"Most see a locked door.
I see twelve ways in,
and thirteen ways to make it unbreachable."

Hello, I'm

PHINEHAS NARH

~$ 

Attack to defend. Break to understand. Secure to protect.

01

About Me

Security Engineer with hands-on experience in penetration testing, vulnerability management, and security operations. Skilled at identifying exploitable weaknesses in web applications and infrastructure, and working closely with engineering teams to implement practical, lasting remediation.

Currently driving AppSec initiatives, contributing to ISO 27001:2022 certification and securing production environments through rigorous testing and hardening. My philosophy: fully understand the attacker's mindset to architect stronger defenses.

When I'm not poking around systems, I'm building open-source security tools, writing CVE walkthroughs, and contributing to the security community.

Application Security Engineer B.Tech Cyber Security
0
+
Years Experience
0
+
Critical Vulns Remediated
0
+
Certifications
0
GitHub Repositories
ph1n3y@security:~

$ whoami

phinehas_narh

$ cat philosophy.txt

"Attack to defend. Break to build."

$ ls ./expertise/

pentest  appsec  soc  iam  devsecops

$ _

02

Experience

Application Security Engineer

ACS
Sep 2025 - Present
Penetration Testing
  • Delivered web application penetration testing across multiple enterprise portals, identifying injection flaws, authentication bypasses, sensitive data exposure, and misconfigured security headers.
  • Coordinated directly with development and operations teams to remediate a logs exposure vulnerability, relocating log files from web root and masking sensitive data in transit.
  • Conducted endpoint compromise simulation on a Windows 10 environment with Acronis Cyber Protect Cloud deployed, validating detection and response capabilities.
Compliance & Governance
  • Supported ISO 27001:2022 certification through Stage 1 and Stage 2 ISMS audits, drafting internal security policies and adhering to Annex controls; contributed to achieving full certification.
  • Built and maintained vulnerability trackers and pentest report templates for centralized findings management across client engagements.
  • Delivered DMARC configuration training and documentation to strengthen organizational email security posture.
Security Operations & Deployment
  • Deployed a cyber deception solution for a large telecommunications client using Zscaler, configuring deception connectors, network aggregators, and verifying log generation for active threat baiting.
  • Configured SSO integration through Microsoft Entra ID (Azure AD), provisioned test users, and validated authentication flows end-to-end.
  • Hardened nginx web servers by implementing security headers; enrolled and managed endpoint devices via Microsoft Intune and M365 Defender application controls.
  • Ran phishing simulation campaigns using Wizer across client environments to establish awareness baselines and drive targeted training interventions.
DevSecOps & Cloud Security
  • Integrated SonarQube into development pipelines to enforce static code analysis, catching security vulnerabilities and code quality issues before reaching production.
  • Applied Azure security controls across multiple projects, including Entra ID identity management, conditional access policies, and secure SSO configuration for enterprise clients.
  • Leveraged AWS cloud security knowledge to assess workload posture, apply least-privilege IAM policies, and align deployments with the AWS shared responsibility model.
  • Embedded security checkpoints across CI/CD workflows, coordinating with DevOps teams to remediate exposed secrets, misconfigurations, and dependency vulnerabilities before production release.
Pre-sales & Client Engagement
  • Prepared and delivered security awareness webinars covering penetration testing fundamentals; led Palo Alto product demonstrations and Acronis Cyber Protect Cloud proof-of-value engagements.
  • Conducted consultative security discussions with multiple enterprise prospects, translating technical risk into business impact and recommending tailored solutions.
  • Built and trained an AI-powered customer-facing chatbot with prompt injection hardening to automate 24/7 service interaction across client deployments.
Burp Suite ISO 27001 Web Pentesting SonarQube Azure AWS Zscaler CI/CD Security Wizer Acronis nginx M365 Defender DMARC Deception Tech

Security Analyst

EITBS
Oct 2022 - Nov 2024
Vulnerability Management
  • Executed vulnerability assessments and penetration testing across 5+ systems and endpoints using Nessus and manual techniques, identifying and driving remediation of 7 critical vulnerabilities to reduce attack surface exposure.
  • Performed application security assessments supporting consolidation of 10+ high-resource applications onto centralized infrastructure, reducing server costs by 25%.
Endpoint & Security Operations
  • Administered endpoint protection platforms (Acronis, Symantec) and coordinated security awareness initiatives via KnowBe4, achieving a 47% improvement in phishing resilience metrics.
  • Led technical evaluation for managed SOC provider selection, defining detection and incident response requirements projected to reduce mean time to respond by 70%.
  • Delivered security hardening for 4 endpoints to organizational baseline standards.
Strategy & Awareness
  • Authored and presented an AI risk assessment to senior leadership, initiating a cross-functional task force to evaluate emerging technology threats and adoption strategies.
  • Conducted security awareness training for 20+ employees on threat identification, phishing recognition, and incident response protocols.
Nessus KnowBe4 SOC Acronis Symantec Endpoint Security Risk Assessment SIEM
03

Projects

8

number_tracker

Phone number OSINT tool for location and activity analysis. Geolocates numbers and extracts carrier metadata for investigations.

Python OSINT Recon

CTI Threat Intelligence Toolkit

Python backend for ingesting, processing, and visualizing cyber threat intelligence feeds. Supports structured CTI formats with a JS visualization layer.

Python JavaScript Threat Intel CTI

Browser-Trust

Browser-based device trust scoring tool that evaluates client-side security posture and assigns risk scores for zero-trust access decisions.

HTML JavaScript Zero Trust
1

CVE-2024-4577 Walkthrough

Full incident response walkthrough for the PHP CGI argument injection zero-day. Covers attack chain, CVSS analysis, and mitigation controls.

CVE Analysis IR PHP Exploit Dev

o1xport

Versatile port scanning tool built for penetration testing workflows. Fast, configurable, and outputs structured scan reports for analysis.

Python Networking Pentesting

USB_controller

USB security tool that monitors, logs, and controls device access events in real-time, providing audit trails for endpoint security enforcement.

Python Endpoint Security Monitoring

File-Integrity-Model

File integrity monitoring tool that detects unauthorized changes and triggers notifications, supporting host-based intrusion detection workflows.

Python FIM HIDS
1

Cisco Networking Projects

Five enterprise network topologies with defense-in-depth controls, IPsec VPN tunnels, WPA3, and RBAC across 100+ concurrent device environments.

Cisco Networking VPN Firewall

Pentesting-Projects

A collection of personal penetration testing engagements. Covers CVE exploitation, authentication bypass on legacy systems, CVSS-scored findings, and stakeholder-ready pentest reports with compensating controls.

Python Metasploit CVE Exploit Reporting
04

Open Source

Self-sourced contributions to reputable security and infrastructure projects: real bugs, new detections, and hardening fixes. Every change is one I reviewed, tested, and can defend end to end, with AI assistance disclosed wherever a project's policy asks for it.

7 Pull Requests
3 Merged
6 Reputable Projects
3 Security Findings
Merged • First landed PR
canonical/cloud-init Merged

Type annotations for the hosts file parser

Added complete type coverage to cloudinit.distros.parsers.hosts and removed the module from cloud-init's mypy override, advancing the project's long-running static-typing initiative (issue #5445). Worked through four rounds of maintainer review, a merge conflict, mypy fallout on the test module, and CLA sign-off before it was merged by a Canonical maintainer.

Python Type Safety mypy Cloud-init
NVIDIA/garak Under Review

Prompt injection in the TAP/PAIR LLM judge

A target model could forge a Rating: [[1]] block in its own output and make garak's model-as-judge score a genuine jailbreak as safe. Sanitised the judge input and anchored scoring on the judge's own final verdict. Confirmed against a live judge; 9 regression tests.

LLM Security Prompt Injection Python
NVIDIA/garak Merged

Unicode normalization for content detectors

Closed a detector-evasion gap: fullwidth homoglyphs and zero-width characters let dangerous model output slip past garak's byte-level string matching. Added optional NFKC normalization with format-character stripping, backward compatible by default. 17 tests.

LLM Security Unicode Detection
gitleaks/gitleaks Under Review

Secret-detection rules for Groq & xAI keys

Added detection rules for Groq (gsk_…) and xAI (xai-…) API keys to the gitleaks scanner, with verified key formats, true and false-positive test cases, and a regenerated ruleset config.

Go Secret Scanning DevSecOps
bridgecrewio/checkov Under Review

New AWS check: public Secrets Manager policy

Added CKV_AWS_394 to close a real false negative: a Secrets Manager resource policy granting GetSecretValue to any principal (Principal: *) was silently passing. Modeled on the existing any-principal checks with full pass/fail Terraform fixtures.

Python IaC Security AWS
svinota/pyroute2 Under Review

Netlink decode crash on wireless scans

Fixed an AttributeError traceback thrown on every Linux wireless-scan event in debug mode, where the netlink layer called .decode() on a list of NLA cells. Five-line isinstance guard with unit tests, for an issue that had sat open 14 months.

Python Linux Netlink
mlrun/mlrun Merged

Path-traversal hardening in archive extraction

Fixed a tar-slip path traversal (CWE-22) in mlrun's project/source download: a malicious .tar.gz extracted with an unfiltered extractall() could write files outside the target directory. Routed extraction through the project's own safe helpers with a member pre-flight and guaranteed temp-file cleanup, plus regression tests. Merged after a maintainer code-review, which included empirically disproving one of its findings.

Python Path Traversal MLOps

Security Research & Responsible Disclosure

Open-source infra dashboard Responsible Disclosure

Stored XSS (CWE-79)

Discovered and confirmed a stored cross-site scripting vulnerability in a widely-used open-source infrastructure dashboard, with a working proof-of-concept built against the project's real code paths. Handled through responsible disclosure, so specifics are withheld here until a fix ships.

XSS CWE-79 PoC
Details on public disclosure
Security-automation platform Responsible Disclosure

Tenant isolation secure-defaults gap

Identified a defense-in-depth gap in an open-source SOAR platform: database-level tenant isolation (Postgres row-level security) was disabled by default, leaving cross-workspace isolation dependent on application checks alone. Documented as a hardening advisory with remediation guidance, handled through responsible disclosure.

Multi-Tenancy Postgres RLS Secure Defaults
Details on public disclosure
Self-hosted backup manager Responsible Disclosure

Privilege escalation to host RCE (CWE-78)

Found and confirmed a privilege-escalation to server-side remote code execution in a self-hosted backup tool: a low-privilege role could smuggle an argument into a wrapped command-line tool and run commands on the host. Verified with a working proof-of-concept against the tool's real code path. Handled through responsible disclosure, so specifics are withheld until a fix ships.

RCE CWE-78 Privilege Escalation
Details on public disclosure

CVE Research & Writeups

PhinehasNarh/cve-research Public Repo

CVE research library: 30+ analyses

A growing library of CVE walkthroughs, each with a written analysis, a detection script, an exploit reference, and incident-response notes. Spans high-impact CVEs including Log4Shell, the XZ Utils backdoor, and PHP-CGI argument injection across web, network, and infrastructure targets.

CVE Analysis Detection Exploit Dev
CVE-2024-4577 Walkthrough

PHP-CGI zero-day: IR walkthrough

A full incident-response reconstruction of the PHP-CGI argument-injection zero-day (CVE-2024-4577): tracing the attack from IDS/IPS alerts through Apache logs, timeline analysis with PECmd and Timeline Explorer, and remediation guidance, with exploit specifics deliberately omitted.

CVE-2024-4577 Incident Response Forensics
05

Skills

Languages

Python C# JavaScript Go HTML CSS Bash

Security Tools

Burp Suite Wireshark Metasploit Nmap Nessus SAST DAST

Operations

SIEM EDR XDR SOC DevSecOps Incident Response

Methodologies

OWASP Top 10 Threat Modeling CVSS MITRE ATT&CK ISO 27001 Zero Trust

Libraries

Pandas NumPy Matplotlib sqlite3 socket subprocess
06

Certifications

Professional Certifications

CompTIA

Security+

2026

Core security competencies in threats, vulnerabilities, architecture, implementation, and incident response.

eSecurity Institute

Certified Computer Forensic Analyst

2026

Digital evidence acquisition, forensic analysis, and incident reconstruction across host and storage media.

The SecOps Group

Certified AppSec Pentester

2026

Hands-on web application penetration testing: identifying and exploiting real-world vulnerabilities across the OWASP Top 10 and beyond.

Cisco

Cyber Ops Associate

Feb 2024

Security monitoring, log analysis, incident triage, and threat intelligence within SOC environments.

AWS

Cloud Practitioner

Feb 2025

AWS shared responsibility model, cloud security controls, and architecture best practices.

Cisco

CCNA

May 2024

Network infrastructure security, routing protocols, switching, and network access control implementation.

AXELOS

ITIL Foundation

April 2024

IT service management principles aligned with business continuity and risk management objectives.

Mastermind

ISO 27001:2022 Lead Auditor

Feb 2026

Qualified to plan, conduct, and lead ISMS audits per ISO/IEC 27001:2022 auditing guidelines.

Technical Trainings

Certified Red Team Operations Management (CRTOM) Dec 2025
Certified Phishing Prevention Specialist (CPPS) Dec 2025
API Penetration Testing May 2026 • APIsec University
AI Skills Fest 2025 • Microsoft
Zscaler Technical Associate Jul 2025 • Zscaler
Data Security Sep 2025 • GIZ
Threat Hunting Apr 2024 • Security Blue Team
Vulnerability Management Apr 2024 • Security Blue Team
Digital Forensics Mar 2024 • Security Blue Team
Penetration Testing Oct 2023 • IT Masters
Risk Management May 2023 • PwC
Machine Learning Jun 2023 • Cognizant
07

Education

Bachelor of Technology in Cyber Security

Accra Technical University
Jan 2022 - Dec 2025
GPA: 4.13/5.0
08

Get In Touch

Currently open to new opportunities and collaborations. Whether you have a project, a role, or just want to talk security, my inbox is open.

Email phinehastettehnarh@gmail.com
GitHub PhinehasNarh
LinkedIn Phinehas Narh