Cybersecurity Strategy Consulting and Project Management for an airline that was in its start-up phase in the Middle East on behalf of Accenture.
My duties included the following:
- Leading the Cyber GRC project to build the cybersecurity function for an aviation client, filling a critical security gap and laying groundwork for sustained cyber resilience.
- Developing and implementing a cybersecurity strategy and roadmap aligned with ISO 27001 and region-specific regulations.
- Executing a specialised threat profiling exercise, developing a unique threat landscape and identifying risks and vulnerabilities specific to the aviation sector.
- Creating a detailed cybersecurity strategy and roadmap with an executive summary, ensuring alignment with client objectives and clarity for C-suite stakeholders.
Key outcomes included:
- Established a cybersecurity function from the ground up, giving the client a formal security posture where none previously existed.
- Reduced organisational risk exposure by identifying aviation-specific threats before they could be exploited.
- Positioned the client for long-term cyber resilience rather than reactive, ad hoc security responses.
Positioning is mostly about what you refuse to be.
Anyone can list the audiences they want to reach. Anyone can write down the problems they solve. That part is easy.
The hard part is naming what you'll turn down. The clients you'll pass on. The work you'll stop pitching for. The categories you'll let competitors own without a fight.
Every time you say "we can also do that," your positioning gets weaker. The market can't tell what you're for.
The companies with the clearest positioning name a specific buyer, a specific problem, and a specific moment. Everyone else competes on price.
Completely agree. Trying to help everyone means you end up standing out to no one. Knowing what jobs to say no to is what makes people respect your focus.
This project focused on building and testing a practical AI security assessment lab for evaluating LLM defenses against prompt injection and jailbreak attacks.
I integrated Spikee by Reversec with a locally hosted cybersecurity model running through LM Studio, then added NVIDIA NeMo Guardrails to compare model behavior under three conditions: no guardrails, input filtering, and combined input/output protection.
The work included configuring the local model environment, building a custom FastAPI gateway, integrating NeMo Guardrails, troubleshooting model latency and timeout issues, creating a reusable Spikee target, and analyzing attack results using Spikee’s built-in reporting tools.
The project also explored different adversarial testing approaches, including prompt injection datasets, obfuscation, encoded attacks, Best-of-N testing, synthetic canary leakage tests, and structured benchmark comparisons.
The objective was to measure how much the guardrails reduced successful attacks while keeping the model, dataset, and testing conditions consistent.
This project demonstrates a hands-on approach to LLM red teaming, AI safety testing, prompt-injection assessment, and guardrail validation for organizations deploying generative AI systems.