Skip to content
View mdrahatrahmanakas's full-sized avatar
🏠
Working from home
🏠
Working from home

Highlights

  • Pro

Block or report mdrahatrahmanakas

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mdrahatrahmanakas/README.md

ISO 27001 Lead Auditor GRC & Offensive Security Open to Work


LinkedIn Gmail GitHub TryHackMe

Profile Views


👋 About Me

I'm a cybersecurity professional based in Dhaka, Bangladesh operating at the intersection of Governance, Risk & Compliance and Offensive Security — a combination most security teams are still missing. The compliance frameworks I design aren't just documented; they're verified against the attacker mindset trying to break them.

"Most security professionals defend or audit. I do both — and build the frameworks that prevent breaches before they happen."


🏆 Certifications

ISO 27001:2022 Lead Auditor ISO 27001:2022 Security Associate IBM GRC & Data Privacy Cisco Ethical Hacker CCEP Educator

# Certification Issuer Domain
🥇 ISO/IEC 27001:2022 Lead Auditor Mastermind Assurance ISMS Auditing · Risk Management
🥈 ISO/IEC 27001:2022 Security Associate™ SkillFront Information Security · Risk Assessment
🏅 Governance, Risk, Compliance & Data Privacy IBM SkillsBuild GRC · Data Privacy · Compliance
🏅 Ethical Hacker Cisco Penetration Testing · Offensive Security
🏅 Certified Cybersecurity Educator (CCEP) Red Team Leaders Security Training · Architecture

💼 Experience

🔐 Cybersecurity Consultant — GRC & Offensive Security  |  2025 – Present  ·  Remote

Designing ISO 27001 and NIST CSF-aligned security programs for clients, with every control set verified — not just documented — under realistic attack conditions.

Deliverables: Statement of Applicability (SoA) · Risk Registers · Gap Assessment Reports · Control Implementation Roadmaps · Audit-Ready Evidence Packages

ISO 27001 NIST CSF GRC Ethical Hacking Risk Register

📡 Service Account Manager — Genex Infosys · Grameenphone Enterprise  |  2023 – 2025  ·  Dhaka

Managed enterprise service delivery for Bangladesh's largest telecom, overseeing SLA compliance, KPI reporting, and cross-functional coordination across major corporate accounts.

🏆 Attrition Warrior Award — September 2023 · Awarded for outstanding performance under high-pressure operational conditions.

SLA Management KPI Monitoring Enterprise Accounts Service Delivery

🧪 Penetration Tester & Security Researcher  |  2022 – 2023  ·  Mist Leetcon · Riot Center · Independent

Conducted penetration testing and vulnerability research across CTF environments and live targets. All findings documented with CVSS scoring and structured reports, directly informing defensive hardening decisions.

Red Teaming Penetration Testing CVSS Scoring Vulnerability Research CTF


🎯 Core Competencies

🛡️ Compliance & GRC ⚔️ Offensive Security 🔬 Detection & Defense 🏗️ Architecture
ISO 27001 Lead Auditing Penetration Testing SOC Operations ISMS Design
Gap Assessments Metasploit · Burp Suite Splunk · Sentinel Risk Registers & SoA
NIST · GDPR · HIPAA OSINT & Reconnaissance Sigma Rule Engineering Policy Frameworks
BCP / DR Planning Threat Modeling IAM · Digital Forensics Audit-Ready Controls

🛠️ Tools & Stack

Compliance & Frameworks

ISO 27001 NIST CSF GDPR HIPAA PCI-DSS GRC BCP/DR

Offensive Security

Metasploit Burp Suite Nmap Wireshark OSINT Threat Modeling

Detection & Defense

Splunk Microsoft Sentinel Sigma Rules SOC Operations IAM Digital Forensics


🔭 Current Focus

🟢  ISO 27001:2022 gap assessments for SME clients           [Remote · Ongoing]
🟢  Detection engineering — custom Sigma rules for SOC       [Personal Project]
🟢  CTF challenges on TryHackMe (Rahat404x)                  [Active]
🟡  Public GRC template library for Bangladeshi orgs         [In Progress]

🎮 Practice & Research

TryHackMe


🤝 Let's Work Together

If you're building or auditing a security program and need someone who can read a risk register and run a Metasploit module — that's the conversation worth having.

Open to: GRC Consulting · ISO 27001 Gap Assessments · Penetration Testing · Detection Engineering · Security Research

Connect on LinkedIn   Send an Email

✦ Open to remote / hybrid opportunities in cybersecurity, GRC, and offensive security ✦

Popular repositories Loading

  1. mdrahatrahmanakas mdrahatrahmanakas Public

    2

  2. malware-sandbox malware-sandbox Public

    Python 2

  3. iso27001-compliance-checker iso27001-compliance-checker Public

    Python 1

  4. CL4R1T4S CL4R1T4S Public

    Forked from elder-plinius/CL4R1T4S

    LEAKED SYSTEM PROMPTS FOR CHATGPT, GEMINI, GROK, CLAUDE, PERPLEXITY, CURSOR, DEVIN, REPLIT, AND MORE! - AI SYSTEMS TRANSPARENCY FOR ALL! 👐

    1 1

  5. public-skills-builder public-skills-builder Public

    Forked from shuvonsec/public-skills-builder

    Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no private reports needed

    Python 1 1

  6. caveman caveman Public

    Forked from JuliusBrussee/caveman

    🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman

    Python 1 1