Skip to content
View mdrahatrahmanakas's full-sized avatar
๐Ÿ 
Working from home
๐Ÿ 
Working from home

Highlights

  • Pro

Block or report mdrahatrahmanakas

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
mdrahatrahmanakas/README.md

ISO 27001 Lead Auditor GRC & Offensive Security Open to Work


LinkedIn Gmail GitHub TryHackMe

Profile Views


๐Ÿ‘‹ About Me

I'm a cybersecurity professional based in Dhaka, Bangladesh operating at the intersection of Governance, Risk & Compliance and Offensive Security โ€” a combination most security teams are still missing. The compliance frameworks I design aren't just documented; they're verified against the attacker mindset trying to break them.

"Most security professionals defend or audit. I do both โ€” and build the frameworks that prevent breaches before they happen."


๐Ÿ† Certifications

ISO 27001:2022 Lead Auditor ISO 27001:2022 Security Associate IBM GRC & Data Privacy Cisco Ethical Hacker CCEP Educator

# Certification Issuer Domain
๐Ÿฅ‡ ISO/IEC 27001:2022 Lead Auditor Mastermind Assurance ISMS Auditing ยท Risk Management
๐Ÿฅˆ ISO/IEC 27001:2022 Security Associateโ„ข SkillFront Information Security ยท Risk Assessment
๐Ÿ… Governance, Risk, Compliance & Data Privacy IBM SkillsBuild GRC ยท Data Privacy ยท Compliance
๐Ÿ… Ethical Hacker Cisco Penetration Testing ยท Offensive Security
๐Ÿ… Certified Cybersecurity Educator (CCEP) Red Team Leaders Security Training ยท Architecture

๐Ÿ’ผ Experience

๐Ÿ” Cybersecurity Consultant โ€” GRC & Offensive Security ย |ย  2025 โ€“ Present ย ยทย  Remote

Designing ISO 27001 and NIST CSF-aligned security programs for clients, with every control set verified โ€” not just documented โ€” under realistic attack conditions.

Deliverables: Statement of Applicability (SoA) ยท Risk Registers ยท Gap Assessment Reports ยท Control Implementation Roadmaps ยท Audit-Ready Evidence Packages

ISO 27001 NIST CSF GRC Ethical Hacking Risk Register

๐Ÿ“ก Service Account Manager โ€” Genex Infosys ยท Grameenphone Enterprise ย |ย  2023 โ€“ 2025 ย ยทย  Dhaka

Managed enterprise service delivery for Bangladesh's largest telecom, overseeing SLA compliance, KPI reporting, and cross-functional coordination across major corporate accounts.

๐Ÿ† Attrition Warrior Award โ€” September 2023 ยท Awarded for outstanding performance under high-pressure operational conditions.

SLA Management KPI Monitoring Enterprise Accounts Service Delivery

๐Ÿงช Penetration Tester & Security Researcher ย |ย  2022 โ€“ 2023 ย ยทย  Mist Leetcon ยท Riot Center ยท Independent

Conducted penetration testing and vulnerability research across CTF environments and live targets. All findings documented with CVSS scoring and structured reports, directly informing defensive hardening decisions.

Red Teaming Penetration Testing CVSS Scoring Vulnerability Research CTF


๐ŸŽฏ Core Competencies

๐Ÿ›ก๏ธ Compliance & GRC โš”๏ธ Offensive Security ๐Ÿ”ฌ Detection & Defense ๐Ÿ—๏ธ Architecture
ISO 27001 Lead Auditing Penetration Testing SOC Operations ISMS Design
Gap Assessments Metasploit ยท Burp Suite Splunk ยท Sentinel Risk Registers & SoA
NIST ยท GDPR ยท HIPAA OSINT & Reconnaissance Sigma Rule Engineering Policy Frameworks
BCP / DR Planning Threat Modeling IAM ยท Digital Forensics Audit-Ready Controls

๐Ÿ› ๏ธ Tools & Stack

Compliance & Frameworks

ISO 27001 NIST CSF GDPR HIPAA PCI-DSS GRC BCP/DR

Offensive Security

Metasploit Burp Suite Nmap Wireshark OSINT Threat Modeling

Detection & Defense

Splunk Microsoft Sentinel Sigma Rules SOC Operations IAM Digital Forensics


๐Ÿ”ญ Current Focus

๐ŸŸข  ISO 27001:2022 gap assessments for SME clients           [Remote ยท Ongoing]
๐ŸŸข  Detection engineering โ€” custom Sigma rules for SOC       [Personal Project]
๐ŸŸข  CTF challenges on TryHackMe (Rahat404x)                  [Active]
๐ŸŸก  Public GRC template library for Bangladeshi orgs         [In Progress]

๐ŸŽฎ Practice & Research

TryHackMe


๐Ÿค Let's Work Together

If you're building or auditing a security program and need someone who can read a risk register and run a Metasploit module โ€” that's the conversation worth having.

Open to: GRC Consulting ยท ISO 27001 Gap Assessments ยท Penetration Testing ยท Detection Engineering ยท Security Research

Connect on LinkedIn ย  Send an Email

โœฆ Open to remote / hybrid opportunities in cybersecurity, GRC, and offensive security โœฆ

Popular repositories Loading

  1. mdrahatrahmanakas mdrahatrahmanakas Public

    2

  2. malware-sandbox malware-sandbox Public

    Python 2

  3. iso27001-compliance-checker iso27001-compliance-checker Public

    Python 1

  4. CL4R1T4S CL4R1T4S Public

    Forked from elder-plinius/CL4R1T4S

    LEAKED SYSTEM PROMPTS FOR CHATGPT, GEMINI, GROK, CLAUDE, PERPLEXITY, CURSOR, DEVIN, REPLIT, AND MORE! - AI SYSTEMS TRANSPARENCY FOR ALL! ๐Ÿ‘

    1 1

  5. public-skills-builder public-skills-builder Public

    Forked from shuvonsec/public-skills-builder

    Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups โ€” 18 vuln classes, no private reports needed

    Python 1 1

  6. caveman caveman Public

    Forked from JuliusBrussee/caveman

    ๐Ÿชจ why use many token when few token do trick โ€” Claude Code skill that cuts 65% of tokens by talking like caveman

    Python 1 1