Skip to content
View jasonachkar's full-sized avatar

Block or report jasonachkar

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
jasonachkar/README.md

πŸ‘‹ Hi, I’m Jason Achkar Diab

I’m a Software Engineer transitioning into Cybersecurity, with a strong focus on Cloud Security (Azure), secure software architecture, and DevSecOps. I bring a builder-first mindset to security β€” combining hands-on development experience with structured security engineering and risk management.

πŸŽ“ MSc Cybersecurity (in progress) – University of London πŸ“œ Certifications: CompTIA Security+, Microsoft AZ-900, Google Cybersecurity πŸ“ Based in Canada Β· Open to Canada & remote roles


πŸ” What I Focus On

  • Cloud Security (Azure-first) Identity & access management, Defender for Cloud, logging, governance, secure landing zones

  • Application & API Security OWASP Top 10, secure authentication flows, threat modeling, secure SDLC

  • SIEM & Detection Engineering Log analysis, KQL-based detections, MITRE ATT&CK mapping, security monitoring

  • DevSecOps & Automation CI/CD security gates, SAST/SCA, container scanning, infrastructure-as-code security


πŸ›  Technical Skills

Cybersecurity & Cloud

  • Azure Security, Azure Entra ID (Azure AD), RBAC, Zero Trust
  • SIEM concepts, detection engineering, incident response
  • Threat modeling (STRIDE), risk assessment
  • CIS Benchmarks, security hardening
  • Secure SDLC & security reviews

Software Engineering (Security-Oriented)

  • Languages: C#, TypeScript, JavaScript, Python, SQL
  • Backend: ASP.NET Core, Node.js, REST APIs, JWT, OAuth 2.0
  • Cloud & DevOps: Azure, Docker, GitHub Actions, CI/CD
  • Databases: PostgreSQL, SQL Server, MongoDB
  • Testing & Quality: Unit testing, static analysis, secure coding practices

πŸš€ Featured Work

πŸ” Personal Cybersecurity Portfolio

🌐 Website: https://jasonachkardiab.com

An enterprise-grade portfolio showcasing real cybersecurity engineering work, including:

  • SIEM detection console with custom query language
  • Threat modeling playground (STRIDE + MITRE ATT&CK)
  • Azure security architecture blueprints
  • DevSecOps CI/CD security pipeline simulator

Built with Next.js, TypeScript, Tailwind, and secure-by-design principles.


πŸ“‚ Selected Projects

  • Azure Secure Landing Zone (IaC) Secure Azure baseline with RBAC, network segmentation, logging, and governance

  • SIEM Detection Engineering Pack KQL detections for authentication abuse, privilege escalation, lateral movement

  • Secure API Gateway Pattern JWT auth, rate limiting, validation, OWASP API Top 10 mitigations

  • Threat Model – Multi-Tenant CRM Full STRIDE analysis with data flows, risks, and mitigations

  • DevSecOps CI/CD Security Gates SAST, dependency scanning, container & IaC security with automated fail gates

(Repositories available on my GitHub profile πŸ‘‡)


🎯 Career Direction

I’m aiming for roles such as:

  • Cloud Security Engineer
  • Security Engineer / DevSecOps
  • Cybersecurity Consultant (GRC / Cloud / AppSec)
  • Detection Engineer / SOC Engineering

I’m particularly interested in environments where engineering quality, security architecture, and automation are valued.


🌍 About Me

  • Trilingual: English, French, Arabic
  • Strong communicator β€” able to translate security risks to technical and non-technical audiences
  • Passionate about building secure systems, not just finding vulnerabilities

🀝 Let’s Connect


Pinned Loading

  1. azure-secure-landing-zone-baseline azure-secure-landing-zone-baseline Public

    HCL

  2. cloud-security-hardening-checklist cloud-security-hardening-checklist Public

    PowerShell

  3. crm-threat-model crm-threat-model Public

    TypeScript 1

  4. microsoft-sentinel-siem-detection microsoft-sentinel-siem-detection Public

    JavaScript

  5. cybersecurity-writeups cybersecurity-writeups Public

    JavaScript 1

  6. network-traffic-analyzer network-traffic-analyzer Public

    Python 1