Jason Achkar Diab
CompTIA Security+ · AZ-900 · SC-500 (In Progress) · MSc Cybersecurity — Georgia Tech
Platform and DevSecOps engineer with a software engineering foundation and production experience building secure CI/CD pipelines, infrastructure-as-code, and multi-tenant cloud systems on Microsoft Azure. Solo-built and deployed SecureObs, a security SaaS unifying seven scanners with cross-tool deduplication, CI/CD build gating, and credential-free IaC attack-path analysis.
Current Focus
Security+, AZ-900, Google Cybersecurity, SC-500 in progress
Platform engineering, DevSecOps, full-stack secure development
Covered across detection rules, tooling, and cloud controls
Open to Opportunities
Cloud Security Engineer, Security Consultant, DevSecOps roles in Canada or remote
About Me
Platform & DevSecOps engineer building secure systems from the ground up.
I'm a platform and DevSecOps engineer at Genetec, where I administer and secure the R&D engineering platform (Azure DevOps Server/Services and GitHub), enforce access governance, and build internal tooling in C#, Go, and PowerShell to automate configuration and compliance across shared developer systems.
I hold a Bachelor of Computer Science from Concordia University (2025), am pursuing an MSc in Cybersecurity (Information Security) at Georgia Tech (2026–2028), and hold CompTIA Security+, AZ-900, and Google Cybersecurity certifications, with SC-500 in progress. I approach problems from both a builder and defender perspective.
Outside of my day job, I solo-built SecureObs — a production-deployed, multi-tenant security SaaS at secureobs.com — that unifies seven open-source scanners with an IaC attack-path engine, cross-tool deduplication, SARIF export, and CI/CD build gating. My goal is to work in security engineering, cloud security architecture, or DevSecOps roles where I can help teams build secure systems at scale.
Focus Areas
Core Strengths
Platform Security
Securing developer platforms, pipeline policies, and access governance at scale
Secure CI/CD
Build gates with SAST, DAST, secrets scanning, SCA, and IaC validation
Cloud Architecture
Azure defense-in-depth: Key Vault, Managed Identities, private networking, RBAC
Security Engineering
Threat modeling, secure SDLC, OWASP/CWE mitigations, least privilege
IaC Automation
Terraform, HCL static analysis, ephemeral sandboxed runners, config governance
SaaS Product Development
Solo-built production multi-tenant security SaaS with defense-in-depth architecture
Security Domain Coverage
Professional Experience
Secure software development with a focus on building resilient systems and integrating security throughout the SDLC
Platform Engineer — Software Configuration Management & Tools (Engineering Efficiency)
Genetec Inc.
Key Achievements
- Administer and secure the R&D ALM platform (Azure DevOps Server/Services and GitHub) for engineering teams, enforcing secure configurations, branch/pipeline policies, and access governance
- Build and maintain internal tooling and libraries in C#, Go, and PowerShell that automate configuration, governance, and reporting across shared developer applications
- Design, configure, and maintain build and release pipelines with conditional gates and environment promotion logic; provision supporting infrastructure as code with Terraform on Azure
- Develop data export and reporting tooling that surfaces configuration, compliance, and pipeline health across teams to support governance decisions
Security Highlights
- Enforcing secure-by-default configurations and access governance across shared source-control and build systems
- Standardizing pipeline policies and branch protections across the R&D platform
- Provisioning least-privilege infrastructure-as-code on Azure
Technologies
Full-Stack Developer, DevSecOps
SES & Technologies Ltd.
Key Achievements
- Built and integrated a DevSecOps toolchain into Azure DevOps pipelines (Semgrep SAST, OWASP ZAP DAST, Gitleaks secrets scanning), containerized with Docker, with gates that block promotion on high-severity findings
- Designed and implemented RBAC/IAM from scratch across enterprise applications: authentication flows, role/permission scoping, and access-group management via Angular + NgRx administration panel
- Architected and delivered .NET backend services and REST APIs following Clean Architecture, DDD, CQRS, and Repository patterns, plus Angular frontends, across the full SDLC
- Engineered pipeline-as-code (YAML) build, test, and release stages with conditional gates and environment promotion across multi-repository codebases
Security Highlights
- Integrated SAST, DAST, and secrets scanning into production CI/CD pipelines with hard security gates
- Designed RBAC/IAM architecture from zero for enterprise applications
- Applied least-privilege and secure-by-design patterns throughout delivery
Technologies
Software Developer Intern — AutoVu
Genetec Inc.
Key Achievements
- Delivered backend services in .NET and C# for the AutoVu platform, a system serving law-enforcement agencies handling sensitive data
- Integrated REST and SignalR APIs for real-time communication in a microservices ecosystem
- Wrote unit and integration tests to reduce regression risk ahead of releases in a security-critical environment
Security Highlights
- Worked in a security-critical production environment handling law-enforcement sensitive data
- Contributed to testing practices that reduce regression risk in a sensitive-data context
Technologies
Applications Engineer Intern
Matrox Graphics Inc.
Key Achievements
- Built diagnostic automation tooling in Python and C# to surface misconfigurations, insecure defaults, and overly permissive access settings in customer deployments — improving time-to-resolution by 55–65% for enterprise support cases
- Performed configuration audits and log analysis to identify root causes and security gaps
- Authored hardening recommendations and standardized triage documentation across support teams
Security Highlights
- Built tooling specifically targeting misconfiguration detection, insecure defaults, and overly permissive access in enterprise deployments
- Delivered hardening recommendations and standardized security documentation
Technologies
Featured Projects
Cybersecurity projects demonstrating security architecture, threat detection, and secure development practices
SecureObsDevSecOps Security Observatory
A deployed, multi-tenant DevSecOps SaaS that unifies seven open-source security scanners into a centralized triage and enforcement platform. SecureObs provides normalized findings, cross-tool correlation, CI/CD build gates, pull-request feedback, and Terraform-based Azure attack-path analysis through a .NET 8 Clean Architecture backend, Angular 21 SPA, and PostgreSQL with defense-in-depth tenant isolation.
SAST, SCA, secrets, container, IaC, Python, and JavaScript security analysis through one versioned scanner image.
Unit, HTTP integration, and PostgreSQL Testcontainers coverage for authorization, RLS, ingestion, billing, deduplication, and build gates.
Managed integrations for GitHub Actions and Azure DevOps, including repository discovery, generated pipeline changes, and first-run verification.
Application-level authorization backed by PostgreSQL FORCE row-level security under a restricted runtime database role.
Multi-scanner aggregation and enforcement
Runs seven security scanners through one versioned container, normalizes heterogeneous outputs into a unified finding model, correlates repeated and cross-tool results, and enforces project-specific build-gate policies.
IaC attack-path analysis
Processes Terraform plan data inside customer-controlled CI, uploads only a sanitized topology model, and maps findings onto Azure resource relationships to surface infrastructure exposure and attack paths without receiving cloud credentials, state files, or raw plans.
Defense-in-depth multi-tenancy
Combines tenant-scoped application authorization with PostgreSQL FORCE row-level security, separate migration and runtime database roles, fail-closed tenant context, and real PostgreSQL isolation regression tests.
Managed CI/CD integrations
Connects GitHub and Azure DevOps repositories, discovers Terraform roots, generates reviewable pipeline changes, provisions project-scoped API keys into encrypted CI secret stores, and verifies the resulting integration.
Identity, secrets, and auditability
Uses Microsoft Entra ID with PKCE, hashed and revocable pipeline API keys, Azure Key Vault with Managed Identity, append-only administrative audit records, security headers, rate limiting, and Application Insights telemetry.
Self-verifying release pipeline
Builds, versions, signs, and publishes scanner images with SBOM and provenance attestations, updates deployed scanner configuration, scans SecureObs with its own release artifact, and validates ingestion and build-gate behavior through automated canaries.
More projects and labs in development. Check my GitHub for the latest updates.
Certifications & Education
Structured learning path combining industry certifications with formal academic study in cybersecurity
Certifications
CompTIA Security+
Industry-standard certification covering core cybersecurity principles, threat analysis, risk management, and security controls across networks, applications, and cloud environments.
Key Skills
SC-500: Microsoft Cloud & AI Security Engineer
Advanced certification for implementing Microsoft cloud security controls, AI security, Microsoft Defender, and compliance solutions across Azure environments.
Key Skills
Microsoft Azure Fundamentals (AZ-900)
Foundational certification demonstrating knowledge of cloud services, Azure architecture, security, privacy, compliance, and trust in Microsoft Azure.
Key Skills
Google Cybersecurity Professional Certificate
Comprehensive program covering security foundations, network security, Linux, Python automation, threat detection with SIEM tools, and incident response procedures.
Key Skills
Education
Master of Science in Cybersecurity, Information Security Specialization
Georgia Institute of Technology
Online • 2026 – 2028 (In Progress)
Highlights
- Secure software development
- Identity and access management
- Network security and intrusion detection
- Applied cryptography
- Software vulnerability analysis
Bachelor of Computer Science
Concordia University
Montreal, QC • Graduated April 2025
Highlights
- Software architecture
- Computer networks
- Database systems
- Secure software development
- Operating systems
SIEM Detection Console
A quick look at the event stream and detections — the full console with the query builder, timeline, and MITRE-mapped detection rules lives on its own page.
SOC Detection Stream
Latest correlated security events
Investigate the complete dataset
Query builder · timeline · MITRE rules · export
MITRE ATT&CK Coverage
Techniques covered across detection rules, tooling, and cloud controls — click any tile to see how it's covered and where it's implemented
Recent CVE Intelligence
Live feed of recent Common Vulnerabilities and Exposures — I track this because attackers do.
Powered by CIRCL CVE · Scores are CVSS base scores · Links open the NVD entry
Technical Writing
In-depth guides on cloud security, detection engineering, and AppSec — published at docs.jasonachkardiab.com
Get In Touch
Interested in cloud security, cybersecurity consulting, or DevSecOps roles? Let's connect. Open to opportunities in Canada and remote positions.
Security Engineer
Cloud & application security architecture, threat modeling, secure code review, and security posture uplift for Azure-first teams.
DevSecOps Engineer
Embedding security into CI/CD pipelines, automating SAST/SCA/container scanning gates, and building shift-left security culture.
Cloud Security Consultant
Azure security posture review, landing zone hardening, Sentinel detection pack deployment, and Zero Trust IAM advisory.
Drop a line
Links
Prefer async? Reach out via email or socials. Resume is available to preview or download.