Final-Year Engineering Student

Bagy Oussama

Cybersecurity &
Telecommunications Engineering

Final-year engineering student in Cybersecurity & Telecommunication Systems at ENSA Marrakech, Cadi Ayyad University. Currently completing a Software Engineering Internship at Optipark. Focused on Cybersecurity, AI Security, Cloud Security, Offensive Security and Secure Software Engineering.

Projects

Featured Engineering Projects

A selection of my most advanced cybersecurity, DevSecOps, cloud infrastructure, and security engineering projects.

Next-Generation DevSecOps Platform

Transforms natural-language infrastructure requirements into validated DevSecOps and Infrastructure-as-Code artifacts, then automates security checks, cloud provisioning, CI/CD execution and deployment monitoring. The repository, demo, report and presentation document the complete engineering workflow.

Groq LLMFastAPIReactTerraformJenkinsDocker

Project summary

  • Generates validated DevSecOps and Infrastructure-as-Code artifacts from natural-language requirements.
  • Automates security checks, cloud provisioning and CI/CD execution with Jenkins, Terraform, SonarQube and Trivy.
  • Provides deployment monitoring through Prometheus and Grafana.

Cyber Chaos Arena – Self-Healing HoneyNet

An intelligent SOC and self-healing honeynet for detecting attacks, redirecting threats, and supporting controlled remediation. It combines traffic inspection, deception, centralized monitoring, and local AI-assisted analysis.

NGINXModSecurityOWASP CRSSplunkOllamaGrafana

TLS Posture Analyzer

An open-source Android TLS auditing platform that finds insecure certificate validation, cleartext traffic, weak configurations, and missing pinning. It combines APK analysis, security-standard mapping, and AI-assisted remediation.

PythonFastAPIReactAndroidjadxapktool

Enterprise SIEM Hardening Platform

A hardened Wazuh SIEM platform for centralized log collection, integrity monitoring, event correlation, and threat detection. Its objective is to protect the monitoring pipeline while improving infrastructure-wide security visibility.

WazuhLinuxSyslogOSSECELK StackSecurity Monitoring

VMware vSphere Enterprise Cloud Platform

An enterprise virtualization environment built with VMware vSphere, two ESXi hosts, and centralized vCenter management. It demonstrates resilient workload operation through clustering, availability, balancing, and migration.

VMware vSphere 7ESXivCenter Server AppliancevSphere DRSvSphere HAvMotion

Additional Engineering Projects

Enterprise Network Access Control (NAC)

PacketFence NAC platform using IEEE 802.1X, RADIUS, and identity-based policies to secure enterprise network access.

PacketFenceRADIUSIEEE 802.1XPEAPMSCHAPv2

VoIP Security Hardening (Asterisk & Zoiper)

Asterisk VoIP infrastructure with Zoiper endpoints, secure SIP communications, authentication, and system hardening.

AsteriskLinuxSipSecurity

StockPilot – Inventory Management System

Spring Boot inventory platform for authentication, product and supplier tracking, stock monitoring, and PDF documents.

Java 17Spring BootSpring MVCSpring SecuritySpring Data JPA

GossipGuard – Post-Quantum Secure IPC

Post-quantum IPC system using McEliece encryption to protect process communication against future quantum attacks.

PythonLinuxUNIX SignalsAES-256CBC Mode

Apache Spark – Distributed Computing Engine

Apache Spark engine for large-scale analytics workloads using distributed execution and parallel data processing.

Apache SparkSpark CoreSpark SQLSpark StreamingMLlib

Experience

Professional Timeline

OptiparkCurrent

Cybersecurity Intern (PFA)

Jul 2026 – Present

Supporting the preparation of an internal Security Operations Center through authorized network discovery, asset mapping and vulnerability assessment across Windows, Active Directory, VMware ESXi and Linux environments.

NmapVulnerability AssessmentSOCActive DirectoryVMware ESXiLinux

Key achievements

  • Mapped active hosts, ports, protocols and exposed services across the authorized internal network.
  • Assessed Windows Server, Active Directory, VMware ESXi and Linux assets for vulnerabilities and relevant CVEs.
  • Prepared technical findings for centralized SOC monitoring, incident detection and reporting.
ABSEC Cybersecurity

DevSecOps Intern

Jul 2025 – Jul 2025

Designed and deployed an AI-powered GitLab CI/CD security pipeline combining intelligent commit analysis, automated code inspection, SAST, vulnerability scanning and consolidated reporting to detect risky changes early and reduce security regressions.

GitLab CI/CDCodeBERTCodeT5SonarQubeTrivySAST

Key achievements

  • Integrated CodeBERT and CodeT5 to classify risky commits and detect secrets, injection patterns, weak hashes and XSS indicators.
  • Combined SonarQube and Trivy findings into an automated security workflow prioritizing CRITICAL and HIGH vulnerabilities.
  • Generated consolidated reports to accelerate developer remediation and reduce security regressions.
Hack Secure

Red Team Intern

Apr 2025 – May 2025

Performed hands-on Red Team assessments across web applications and Linux environments, covering vulnerability discovery, exploitation, traffic analysis, privilege escalation, persistence and post-exploitation in controlled laboratories.

Kali LinuxNmapMetasploitWiresharkSQLMapGobuster

Key achievements

  • Identified and exploited SQL injection, XSS and exposed HTTP credentials in vulnerable web applications.
  • Compromised Metasploitable 2, established persistence and performed Meterpreter post-exploitation.
  • Built a Python file encryption and decryption utility using Fernet cryptography.
ENSA Marrakech – Cadi Ayyad University

Cybersecurity & Telecommunication Systems Engineering Student

2022 – 2027

Pursuing a five-year engineering degree combining cybersecurity, telecommunications, cloud infrastructure, virtualization, cryptography and secure software engineering through intensive laboratories, technical projects and professional internships.

CybersecurityTelecommunicationsNetwork SecurityCloud ComputingVirtualization

Key achievements

  • Completed multidisciplinary projects in cybersecurity, cloud infrastructure and secure software engineering.
  • Participated in CTFs, penetration-testing laboratories and security-focused research activities.
  • Completed internships in Offensive Security, DevSecOps and Cybersecurity Engineering.

Skills

Skills & Expertise

Cybersecurity

Security engineering, offensive security, infrastructure protection and enterprise defense technologies.

Network SecuritySecurity Operations Center (SOC)Security Information and Event Management (SIEM)Vulnerability AssessmentThreat DetectionSecurity HardeningPenetration TestingActive Directory Security

DevSecOps & Cloud

Secure delivery pipelines, cloud-native infrastructure, automated validation and production monitoring.

Secure CI/CDInfrastructure as CodeContainer SecurityKubernetesTerraformAWSSecurity TestingCloud Observability

Programming

Software development, security automation, scripting and data-driven application engineering.

PythonJavaTypeScriptSQLPowerShell

Infrastructure & Virtualization

Enterprise infrastructure administration, virtualization platforms and resilient systems engineering.

VMware vSphereWindows ServerLinuxActive DirectoryHigh AvailabilityVirtualization

Networking

Designing, configuring and troubleshooting enterprise network infrastructures using routing, switching, segmentation and core network services.

Enterprise NetworkingTCP/IPVLAN SegmentationRouting & SwitchingDNS & DHCPVPNNetwork Troubleshooting

Artificial Intelligence & Data Engineering

Applied language models, intelligent security analysis and scalable data-processing workflows.

Large Language ModelsHugging Face TransformersApache SparkAI-Assisted Security AnalysisData EngineeringMachine Learning

Certifications

Certifications & Credentials

TryHackMe logo

TryHackMe

Issued April 2026

Security Engineer

Completed advanced hands-on training covering offensive security, penetration testing, privilege escalation, Active Directory, web exploitation and practical attack simulations.

TryHackMe logo

TryHackMe

Cyber Security 101

Developed practical cybersecurity fundamentals through hands-on labs covering Linux, Windows, networking, web security and common attack techniques.

Cisco logo

Cisco

Issued January 2025

Introduction to Cybersecurity

Built a strong foundation in cybersecurity principles, digital threats, network defense and secure online practices.

MLIA Edu logo

MLIA Edu

Issued June 2026

Mobile Application Security

Explored Android application security, vulnerability assessment, secure mobile development and protection against common mobile threats.

ISC² logo

ISC²

Network Security Fundamentals

Developed foundational knowledge of secure network architecture, segmentation, communication protocols, access control and enterprise defense strategies.

ISC² logo

ISC²

Incident Response & Disaster Recovery

Studied incident handling, business continuity and disaster-recovery strategies for improving organizational cyber resilience.