DevSecOps Engineer
Hossam Ibraheem
0x70ssAM · Riyadh, Saudi Arabia
I build the security layer inside CI/CD pipelines—integrating SAST, SCA, DAST, and IAST so vulnerabilities are addressed before production. Enterprise tooling. Kubernetes-native. Shift-left by default.
- 3+
- Years in DevSecOps
- 40%
- Vulnerability reduction
- 5
- Government clients
- 50+
- Code flaws remediated
Profile
About me
I'm a DevSecOps Engineer with 3+ years of hands-on experience embedding security into the software delivery lifecycle at enterprise scale. Currently based in Riyadh, serving as Xacta Solutions' DevSecOps representative for BlackDuck—their global SCA/SAST technical partner.
My background spans both sides of the security fence: I started in penetration testing and CTF competitions, then moved into infrastructure and DevOps, and now work at the intersection—making CI/CD pipelines actually secure. I've led tooling implementations for national-level clients including NEOM, Jeddah Municipality, SWCC, the Ministry of Communications, and Royal Protocol through Zinad IT's OpenText partnership.
I hold CKS and CKA certifications, an eWPTX for web application penetration testing, and an RHCSA—covering both offense and defense. When I'm not hardening pipelines, I write in-depth technical guides and compete on HackTheBox and CyberTalents.
- Current role
- DevSecOps Engineer · Xacta Solutions, Riyadh
- Education
- B.Sc. Computer & Information Science · Mansoura University, 2022
- Languages
- Arabic (Native) · English (B2)
- Specialty
- CI/CD Security · SAST · SCA · DAST · IAST · Kubernetes Security
- Blog
- 0x70ssam.github.io
- CTF
- HackTheBox · CyberTalents · Portswigger · SYber CTF 2nd Place
Career
Experience
3+ years delivering enterprise-grade DevSecOps across government, defense, and critical infrastructure sectors in KSA and Egypt.-
Nov 2025 – Present
DevSecOps EngineerCurrent role
Xacta Solutions · Riyadh, KSA | BlackDuck Global Technical Partner
- Act as DevSecOps Engineer and BlackDuck technical representative in enterprise on-premises client engagements.
- Lead end-to-end integration of SCA, SAST, IAST, and DAST toolchains into existing CI/CD pipelines.
- Design and maintain DevSecOps workflows embedding continuous security validation across every SDLC phase.
- Collaborate with development teams on vulnerability analysis, triage, and remediation workflows.
-
May 2024 – Nov 2025
DevSecOps Engineer
Zinad IT · Smart Village, Egypt | OpenText Representative
- Led OpenText security tooling implementation for 5 strategic government and enterprise clients.
- Integrated SAST and DAST into CI/CD pipelines, reducing pre-production vulnerabilities by 40%.
- Streamlined dependency tracking via Sonatype Nexus IQ, cutting critical library issues by 30%.
- Performed secure code reviews uncovering and remediating 50+ code-level security flaws.
- Delivered enterprise knowledge-transfer sessions on Fortify SSC, Black Duck, and Seeker.
- Conducted Vulnerability Assessments and Threat Modeling across client environments.
- Pre-productionvulnerabilities ↓ 40%
- Criticaldependencies ↓ 30%
- Codeflaws 50+ fixed
- 5strategic clients
-
Apr 2024 – Mar 2025 · Part-Time
DevOps Engineer
CTF.ae · UAE
- Deployed and managed secure Azure cloud infrastructure via Terraform IaC for CTF competition events.
- Automated challenge deployment pipelines for reliability and scalability under competition load.
-
Mar 2024 – May 2024
Infrastructure Engineer
EG-CERT · Egyptian Computer Emergency Readiness Team · Smart Village, Egypt
- Maintained virtual infrastructure across Proxmox and VMware ESXi hypervisors.
- Configured FortiGate firewalls and implemented secure backup and recovery strategies.
Work
Featured projects
Enterprise implementations, reference platforms, and public knowledge artifacts built across my career.Cloud-Native DevSecOps Platform
End-to-end enterprise platform: Terraform (IaC) → Ansible (configuration management) → Kubernetes → Tekton (CI) → ArgoCD (GitOps). Policy-as-Code with OPA/Conftest and centralized vulnerability management through DefectDojo.
- Terraform
- Ansible
- Tekton
- ArgoCD
- Trivy
- Checkov
- Gitleaks
- OPA
- DefectDojo
Secure Azure DevOps CI/CD Pipeline
Production-ready pipeline in Azure DevOps with SAST, DAST, SCA, secrets scanning, and compliance-gate enforcement at each SDLC stage—from commit to deployment.
- Azure DevOps
- SAST
- DAST
- SCA
- Compliance Gates
- Secret Scanning
DevSecOps Roadmap 2026 — 17-Phase Guide
A comprehensive roadmap synthesizing NIST SSDF, OWASP SAMM/ASVS/DSOMM, and Practical DevSecOps 2026, from foundations through eBPF runtime security, SLSA, SBOM, and AI/ML threat surfaces.
- NIST SSDF
- OWASP SAMM
- SLSA
- SBOM
- Zero Trust
- eBPF
Fortify SSC 24.4 on Kubernetes / Helm
Production deployment guide for Fortify SSC 24.4 on Kubernetes, including air-gap constraints, Helm pull and custom-values patterns, and enterprise on-premises considerations from real client deployments.
- Kubernetes
- Helm
- Fortify SSC
- Air-Gap
- On-Premises
Hardened K8s DevSecOps Lab
Single-node Kubernetes lab on Ubuntu 24.04 with Calico/Cilium NetworkPolicy enforcement, Falco eBPF runtime security, Falcosidekick alerting, and air-gapped Helm deployment patterns.
- Kubernetes
- Calico
- Cilium
- Falco
- Falcosidekick
- eBPF
- Air-Gap
Trusted Online Voting System (TOV)
B.Sc. graduation project, awarded an Excellent grade: a cryptographically secure, privacy-preserving voting platform for transparent elections and collective decision-making. Mansoura University, 2022.
- Cryptography
- Privacy
- Secure Design
- B.Sc. 2022
Writing
Selected writing
Long-form guides on DevSecOps architecture, CI/CD security, and cloud-native tooling.DevSecOps Roadmap — From Foundations to Expert
DevSecOps Roadmap 2026: From Foundations to Expert
Building a Cloud-Native DevSecOps Platform End-to-End
End-to-End DevSecOps CI/CD with Azure DevOps
Deploying Fortify SSC 24.4 on Kubernetes via Helm
CTF Writeups & Penetration Testing Notes
Capabilities
Technical skills
Application Security
- SAST
- DAST
- IAST
- SCA
- SBOM
- Threat Modeling
- Secure Code Review
- Vulnerability Assessment
- Web App Pentesting
Enterprise Tooling
- BlackDuck SCA/SRM
- Coverity
- Fortify SSC
- ScanCentral
- WebInspect
- Seeker IAST
- Sonatype Nexus IQ
- DefectDojo
CI/CD & GitOps
- GitLab CI/CD
- Jenkins
- Azure DevOps
- Tekton
- ArgoCD
- CircleCI
- GitHub Actions
Cloud & Containers
- AWS
- Azure
- Kubernetes
- OpenShift
- Docker
- Terraform
- Ansible
- CloudFormation
Runtime Security
- Falco
- Falcosidekick
- eBPF
- Calico
- Cilium
- NetworkPolicy
- WireGuard
- FortiGate
Observability
- Prometheus
- Grafana
- Elasticsearch
- Kibana
- Zabbix
Credentials
Certifications
- 2026 Certified Kubernetes Security Specialist — CKS
- 2025 Certified Kubernetes Administrator — CKA
- 2025 Web App Penetration Tester eXtreme — eWPTX
- 2025 DevSecOps Learning Path — TryHackMe
- 2023 Red Hat Certified System Administrator — RHCSA
- 2023 AWS Certified Cloud Practitioner — CLF-C01
- 2023 AZ-900: Microsoft Azure Fundamentals
Recognition
Achievements & community
2nd Place — SYber CTF
National-level cybersecurity competition
10th Place — Egypt National CTF 2020
Egypt's premier national capture-the-flag
Innovation Ambassador — TIEC
Technology Innovation & Entrepreneurship Center, 2021–Present
Vice Coordinator — CAT Reloaded
Technical community, Mansoura University, 2021
Excellent Grade — Graduation Project
Trusted Online Voting System · Mansoura University, 2022
HackTheBox · CyberTalents · Portswigger
Active offensive security practice and challenges
Let's work together
Get in touch
Open to enterprise DevSecOps consulting, CI/CD security architecture reviews, and speaking engagements. Based in Riyadh—available globally.