Mark El-Khoury

Director of Engineering

New York, New York, United States10 yrs 7 mos experience

Key Highlights

  • Expert in Cyber-security and Penetration Testing.
  • Led vulnerability management programs across multiple organizations.
  • Experienced instructor in Cybersecurity Bootcamp.
Stackforce AI infers this person is a Cyber-security expert with extensive experience in vulnerability management and penetration testing.

Contact

Skills

Core Skills

Cyber-securityPenetration TestingVulnerability ManagementVulnerability Assessment

Other Skills

Terminal & BashLinux & Windows Sysadmin FundamentalsArchiving and Logging DataNetwork SecurityCloud SecurityCryptographyWeb Application SecuritySIEMDigital ForensicsGovernance, Risk, & ComplianceInfrastructure and application monitoringDevSecOpsCode and design reviewsInternal penetration testsVendor management

About

proficient in word, power point, and paint

Experience

10 yrs 7 mos
Total Experience
2 yrs 1 mo
Average Tenure
2 yrs
Current Experience

Movable ink

Director, Security Engineering

May 2024Present · 2 yrs · NYC

Activision blizzard

Principal Product Security Engineer

Jan 2023May 2024 · 1 yr 4 mos · NYC · Remote

Clear (clearme.com)

ProdSec

Dec 2021Dec 2022 · 1 yr · NYC

  • Emoji curator: Uploaded over 160 Slack Emojis, notably cat-popcorn, vince-2, tada-its-beans, behind-seven-hotdogs, and party-fidget-spinner.

Columbia university in the city of new york

Instructor at Cybersecurity Bootcamp

Jan 2019Jan 2023 · 4 yrs

  • Rambling for hundreds of hours.
  • Terminal & Bash: command line tools, including awk and sed, on a Ubuntu virtual machine setup via vagrant.
  • Linux & Windows Sysadmin Fundamentals: Linux filesystem and hierarchy, file and user permissions (ACL), cronjob scheduling and crontab, managing running processes and services, package managers, password auditing tools like 'john', system privileges, Active Directory, group policies.
  • Archiving and Logging Data: archiving tools (tar), auditing and logging tools (journalctl, logrotate, auditd).
  • Network Security: Secure network architecture & diagrams, firewall configuration and management, snort rules, network security monitoring tools, port scanning (nmap), packet inspection (wireshark).
  • Cloud Security: Microsoft Azure, configuring VNETs, deploying applications on Docker containers via Ansible playbooks, load balancers, security groups, virtualization, redundancy.
  • Cryptography: Symmetric & asymmetric cryptography, hashing algorithms, OpenSSL, GPG, SSL/TLS certificates, hashcat, rainbow tables, steganography, digital signatures.
  • Web Application Security: SQLi, XSS, RCE, code injection, Burp Suite.
  • Penetration Testing: Recon, OSINT, metasploit, msvenom, searchsploit, heartbleed, shellshock, exploitation, meterpreter shell, privilege escalation, persistent access.
  • SIEM: Splunk, ELK stack (Kibana), configuring alerts, thresholds, baselines.
  • Digital Forensics: Data recovery and analysis from an imaged iPhone via Autopsy.
  • Projects: Playing the role of both offense and defense.
  • Governance, Risk, & Compliance: OWASP threat model, training & awareness, policies & standards, risk management, business continuity planning, disaster recovery, governance frameworks, security program effectiveness, organizational security culture & hygiene, auditing, risk analysis and threat modeling to conceptualize, quantify, and communicate the risk of threats to the proper managerial stakeholders.
Terminal & BashLinux & Windows Sysadmin FundamentalsArchiving and Logging DataNetwork SecurityCloud SecurityCryptography+6

Betterment

Lead Security Engineer

Aug 2018Dec 2021 · 3 yrs 4 mos · NYC

  • Applying hacker-repellent spray (organic, grass fed, non-GMO) to infra, apps, people, and door hinges.
  • Infrastructure and application monitoring and hardening.
  • Leading the vulnerability management program.
  • DevSecOps: Securing containers, third party dependencies, CI/CD pipeline, IAM, IaC
  • Cloud security and hardening.
  • Conducting code and design reviews.
  • Opening and reviewing PRs (Ruby, Python, Terraform, Ansible, Java, Bash)
  • Running internal penetration tests.
  • Managing vendor penetration tests and red teams, from scoping to remediation.
  • Devising a DLP program.
  • Devising incident response playbooks.
  • Wrote policies to achieve and maintain SOC2 compliance.
  • Email security (DMARC/DKIM/SPF).
  • Enhancing SIEM usage and the logging pipeline.
  • Handling vendor relationships and tool management.
  • Working closely with various teams and stakeholders across the org.
  • Building a security roadmap.
Infrastructure and application monitoringVulnerability managementDevSecOpsCloud securityCode and design reviewsInternal penetration tests+6

Ncc group

Security Consultant

Sep 2015Aug 2018 · 2 yrs 11 mos · NYC

  • Trade offer: I get to hack, you get a PDF.
  • Conducted penetration tests and vulnerability assessments on various platforms and environments, including: Web applications and services, native Windows applications, internal and external network security assessments, IEEE 802.11 wireless penetration tests, cloud provider configuration reviews, code review, software architecture and design reviews. Also managed bug bounties and immediate response for large clients.
Conducting penetration testsVulnerability assessmentsManaging bug bountiesPenetration TestingVulnerability Assessment

Education

Button Mashing

Stackforce found 100+ more professionals with Cyber-security & Penetration Testing

Explore similar profiles based on matching skills and experience