An open API service indexing awesome lists of open source software.

https://github.com/msaad00/msaad00

GitHub profile for Wagdy Saad: security data, cloud and AI security, detection engineering, and compliance evidence.
https://github.com/msaad00/msaad00

compliance data-engineering github-profile nyc security-analytics security-engineering trustops

Last synced: 11 days ago
JSON representation

GitHub profile for Wagdy Saad: security data, cloud and AI security, detection engineering, and compliance evidence.

Awesome Lists containing this project

README

          

# Wagdy Saad

Staff Security Engineer | Cloud & AI Security | Security Data & Analytics |
Detection Engineering | Vulnerability Management | CSPM & DSPM | GIAC GCTD,
Security+

Based in NYC, with 10+ years across security data and analytics engineering,
cloud security, detection engineering, vulnerability management, and compliance
evidence.

I build security data platforms, detection pipelines, and automated remediation:
asset inventory and visibility, posture and compliance assessment against CIS
and NIST, threat detection mapped to MITRE ATT&CK / ATLAS, and automated
response.

Recent work extends that model to cloud and AI security: AI agent and MCP server
observability, tool usage, access paths, privileged roles, SBOM / AI-BOM
evidence, and customer-controlled governance workflows.

## Focus

- Security data platforms, security analytics, and data engineering.
- Cloud and AI security across AWS, Azure, GCP, Snowflake, agents, and MCP.
- Detection engineering, vulnerability management, CSPM/DSPM, and automated
response.
- Compliance evidence and security posture mapped to CIS, NIST, MITRE ATT&CK,
MITRE ATLAS, and OWASP LLM.
- Cross-functional work with GRC, Product, and customer-facing teams to turn
security data into self-serve evidence and product-grade posture workflows.

## Credentials

- GIAC Cloud Threat Detection (GCTD).
- SANS SEC541: Cloud Security Threat Detection.
- Certified DSPM Architect.
- CompTIA Security+ ce.
- SnowPro Core.

## Public Work

| Lane | Repository | What it shows |
|---|---|---|
| AI supply-chain security | [agent-bom](https://github.com/msaad00/agent-bom) | CVE blast-radius mapping, AI-BOM/SBOM evidence, graph-backed findings, MCP/server inventory, runtime controls, and compliance mappings for AI agents and MCP servers. |
| Security data platform | [cloud-ai-security-skills](https://github.com/msaad00/cloud-ai-security-skills) | Cloud and AI security automation: ingestion, OCSF normalization and mapping, compliance tagging, CIS benchmark skill bundles, and security data lake workflows. |
| TrustOps data systems | [trustops-security-data-lake](https://github.com/msaad00/trustops-security-data-lake) | Security analytics and governance data lake patterns for findings pipelines, audit trails, compliance analytics, and control-plane reporting. |
| SQL analytics foundation | [sql-analytics-portfolio](https://github.com/msaad00/sql-analytics-portfolio) | Archived SQL analytics exercises covering business question logic, retention, ranking, cohorts, marketplace analytics, finance-style reporting, and operational analytics. |
| HBS Bank attrition analytics | [hbs-bank-customer-attrition-analytics](https://github.com/msaad00/hbs-bank-customer-attrition-analytics) | Archived 2021 customer attrition project: Python churn EDA, statistical testing, visualization, ML modeling, Tableau workbook, and technical presentations. |
| AEMR outage analytics | [aemr-outage-sql-analytics](https://github.com/msaad00/aemr-outage-sql-analytics) | Archived 2021 SQL project analyzing approved and forced energy outage events by participant, facility, year, duration, outage count, and MW loss. |
| Holland Hotels analytics | [holland-hotels-booking-analytics](https://github.com/msaad00/holland-hotels-booking-analytics) | Archived 2021 hotel bookings project with booking insights, logistic regression artifacts, Tableau workbook, and executive/technical presentation work. |
| Chem Corp BI portfolio | [chem-corp-business-intelligence](https://github.com/msaad00/chem-corp-business-intelligence) | Archived 2021 business analytics project with problem framing, Tableau workbook, and stakeholder-ready presentation artifacts. |

## How To Read This Profile

The older analytics repositories are intentionally public as historical
portfolio evidence. They show the SQL, Python, BI, and analytics engineering
foundation behind the current security analytics, security engineering,
compliance, TrustOps, cloud security, and AI security work.

No company names are listed here; this profile is organized around public work,
technical scope, and evidence.