Cybersecurity student · Bahrain
Governance, risk and compliance for the GCC financial sector —
with enough offensive grounding to know what the controls are defending against.
Bahrain's banking and fintech sector is regulated by the Central Bank of Bahrain, audited against international standards, and served largely by professionals who specialise in one side or the other. I'm building toward the intersection: someone who can read a CBB requirement, map it to ISO 27001 and NIST CSF, and also explain what an attacker does when that control is missing.
Most security content in the region is written in English for people who already understand it. I also publish in Arabic, for people who don't yet.
| Lane | Where I am | Where I'm going |
|---|---|---|
| Offensive security | Foundations through hands-on labs | HTB CPTS, then OSCP |
| GRC & audit | Mapping CBB Rulebook requirements to ISO 27001 and NIST CSF 2.0 | Applied assurance work; CISA |
| Cloud & fundamentals | AWS Cloud Practitioner certified | CompTIA Security+ |
Offence is the lane I find genuinely interesting. GRC is the income floor. Doing both is deliberate — auditors who have never seen an exploit write controls that look correct on paper.
bahrain-grc-framework — CBB Rulebook OM-5.5 mapped to ISO/IEC 27001:2022 and NIST CSF 2.0, control by control, in English and Arabic. All 62 paragraphs are covered, alongside a five-phase implementation plan for organisations starting with no control baseline, a documented methodology, and a candid limitations section. Mappings are under row-by-row verification and are labelled as drafts until that pass is complete.
hash-cracking-reference — Why legacy password hashing fails, how attackers exploit it, and what to do when you find MD5 in production. Covers the part most remediation plans skip: hashing is one-way, so you cannot convert legacy hashes, and "replace MD5 with Argon2id" is not an executable instruction on a live system.
طالب أمن سيبراني في جامعة البحرين · محتوى تقني بالعربية
Open to internship conversations in GRC, IS audit, and security operations across Bahrain and the GCC.