Available for security engagements

Nadim Al-Saliby
Security Engineer
/ DevSecOps

I build and secure the platforms others depend on: airgapped Kubernetes clusters, zero-trust infrastructure, and dark-web threat-intelligence systems. Founder of DarkHuginn (acquired by WhoMeta), where I now serve as Chief Security Officer.

$ whoami
security_engineer · devsecops · threat_intel
$ cat profile.yaml
role: CSO @ WhoMeta
founded: DarkHuginn → acquired
community: Wazuh Ambassador
base: Beirut, Lebanon (remote)
stack: [k8s, terraform, wazuh, ebpf, tor]
$
8+
Years in infrastructure & security
1 exit
DarkHuginn founded & acquired by WhoMeta
225+
Production workloads migrated with zero downtime
2 SOCs
Security Operations Centers built from scratch
// 01

ls ./projects --featured

A selection across threat intelligence, platform engineering, offensive security, and detection engineering.

view all projects
threat-intel2024 – 2025

DarkHuginn: Dark-Web Intelligence Platform

★ Founder · acquired by WhoMeta

Built end-to-end: automated Tor crawling pipelines discovering onion services, markets, and leak sites; blockchain-intelligence workflows tracing illicit wallets; OSINT enrichment linking indicators to open sources. Scaled on message queues and distributed workers.

PythonTorPostgreSQLDockerBlockchain APIs
platform2025 – 2026

Airgapped Kubernetes Security Platform

Designed WhoMeta's full foundation: Terraform IaC, AKS + self-hosted airgapped RKE2 HA clusters, private git and CI, registry with image signing and scanning, secrets management, SSO, and end-to-end GitOps, all open-source on a startup budget.

TerraformRKE2ArgoCDHarborKeycloakcosign
offensive2025

Internal Penetration Test (Financial Services)

Authorized pentest of internal services for a European digital-asset trading and custody provider. Deep testing of authentication, access control (IDOR, privilege escalation), injection, and SSRF, with automated scanning verified manually so every finding carried demonstrable impact. Delivered CVSS-rated report and remediation retest.

Burp SuiteNmapNessusOWASPSQLmap
detection2026 – present

Wazuh Ambassador: Detection-Engineering Research

★ Accredited Wazuh Ambassador

Published research with rule packs and tooling: Kubernetes hardening mapped to 7 compliance frameworks, closing kernel-level detection gaps with eBPF/Tetragon, catching Shadow AI via network telemetry, and detecting rogue MCP servers with MITRE ATT&CK-mapped rules.

WazuhTetragonHelmMITRE ATT&CKk3s
// 02

git log --experience

05/2025 – present
Chief Security Officer
WhoMeta · Remote

Leading security architecture, threat-intelligence infrastructure, and monitoring platforms supporting cybercrime investigations, from Terraform-provisioned airgapped Kubernetes to the full SOC stack.

02/2024 – 05/2025
Founder & Threat Intelligence Engineer
DarkHuginn · Lebanon

Founded and built a dark-web threat-intelligence platform (crawling, blockchain analysis, OSINT enrichment), later acquired by WhoMeta and integrated into its investigation workflows.

03/2023 – 03/2025
Linux & Cloud Engineer
Carma · Lebanon

Ran distributed systems across data centers and AWS: monitoring (Grafana, Icinga2, Kibana), Ansible automation, load balancing, disaster recovery, and Linux/AWS security hardening.

03/2022 – 03/2023
IT Engineer
4T · Lebanon

Windows Server, Cisco Meraki networking, Microsoft 365 Defender, Zabbix monitoring, and Veeam backup across on-prem and cloud.

09/2021 – 03/2022
System Administrator
Smart Solution & E-Consultancy · Lebanon

Windows Server networks (Active Directory, DNS, DHCP), plus VLANs, trunking, and ACLs on Cisco ASA.

07/2018 – 06/2021
System Administrator
Universant · Lebanon

Windows and Linux server operations, disaster-recovery planning, vulnerability assessment and patching.

// 03

cat skills.json

Platform & Cloud

Kubernetes (RKE2/AKS)TerraformAnsibleArgoCD / GitOpsDockerAWSAzureLinuxCilium / eBPFWireGuard

Detection & Response

Wazuh SIEM/XDRTheHiveMISPSuricata / ZeekFalcoVelociraptorPrometheus / GrafanaSOAR (Shuffle)Detection engineering

Offensive Security

Burp SuiteNmapNessusSQLmapWiresharkOWASP methodologyNiktoMemory forensics

Intelligence & OSINT

Dark-web investigationOSINT techniquesBlockchain analysisPythonTorAsync scrapingPostgreSQLBash / PowerShell
// 04

ls ./certifications

PWK-200 · Offensive Security
MCSE · Microsoft
MCSA · Microsoft
CCNA R&S · Cisco
// 05

ls ./tools

Small in-browser security utilities I built. Everything runs locally in your browser; nothing is uploaded anywhere.

// 06

init secure_channel

Open to security engineering, platform builds, penetration testing, and threat-intelligence engagements, remote or on-site. Fluent in English, French, and Arabic.