
    • SRM
    • Coverity
    • SAST · DAST · IAST
    • On-Premises
    • Enterprise CI/CD
    • Act as DevSecOps Engineer and BlackDuck technical representative in enterprise on-premises client engagements.
    • Lead end-to-end integration of SCA, SAST, IAST, and DAST toolchains into existing CI/CD pipelines.
    • Design and maintain DevSecOps workflows embedding continuous security validation across every SDLC phase.
    • Collaborate with development teams on vulnerability analysis, triage, and remediation workflows.
  2. May 2024 – Nov 2025

    DevSecOps Engineer

    Zinad IT · Smart Village, Egypt | OpenText Representative

    • Fortify SSC
    • ScanCentral
    • WebInspect
    • Seeker IAST
    • Sonatype Nexus IQ
    • NEOM
    • Jeddah Municipality
    • SWCC
    • MOC
    • Royal Protocol
    • Led OpenText security tooling implementation for 5 strategic government and enterprise clients.
    • Integrated SAST and DAST into CI/CD pipelines, reducing pre-production vulnerabilities by 40%.
    • Streamlined dependency tracking via Sonatype Nexus IQ, cutting critical library issues by 30%.
    • Performed secure code reviews uncovering and remediating 50+ code-level security flaws.
    • Delivered enterprise knowledge-transfer sessions on Fortify SSC, Black Duck, and Seeker.
    • Conducted Vulnerability Assessments and Threat Modeling across client environments.
    • Pre-productionvulnerabilities ↓ 40%
    • Criticaldependencies ↓ 30%
    • Codeflaws 50+ fixed
    • 5strategic clients
  3. Apr 2024 – Mar 2025 · Part-Time

    DevOps Engineer

    CTF.ae · UAE

    • Azure
    • Terraform
    • CI/CD
    • CTF Infrastructure
    • Deployed and managed secure Azure cloud infrastructure via Terraform IaC for CTF competition events.
    • Automated challenge deployment pipelines for reliability and scalability under competition load.
  4. Mar 2024 – May 2024

    Infrastructure Engineer

    EG-CERT · Egyptian Computer Emergency Readiness Team · Smart Village, Egypt

    • Proxmox
    • VMware ESXi
    • FortiGate
    • Maintained virtual infrastructure across Proxmox and VMware ESXi hypervisors.
    • Configured FortiGate firewalls and implemented secure backup and recovery strategies.

Work

Featured projects

Enterprise implementations, reference platforms, and public knowledge artifacts built across my career.

Cloud-Native DevSecOps Platform

End-to-end enterprise platform: Terraform (IaC) → Ansible (configuration management) → Kubernetes → Tekton (CI) → ArgoCD (GitOps). Policy-as-Code with OPA/Conftest and centralized vulnerability management through DefectDojo.

  • Terraform
  • Ansible
  • Tekton
  • ArgoCD
  • Trivy
  • Checkov
  • Gitleaks
  • OPA
  • DefectDojo
Read article

Secure Azure DevOps CI/CD Pipeline

Production-ready pipeline in Azure DevOps with SAST, DAST, SCA, secrets scanning, and compliance-gate enforcement at each SDLC stage—from commit to deployment.

  • Azure DevOps
  • SAST
  • DAST
  • SCA
  • Compliance Gates
  • Secret Scanning
Read article

DevSecOps Roadmap 2026 — 17-Phase Guide

A comprehensive roadmap synthesizing NIST SSDF, OWASP SAMM/ASVS/DSOMM, and Practical DevSecOps 2026, from foundations through eBPF runtime security, SLSA, SBOM, and AI/ML threat surfaces.

  • NIST SSDF
  • OWASP SAMM
  • SLSA
  • SBOM
  • Zero Trust
  • eBPF
Read article

Fortify SSC 24.4 on Kubernetes / Helm

Production deployment guide for Fortify SSC 24.4 on Kubernetes, including air-gap constraints, Helm pull and custom-values patterns, and enterprise on-premises considerations from real client deployments.

  • Kubernetes
  • Helm
  • Fortify SSC
  • Air-Gap
  • On-Premises
Read article

Hardened K8s DevSecOps Lab

Single-node Kubernetes lab on Ubuntu 24.04 with Calico/Cilium NetworkPolicy enforcement, Falco eBPF runtime security, Falcosidekick alerting, and air-gapped Helm deployment patterns.

  • Kubernetes
  • Calico
  • Cilium
  • Falco
  • Falcosidekick
  • eBPF
  • Air-Gap
GitHub

Trusted Online Voting System (TOV)

B.Sc. graduation project, awarded an Excellent grade: a cryptographically secure, privacy-preserving voting platform for transparent elections and collective decision-making. Mansoura University, 2022.

  • Cryptography
  • Privacy
  • Secure Design
  • B.Sc. 2022
GitHub

Writing

Selected writing

Long-form guides on DevSecOps architecture, CI/CD security, and cloud-native tooling.
DevSecOps · Interactive Roadmap · Open Source

DevSecOps Roadmap — From Foundations to Expert

An open-source interactive roadmap covering 17 phases, from Linux fundamentals to cloud-native defense, eBPF runtime security, and AI/ML threat surfaces. Read article
DevSecOps · Cloud Native

DevSecOps Roadmap 2026: From Foundations to Expert

A 17-phase guide synthesizing NIST SSDF, OWASP SAMM, and DSOMM. Read article
DevSecOps · Architecture

Building a Cloud-Native DevSecOps Platform End-to-End

Terraform, Ansible, Tekton, ArgoCD, OPA Policy-as-Code, and GitOps security gates. Read article
DevSecOps · Azure

End-to-End DevSecOps CI/CD with Azure DevOps

A secure Azure DevOps pipeline with SAST, DAST, SCA, and compliance gates at every stage. Read article
DevSecOps · Kubernetes

Deploying Fortify SSC 24.4 on Kubernetes via Helm

A production guide to Helm customization, air-gap constraints, and enterprise deployment patterns. Read article
Penetration Testing

CTF Writeups & Penetration Testing Notes

Field notes from SYber CTF, HackTheBox, Portswigger Academy labs, and CyberTalents challenges. Read article

Capabilities

Technical skills

Application Security

  • SAST
  • DAST
  • IAST
  • SCA
  • SBOM
  • Threat Modeling
  • Secure Code Review
  • Vulnerability Assessment
  • Web App Pentesting

Enterprise Tooling

  • BlackDuck SCA/SRM
  • Coverity
  • Fortify SSC
  • ScanCentral
  • WebInspect
  • Seeker IAST
  • Sonatype Nexus IQ
  • DefectDojo

CI/CD & GitOps

  • GitLab CI/CD
  • Jenkins
  • Azure DevOps
  • Tekton
  • ArgoCD
  • CircleCI
  • GitHub Actions

Cloud & Containers

  • AWS
  • Azure
  • Kubernetes
  • OpenShift
  • Docker
  • Terraform
  • Ansible
  • CloudFormation

Runtime Security

  • Falco
  • Falcosidekick
  • eBPF
  • Calico
  • Cilium
  • NetworkPolicy
  • WireGuard
  • FortiGate

Observability

  • Prometheus
  • Grafana
  • Elasticsearch
  • Kibana
  • Zabbix

Credentials

Certifications

  • 2026 Certified Kubernetes Security Specialist — CKS
  • 2025 Certified Kubernetes Administrator — CKA
  • 2025 Web App Penetration Tester eXtreme — eWPTX
  • 2025 DevSecOps Learning Path — TryHackMe
  • 2023 Red Hat Certified System Administrator — RHCSA
  • 2023 AWS Certified Cloud Practitioner — CLF-C01
  • 2023 AZ-900: Microsoft Azure Fundamentals

Recognition

Achievements & community

01

2nd Place — SYber CTF

National-level cybersecurity competition

02

10th Place — Egypt National CTF 2020

Egypt's premier national capture-the-flag

03

Innovation Ambassador — TIEC

Technology Innovation & Entrepreneurship Center, 2021–Present

04

Vice Coordinator — CAT Reloaded

Technical community, Mansoura University, 2021

05

Excellent Grade — Graduation Project

Trusted Online Voting System · Mansoura University, 2022

06

HackTheBox · CyberTalents · Portswigger

Active offensive security practice and challenges

Let's work together

Get in touch

Open to enterprise DevSecOps consulting, CI/CD security architecture reviews, and speaking engagements. Based in Riyadh—available globally.