Skip to content
View MusahIssah's full-sized avatar

Block or report MusahIssah

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
MusahIssah/README.md
LinkedIn

Hi, I'm Musah!
Cybersecurity Governance, Risk, and Compliance (GRC) professional with hands on experience supporting governance, risk management, compliance, and cybersecurity initiatives across federal and regulated environments. I am passionate about helping organizations strengthen their security posture through effective governance, risk management, compliance, and security controls.

Objective

Motivated and detail-oriented aspiring GRC Analyst seeking to apply foundational cybersecurity knowledge and hands-on experience in NIST RMF, Incident Response, TPRM, SOC 2, ISO 27001, STIG, eMASS, and SIEM tools. Eager to contribute to a security-focused team while continuing to grow through real-world investigations, scripting, and industry certifications.

Skils

SIEM Implementation and Log Analysis

Network Traffic Monitoring and Attack Detection

Security Automation with Shuffle SOAR

Incident Response Planning and Execution

Scripting and Automation for Threat Mitigation

System Hardening Practice

Active Directory

Tools

Network

Endpoint

SIEM

CLOUD

Certifications

Pinned Loading

  1. Phishing-Simulation-Kali365-Device-Code-OAuth-Attack-Pattern Phishing-Simulation-Kali365-Device-Code-OAuth-Attack-Pattern Public

    A hands-on phishing simulation built in Microsoft Defender for Office 365's Attack Simulation Training, modeled on the FBI's May 2026 public advisory on Kali365 — a phishing-as-a-service kit that h…

    2

  2. irongate-defense-solutions-nist-rmf irongate-defense-solutions-nist-rmf Public

    omplete NIST RMF Authorization Package for a simulated federal contractor environment. Includes FIPS 199, SSP, POA&M, SAR, ATO Memorandum, and ISAs built on a live Windows Server 2022 homelab.

    1

  3. Nessus-Credentialed-Vulnerability-Scan-Lab Nessus-Credentialed-Vulnerability-Scan-Lab Public

    Hands-on walkthrough of a credentialed vulnerability scan using Nessus Essentials against a Windows Server lab target — includes methodology, screenshots, and CVE analysis.

    1

  4. okta-threat-detection-lab okta-threat-detection-lab Public

    Hands-on Okta identity threat simulation lab — Credential Stuffing, Impossible Travel, and MFA Fatigue detection using Okta ThreatInsight and Active Directory

    1

  5. windows-sandbox-malware-analysis windows-sandbox-malware-analysis Public

    Analyzed a suspicious email attachment using Windows Sandbox — identified masquerading executable, unexpected process spawns (cmd.exe, PowerShell), and blocked C2 callback. Zero-cost SOC triage tec…

    1

  6. Windows-Server-2022-DC-STIG-Compliance Windows-Server-2022-DC-STIG-Compliance Public

    Hands-on RMF/ISSO project: hardened a Windows Server 2022 Domain Controller against the DISA STIG using SCC + STIG Viewer, with real findings, remediation, and verified evidence.

    1