Nadim Saliby
Chief Security Officer, WhoMeta
I secure high-assurance environments where breach equals existential risk. AKS/Kubernetes hardening. Policy-as-code enforcement. Threat intelligence integration. OSCP-validated offensive perspective applied to sovereign cloud operations.
Security Operations Scope
What I've delivered at scaleTrack Record
Delivered outcomes in environments that demand precision
Sovereign Cloud Security
Leading infrastructure and platform security for WhoMeta sovereign cloud. AKS/Kubernetes workload hardening. Wazuh SIEM deployment for distributed correlation. Operating where breach equals existential risk.
Current • CSOFounded → Acquired (12 months)
Built DarkHuginn from concept to acquisition by WhoMeta. Autonomous threat intelligence platform integrated into production workflows for air-gapped intelligence collection.
May 2025250+ Production Infrastructure
Managed security for 250+ AWS/Azure instances across distributed data centers. Zero-downtime blue/green deployments. Automated remediation at scale. Infrastructure-as-code with Ansible.
Dubai • 2 yearsOffensive Security Research
Published UAC bypass research and anti-forensics analysis. Offensive perspective applied to defensive architecture and detection engineering.
PublishedTechnical Contributions
Platform development, offensive research, and operational tooling
DarkHuginn
Autonomous darknet intelligence platform for hidden-service discovery, cryptocurrency tracing, and adversarial infrastructure mapping. Acquired by WhoMeta for integration into production workflows supporting air-gapped and OPSEC-sensitive environments.
Windows UAC Bypass Research
Documented proof-of-concept for Windows UAC bypass via fodhelper.exe. Demonstrates privilege escalation vector for security validation and penetration testing operations.
PublicationAnti-Forensics Analysis
Technical analysis of anti-forensics techniques, evasion methodologies, and evidence integrity considerations for defensive security operations and incident response planning.
PublicationOSINT & Triage Utilities
Browser-based security utilities for IOC extraction, PDF triage, EXIF sanitization, and hashing operations. Client-side processing for OPSEC-sensitive environments requiring air-gapped analysis workflows.
Applied Tools
Live, client-side utilities for security workflows
Image Inspector
EXIF + metadata triage with local-only processing.
Open toolPDF Inspector
Static metadata and embedded object assessment.
Open toolIOC Extractor
Normalize and extract indicators from unstructured text.
Open toolHash Lab
Fast, client-side hashing for verification and triage.
Open toolCase Studies
Short, verifiable outcomes and architecture decisions
DarkHuginn: Autonomous Threat Intelligence
Built a platform for hidden‑service discovery, crypto tracing, and adversarial infrastructure mapping. Acquired May 2025 and integrated into production workflows.
View acquisition release250+ Server Security Program
Secured and automated multi‑region AWS/Azure fleet. Built monitoring stacks, implemented segmentation, and executed zero‑downtime migrations.
UAC Bypass & Anti‑Forensics Publications
Published actionable research on Windows UAC bypass and anti‑forensics techniques for defensive validation and incident response.
Career & Credentials
Security leadership, engineering excellence, and continuous validation
Chief Security Officer
WhoMeta
May 2025 – Present
Leading infrastructure and platform security for sovereign cloud operations. Securing AKS/Kubernetes workloads with policy-as-code enforcement, deploying Wazuh SIEM for distributed correlation, and integrating DarkHuginn for threat intelligence. Operating in environments where breach = existential risk.
Founder & Chief Architect
DarkHuginn
2024 – May 2025 (Acquired by WhoMeta)
Founded and built darknet intelligence platform for hidden-service monitoring and adversarial infrastructure analysis. Architected autonomous discovery engines, cryptocurrency tracing pipelines, and digital footprint correlation systems for threat hunting and investigations. Platform acquired by WhoMeta for integration into production workflows supporting air-gapped intelligence collection capabilities.
Cloud Engineer
Carma, Dubai
March 2023 – March 2025
Managed 250+ AWS machines across distributed data centers. Built monitoring with Icinga/Telegraf/Grafana/ELK. Automated infrastructure with Ansible. Zero-downtime blue/green deployments. Secured Linux servers, implemented IAM policies, configured VPC segmentation.
Certifications
PWK 200 - Penetration Testing with Kali Linux
Linux Academy
Network & Server Administration
Education
Digital Forensics Emphasis
Contact
Direct communication for security leadership inquiries