Hey there, I'm Sajawal 
π Full-stack software engineer with a security focus, based in Woking, UK. I build and ship production systems end to end β from a live Rails 8 e-commerce platform I designed and run solo, to multi-tenant SaaS serving 1700+ enterprise clients, to AI-driven security automation pipelines. MSc Cybersecurity (Distinction) from London Metropolitan University and CompTIA Security+, with a focus on DevSecOps, full-stack engineering, vulnerability management, and offensive security.
π Featured β mobilegift.co.uk Β 
A commercial e-commerce platform I designed, built and run solo in Ruby on Rails 8 β serving real customers with live Stripe payments, a device catalogue, and a multi-branch inventory & reservations dashboard. Full lifecycle ownership: front end in Hotwire (Turbo + Stimulus) and Tailwind CSS, containerised with Docker, deployed to Azure for testing, then onto my own hardened VPS with TLS in production β with Brakeman static analysis and dependency scanning in the workflow. I'm the only engineer and the only person on call. It takes real orders today. β mobilegift.co.uk
An end-to-end Rails 8 pipeline: IOC β LLM β MCP servers β automated threat intelligence report. Extracts indicators of compromise from unstructured reporting, cross-references them against an organisation's own infrastructure to determine genuine relevance, and produces a CVSS 3.1-scored assessment with MITRE ATT&CK phase mapping. Built for unreliable conditions: Solid Queue background jobs, JSONB caching so inference never repeats, and NDJSON streaming with automatic fallback to a synchronous path.
A dynamic script-loading harness emulating an e-skimming attack, built from the attacker's side to understand how the technique stays unnoticed rather than how to block it.
Integrating the mcp-for-security framework with Claude Desktop, and running Bolt (Docker-based Kali tooling over MCP) as the execution bridge. Routes IOCs β IPs, domains, URLs, APKs β to the right offensive-security tool: Nmap, Amass, SQLmap, Nuclei.
Reproduced and analysed RevSlider vulnerabilities CVE-2014-9734 and CVE-2017-18535 against a controlled WordPress instance β working from advisory to working exploitation. Ongoing hands-on practice on HackTheBox and TryHackMe, plus a lab environment I build and attack myself.
MSc Cybersecurity Β· Distinction Β· 90% in Cyber Forensics & Cyber Incident Response Β· Advanced Ethical Hacking, Cyber Security Management, Cloud Security
Forensic report graded "an exemplary forensic report that sets a benchmark for technical excellence and investigative rigour."
BS Computer Science Β· Dean's List of Honors (Dec 2022, Jun 2020)
π‘οΈ CompTIA Security+ β 2026
Built and maintain the company's live e-commerce platform (see Featured) end to end, from first line of code to production hosting β unpaid, alongside a customer-facing retail and device-repair role held throughout my MSc.

