
Cybersecurity instructor · Founder & CTO, KingSec
Cybersecurity instructor at 22.
Security audits, vulnerability assessment, and hands-on security training for SMBs and MSPs.
KingSec, shipped and audited, is the clearest proof of how I work.
Privilege escalation via misconfigured service role
Identified during the pre-release audit lifecycle and fixed before v1.0.1 shipped. Full finding details withheld from this public writeup.
What I do
Security work you can actually verify.
Four things I do, each backed by real work you can click into, not a services list with nothing behind it.
Security Audits & Hardening
You do not know what is actually exposed until someone checks it — this is a structured pass over your firewall, remote-access security, exposed services, and patch status, with real before/after evidence.
See the audit →Vulnerability Assessment
You need to know what an attacker could actually reach before they do — I run that scanning and analysis using KingSec, the vulnerability-management tool I designed, built, and audited end-to-end myself, not a resold platform.
See KingSec →Security Awareness Training
Most breaches start with a person, not a firewall — this is a 60-minute live session that teaches non-technical staff to actually recognize phishing, business email compromise, and social engineering.
See the deck →Security Tooling & Automation
Not every gap has an off-the-shelf tool — these are custom scripts built for specific checks that came up in real work: scanning, integrity verification, password strength analysis.
See the tools →Proof
Real work, not a pitch.
Led by the clearest evidence first: a real audit, a real product, a real training deck.
Security audit
Ubuntu Security Audit
Single-host security audit of a personal Ubuntu server, 5 findings, all remediated, with before/after evidence for each.
Flagship product
KingSec
Local-first, AI-augmented attack surface & vulnerability management for SMBs and MSPs.
The problem
SMBs and IT admins need real vulnerability management without sending their attack surface data to a third-party cloud.
What is verified
- E1Executed or directly observed.3,234+ tests passing, mypy clean, 3/3 architecture contracts enforced
- E1Executed or directly observed.Full security audit lifecycle completed, including a critical privilege-escalation fix
- E4Product or architecture decision — a judgment call, not a fact to verify.Zero-telemetry, bring-your-own-AI-key architecture reduces vendor lock-in and data exposure risk
Training
Employee Cybersecurity Awareness Training
60-minute live session teaching non-technical staff to recognize and respond to real threats.



Credentials
Cybersecurity instructor at 22. Teaching at PNY Trainings, working as an Information Security Analyst at Cyberlegends, certified in CCEP and CRTOM.
Certified Cybersecurity Educator Professional (CCEP)
Red Team Leaders - 2026
ActiveVerifyCertified Red Team Operations Management (CRTOM)
Red Team Leaders - 2026
ActiveVerifyAlso completing a BS in Computer Science at Virtual University of Pakistan, and holds a Diploma in Professional Cybersecurity from Cyberlegends, 2024 to 2025, including a full security internship.
More about my backgroundGet in touch
Reach out.
If you need a security audit, a vulnerability assessment, or hands-on training for your team, I would like to hear about it.