khashayar@security:~
$
$
$

Khashayar Nazarkardeh

Cybersecurity and AI Security Leader specializing in penetration testing, AI red teaming, and offensive security with expertise in DLP, AI/LLM risk assessment, and governance mapped to frameworks like MITRE ATLAS and OWASP LLM Top 10. I identify how adversaries exploit systems and AI, then translate findings into the controls, policy, and risk decisions organizations need to stay secure.

01 · Experience

In the field

Sole security professional carrying company-wide responsibility across penetration testing, AI governance, and data protection.

Senior Cybersecurity Specialist
SIR Corp · March 2025 – Present

Owns company-wide penetration testing, AI governance, and tool-approval authority, with primary responsibility for the organization's data loss prevention program and oversight of managed detection and response operations.

  • Increased vulnerability scan visibility to 100% across the environment
  • Led company-wide implementation of DMARC and DLP programs
  • Improved Active Directory security hygiene by 22%
  • Authored gold-standard incident response playbooks derived from tabletop exercises
  • Directed company-wide penetration testing across multiple environments and built corresponding remediation plans
Cybersecurity Analyst
FGF Brands · August 2022 – March 2025
  • Performed thorough vulnerability assessments to identify network, application, and system security weaknesses
  • Executed controlled penetration tests to simulate cyber-attacks, exploiting vulnerabilities to evaluate security defences
  • Analyzed findings from penetration tests and provided actionable security recommendations to improve overall security posture
  • Worked closely with Infrastructure and security teams to implement security measures and verify control effectiveness post-remediation
  • Conducted incident investigations on EDR tools
  • Performed threat hunting on the network to detect, isolate, and provide recommendations on threats
  • Provided proactive security investigation and searches across the environment to detect malicious activity
  • Maintained technical proficiency, sharing knowledge firm-wide through tool development, template enhancements, and methodology improvements
  • Identified and implemented improvements in existing processes and procedures
  • Managed DNS records for domains, and SPF, DKIM, and DMARC records for email fraud defence
  • Monitored sign-in logs and email activity, taking action on suspicious behavior
Governance, Risk and Compliance (GRC) Analyst
Reev Tech · September 2020 – June 2022
  • Assisted the Cybersecurity Manager in the execution of security projects
  • Prepared monthly schedules for organizational cybersecurity awareness programs
  • Communicated identified risks to key stakeholders to initiate and drive risk remediation
  • Performed network vulnerability scans and security assessments
  • Provided secure design consulting services on application development projects
Security Operations Centre (SOC) Analyst
Hadafeno Group · September 2019 – September 2020
  • Monitored and analyzed cybersecurity events using Splunk (SIEM), IDS, McAfee antivirus, and other tools
  • Escalated incidents to the L2 SOC team when relevant
  • Analyzed phishing emails reported by internal end-users
  • Triaged security events and incidents, detected anomalies, and reported remediation actions
  • Worked closely with other IT groups to maintain a high level of IT service for internal and external clients
IT Networking Technician
Yekshow Academy · September 2017 – September 2019
  • Installed numerous network devices including routers, switches, controllers, and Wi-Fi APs
  • Configured routers, switches, and controllers to clients' requirements
  • Installed SSDs, RAM, and disk drives
  • Maintained thorough data backup checks on client servers remotely
  • Helped plan and support software and hardware upgrades
Research and Teaching Assistant
Amir Kabir University of Technology · September 2016 – June 2018
  • Developed a program for steganography in images and text files using Python
  • Researched Optical Character Recognition (OCR) for embedding and extracting messages in a cover PDF
  • Investigated sound waves for steganography in cover voices
  • Co-authored the resulting paper: "A New Method for PDF Steganography in Justified Texts"
02 · Research & Publications

Research & Publications

Peer-reviewed contributions to the information security field.

JOURNAL OF INFORMATION SECURITY AND APPLICATIONS · 2019
A New Method for PDF Steganography in Justified Texts

Introduces a text steganography method that hides data within justified PDF text by exploiting the variable spacing text editors insert to remove ragged edges. The secret message is compressed with Huffman coding, then embedded by selectively replacing justification spaces with normal spaces across chosen host lines, with the scheme keyed for each use to strengthen communication security. Compared to prior text-based steganography approaches, the method embeds a higher information payload without altering the cover file's size, requires no electronic file exchange between parties, and remains recoverable even from a printed copy.

View publication (DOI) →
03 · Capabilities

Capabilities with evidence

Offensive security and AI security, backed by hands-on lab work and applied engagement experience.

AI & LLM Security

  • Prompt injection & jailbreak analysis
  • RAG pipeline exploitation
  • MCP / agentic tool-abuse assessment
  • MITRE ATLAS threat mapping

Offensive Security

  • Penetration testing (web, network, AD)
  • Privilege escalation chains
  • Red team methodology
  • Vulnerability research

Governance & Risk

  • AI policy & tool approval frameworks
  • DLP program design
  • Business impact / risk translation
  • Compliance mapping (OWASP, NIST AI RMF)

Security Research & Community

  • Maintains an active research practice tracking emerging vulnerabilities and adversary TTPs
  • Engaged with the security research community, exchanging insights with practitioners on X and through TASK monthly conference discussions
  • Regularly solves offensive security challenge labs on the OffSec platform to keep hands-on skills sharp against evolving attack techniques
04 · Credentials

Certifications

CBBH
Certified Bug Bounty Hunter
✓ verified
CPTS
Certified Penetration Testing Specialist
✓ verified
CWES
Certified Web Exploitation Specialist
✓ verified
OSAI
OffSec AI Red Teamer (AI-300)
◐ in progress
M.S.
Cryptography & Information Security
✓ completed
05 · Perspectives

Perspectives

Original thinking on where security leadership needs to go next — not case studies of confidential work.

PERSPECTIVES · DATA PROTECTION
Why DLP Needs a New Foundation in the AI Era

Data loss prevention was built for a world where humans moved data — copying a file, attaching a document to an email, uploading to a personal drive. Every major DLP program in production today still assumes that model. But that world is gone. AI copilots now read entire mailboxes to draft a reply. Agentic tools summarize confidential documents on request. Employees paste proprietary code into public LLM chat windows without a second thought. None of this looks like the exfiltration patterns legacy DLP was designed to catch, and most organizations are only starting to notice the gap.

The problem isn't the AI tools. It's the missing foundation underneath them. You cannot protect what you haven't classified. Before any policy, any blocking rule, any endpoint control can work, an organization needs a real answer to a basic question: what is this data, and how sensitive is it? Most companies adopting AI tools today don't have that answer at scale. Labels are inconsistent, ownership is unclear, and sensitive data sits mixed in with everything else — which means AI tools reading "all available context" are, by definition, reading things they shouldn't.

Classification has to come first. Not as a compliance checkbox, but as living infrastructure — data labeled consistently at creation, ownership assigned, sensitivity tiers that actually mean something to the tools enforcing them downstream. Skip this step and every control built on top of it is guessing.

Then protection has to be layered, not singular. No single control catches everything an AI-augmented workflow can do with data. Classification tells you what matters. Endpoint policy governs what a device or application is allowed to do with it. Network and cloud monitoring catch what slips past both. Each layer exists because the others will eventually fail or be bypassed — by a misconfigured integration, a compromised account, or simply a tool doing exactly what it was asked to do with data it was never meant to see.

This is the shift security leaders need to make: DLP is no longer a tool you deploy once. It's a foundation you maintain continuously, because the definition of "movement" now includes an AI model reading, summarizing, and acting on data — not just a person sending it somewhere.

The organizations that get ahead of this aren't the ones with the most tools. They're the ones who classify first, control second, and monitor third — in that order, every time.