Skip to content
View mkouchaoui's full-sized avatar

Block or report mkouchaoui

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mkouchaoui/README.md

Hi there, I'm Mohamed Kouchaoui πŸ‘‹

Senior AI Engineer & DevSecOps Specialist Β· London, UK πŸ‡¬πŸ‡§

LinkedIn Email Twitter Website

Typing SVG


🧠 About Me

  • πŸ” 4+ years securing cloud-native platforms across AWS and GCP, with a focused specialism in LLM/AI security.
  • πŸ›‘οΈ Building security frameworks for LLM-powered SaaS β€” prompt-injection mitigation, adversarial red-teaming, vector DB hardening.
  • βš™οΈ Hands-on Kubernetes, Terraform, and GitOps engineering with zero-trust by default.
  • πŸ“ˆ Track record: 75% workflow optimisation Β· 40% efficiency gains Β· 99.99% uptime through secure automation.
  • πŸŽ“ AWS Security – Specialty Β· GCP Professional DevOps Engineer certified.
  • 🌐 Open to relocation Β· visa sponsorship required.

πŸš€ Tech Stack

☁️ Cloud & Platform

AWS GCP Linux

πŸ“¦ Containers & Orchestration

Kubernetes Docker Helm OPA

πŸ—οΈ IaC & GitOps

Terraform Ansible ArgoCD GitHub Actions GitLab CI

πŸ›‘οΈ DevSecOps

Trivy Sigstore SonarQube OWASP ZAP

πŸ€– AI / LLM Security

OWASP LLM Top 10 MITRE ATLAS Pinecone Weaviate

πŸ’» Languages

Python Go C++ Bash PHP Next.js


πŸ› οΈ Featured Projects

πŸ” AI Security Framework β€” LLM-based SaaS

End-to-end security layer for an LLM-powered SaaS, mapped to OWASP LLM Top 10 & MITRE ATLAS.

  • ~92% reduction in successful prompt-injection attempts in red-team exercises.
  • Real-time mitigation pipeline: input sanitisation, semantic firewalls, classifier-based detection (direct + RAG vectors).
  • Adversarial testing harness as a CI/CD release gate (jailbreak, role-play, encoding attacks).
  • Vector DB hardening (Pinecone, Weaviate) β€” tenant isolation, embedding-poisoning detection.

βš“ Secure Cloud Platform & GitOps Pipeline β€” PC HALLE

  • Verifiable supply-chain integrity via ArgoCD + Cosign/Sigstore + SBOM generation.
  • Admission controllers reject unsigned or vulnerable artefacts.
  • ERP/CRM workloads migrated to EKS/GKE with namespace isolation, network policies, zero-trust ingress.

☁️ High-Availability AWS Platform β€” Sneeze.it

  • 99.99% uptime across multi-AZ workloads with auto-scaling and resilient RDS topologies.
  • Manual operational toil halved via Terraform + GitHub Actions deployment gates.

πŸ“Š GitHub Stats

GitHub Stats GitHub Streak

Top Languages


πŸ… Certifications

  • AWS
  • GCP
  • DevOps
  • Data

🌍 Languages

πŸ‡ΈπŸ‡¦ Arabic (Native) Β· πŸ‡¬πŸ‡§ English (C1) Β· πŸ‡«πŸ‡· French (Working) Β· πŸ‡©πŸ‡ͺ German (Elementary)


"Secure by default. Automated by design. Adversarial by mindset."

Profile views

Popular repositories Loading

  1. trivy-plugin-aisec trivy-plugin-aisec Public

    Go 1

  2. My-DevSecOps-Lab My-DevSecOps-Lab Public

    HCL

  3. trivy trivy Public

    Forked from aquasecurity/trivy

    Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

    Go

  4. trivy-plugin-index trivy-plugin-index Public

    Forked from aquasecurity/trivy-plugin-index

    Plugin index for Trivy. This repo is for plugin maintainers.

    Go

  5. mkouchaoui mkouchaoui Public