Cybersecurity Portfolio

Defence.
Detection. Response.

Building secure digital systems, identifying vulnerabilities, and responding to real-world threats with discipline and rigour.

MSc Cybersecurity (in progress) · Incident Response · Secure Coding · Data Privacy & Compliance · Network Security · WordPress Security

MSc
Cybersecurity
1
Live Incident Resolved
CISCO
Certified
0
Downtime During Recovery
Network Security Incident Response Data Privacy & Compliance Secure Coding Vulnerability Assessment WordPress Hardening GDPR / Privacy Frameworks Risk Management Malware Analysis Plugin Audit Network Security Incident Response Data Privacy & Compliance Secure Coding Vulnerability Assessment WordPress Hardening GDPR / Privacy Frameworks Risk Management Malware Analysis Plugin Audit

Security as a Mindset

My cybersecurity journey started from the inside out — building secure products in my Computer Science degree, and now deepening that understanding through a Master's in Cybersecurity at Swinburne University / Barzan University College, Doha.

I don't just study security in theory — I've responded to a real-world website compromise, conducted structured plugin vulnerability audits, and remediated live threats on production systems without service disruption.

I believe security is most powerful when it's baked into the design process from the start — not bolted on at the end. That's the lens I bring to every digital product I build or maintain.

Defensive Security Incident Response Privacy-by-Design Secure Development Risk-Aware Thinking
security_profile.sh

$ whoami

Ameera Khan — Cybersecurity Graduate Student


$ cat qualifications.txt

MSc Cybersecurity (In Progress) — Swinburne / Barzan UC

BSc Computer Science — GPA 9.75/10

CISCO: Introduction to Cybersecurity ✓


$ ls ./skills/

network_security/  incident_response/
  secure_coding/   data_privacy/
  risk_management/  wordpress_hardening/


$ cat notable_incident.log

[RESOLVED] Live WordPress compromise detected

Root cause: Unpatched outdated plugins

Action: Malware removed, plugins audited & updated

Downtime: 0 minutes


$ # Status: Ready for the next challenge

Expertise & Skills

Defensive & Applied Security

Data Privacy & Compliance85%
Incident Response & Recovery82%
Vulnerability Assessment78%
Network Security Fundamentals78%

Secure Development

Secure Coding Practices80%
WordPress Security Hardening85%
Risk Management Frameworks76%
Plugin & Dependency Auditing88%

Tools & Technologies

WordPress Security Plugin Auditing Network Scanning GDPR / Data Privacy Risk Assessment Malware Removal Cross-browser Testing Firebase Security Rules ReactJS Secure Coding CISCO Networking Linux CLI Log Analysis

Security Projects

Real-world security work and applied cybersecurity projects.

🔍
Security Recovery
THREAT
DETECTED & RESOLVED
Malicious links removed
Root cause identified
Plugins audited & patched
Zero downtime during recovery

Caught in the Act: Live WordPress Security Recovery

Shortly after joining ILM Education, I noticed something unusual on the live website: random words appearing mid-sentence, all hyperlinked to an unknown Ukrainian domain. This was not a design choice — the site had been compromised through outdated, unpatched WordPress plugins.

Investigation Methodology

1. Verified issue across multiple browsers and devices (ruled out local glitch)

2. Audited WordPress dashboard login and activity logs

3. Identified compromised entry point: outdated/expired plugins

4. Removed all malicious embedded links from the live codebase

5. Deleted all unused and expired plugins from the installation

6. Updated every active plugin to its current, patched version

7. Verified clean state across all pages post-remediation

Key Security Lesson

Outdated plugins are one of the most common WordPress attack vectors. Unpatched vulnerabilities give attackers a persistent, low-visibility entry point. Regular plugin audits are essential maintenance — not optional.

WordPress Plugin Security Audit Malware Removal Incident Response Cross-browser Testing
Visit Restored Site
GenRx 🏆 Award Winner

GenRx — Security-Conscious Health Application

As the architect of GenRx — a personalised medicine recommendation platform — I designed the application with privacy-by-design principles from the ground up. Health applications handle sensitive PII (Personally Identifiable Information) and require careful thought about data minimisation, consent flows, and secure data handling.

Security Design Considerations

  • · User consent and data minimisation in medical recommendations
  • · Secure storage of health data via Firebase security rules
  • · Privacy-first UX — no unnecessary data collection
  • · Role-based access for patient vs. system interactions
Privacy-by-Design Firebase Security Rules Health Data Protection FlutterFlow Data Minimisation
Behaviour Management Module Thesis Project

Behaviour Management Module — Secure LMS Build

My final-year thesis project — a full Learning Management System (LMS) prototype built on ReactJS and Firebase — incorporated security considerations throughout the development lifecycle. As a system handling student data and educational records, securing both the data layer and the access controls was a core requirement.

Security Implementation

  • · Firebase Authentication for secure user identity management
  • · Role-based access control (teacher vs. student views)
  • · Firebase Security Rules preventing unauthorised data reads/writes
  • · Input validation to prevent injection vulnerabilities
  • · Secure data architecture for sensitive student records
ReactJS Firebase Auth Security Rules Role-Based Access Input Validation

Credentials

Master of Cybersecurity

In Progress

Barzan University College · Swinburne University of Technology, Doha

Focus: Secure digital infrastructure, risk management, data privacy, compliance frameworks, network security, and advanced threat analysis.

CISCO: Introduction to Cybersecurity

Certified ✓

CISCO Networking Academy

Foundations of cybersecurity: threat landscapes, common attack types, defence strategies, and the role of security professionals in modern organisations.

B.Sc. Computer Science

GPA 9.75/10

MIE–SPPU, Doha, Qatar · Highest Academic Scorer · Scholarship

Core CS curriculum including data structures, algorithms, networks, databases, and software engineering — forming the technical foundation for applied security work.

CISCO: Introduction to Data Science

Certified ✓

CISCO Networking Academy

Data analysis and interpretation skills that support security analytics, log analysis, and threat pattern recognition.

🌐 Community & Events

Qatar Cybersecurity Symposium
Active participant in Qatar's national cybersecurity community events
World AI Summit, Doha
Attendee — intersection of AI and security at national level
QSTP (Qatar Science & Technology Park)
Active in Qatar's technology innovation ecosystem
Katara Innovation Programmes
Award-winning participant (GenRx — 5,000 QAR prize)

Security Insights

Key takeaways from real-world security work and ongoing studies.

🔒

Patch Early, Patch Often

The ILM Education compromise was enabled entirely by outdated plugins. A regular update and audit cadence would have closed the window before it was exploited. Most breaches exploit known vulnerabilities — not zero-days.

🛡️

Security Starts at Design

Retrofitting security onto an existing system is always harder and more expensive than designing it in from the start. Privacy-by-design isn't just a compliance checkbox — it's a philosophy that saves significant remediation effort later.

📋

Methodical Incident Response

When a system is compromised, working systematically from the outside in — verifying scope, then identifying root cause before remediation — prevents both missing things and breaking things. Speed without structure makes incidents worse.

👤

The Human Factor

Technical controls are only as effective as the people operating them. Security awareness, clear processes, and a culture that reports anomalies without fear are as important as any firewall.

📊

Data Minimisation Wins

You cannot lose data you never collected. Designing systems to collect only what's necessary — and handling it with appropriate controls — is both a privacy best practice and a security risk reduction strategy.

🔗

Third-Party Risk is Real

Plugins, libraries, and third-party integrations expand your attack surface beyond your own code. Every dependency is a potential vector. Regular audits, minimal permissions, and keeping the dependency count lean all reduce exposure.

Interested in Collaboration?

Open to cybersecurity roles, research collaborations, and security consulting projects. Let's build something that's not just functional — but genuinely secure.