Edmonton, AB, Canada

Abderrahim
Mayaba

Application Security Engineer & Security Developer

With a background spanning software development, application security, and cybersecurity, I embed security into the SDLC — from vulnerability discovery and code reviews to developing fixes and safe production releases.

Abderrahim Mayaba
Open to new opportunities
SELECTED IMPACT

Work that moved the needle

WORKJAM • 2023–2025

Reachability Analysis
Pipeline

Snyk SCA was generating high volumes of low-signal findings. I extended Eclipse Steady with support for modern Java versions and built Python automation that performs precise call-graph analysis and auto-generates high-confidence pull requests.

OUTCOME

Dramatically improved signal-to-noise and reduced manual triage workload for both security and engineering teams.

Java Python Snyk Eclipse Steady CI/CD
Concordia University • MEng • 2021

Static Code Analyzer
for Secure Patterns

Built a Java static analysis tool using the Abstract Syntax Tree (AST) to automatically detect the "destructive wrapping" anti-pattern in exception handling — an issue that silently destroys stack traces critical for debugging and security investigations.

OUTCOME

Published open-source tool that helps teams maintain proper audit trails and improve code reliability at scale.

Java Eclipse JDT Maven AST Analysis
View on GitHub
EBTIKAR • 2020–2022

Real-Time Threat
Intelligence Platform

Designed and shipped a web-based IP and hash reputation lookup service plus supporting automation. Previously, threat investigations took over eight hours of manual effort.

OUTCOME

Reduced average investigation time from 8+ hours to real-time, enabling the SOC to scale without adding headcount.

Python Bash SIEM Automation
PROFESSIONAL JOURNEY

Experience

Morgan Stanley
Montreal, QC • November 2025 – Present
Senior Software Developer – Threat & Fraud Detection
  • Embed application security into the SDLC for critical threat and fraud detection platforms, leading code security reviews and driving secure development practices.
  • Integrate SAST, DAST, and SCA tools into development pipelines to identify and remediate vulnerabilities early in the lifecycle.
  • Design and develop advanced detection models that identify real-time threats and fraudulent activity within complex financial applications.
  • Triage, validate, and remediate security findings while partnering with engineering teams to deliver secure, resilient production systems.
WorkJam
Montreal, QC • May 2023 – Oct 2025
Application Security Engineer & Security Developer
  • Integrated and managed SAST, DAST, and SCA (Snyk) tools directly into CI/CD pipelines with automated security gates.
  • Led threat modeling for customer-facing services and third-party integrations; partnered with engineering on secure design patterns.
  • Built custom automation (Python + Java) to reduce false positives and generate actionable developer workflows from scanner output.
  • Managed WAF policies and coordinated third-party penetration testing remediation lifecycle.
Morgan Stanley
Montreal, QC • 2022 – 2023
Software Developer
  • Developed and hardened backend services for large-scale risk monitoring and fraud detection platforms in a highly regulated environment.
  • Renovated legacy Java systems, significantly improving security posture, maintainability, and performance.
  • Applied secure SDLC practices and participated in architectural reviews for critical financial surveillance applications.
Ebttikar Technology
Riyadh, Saudi Arabia • 2020 – 2022
SOC Analyst & Automation Developer
  • Built automation and a real-time reputation lookup service that reduced threat investigation time from 8+ hours to seconds.
  • Led incident response and threat hunting across critical banking systems; developed custom SIEM content and detection rules.
  • Performed static code analysis on suspicious samples and designed security automation workflows that scaled the SOC.
TAV Technologies
Riyadh, Saudi Arabia • 2016 – 2019
IT Team Leader & Aviation Systems Administrator

Led a global team supporting mission-critical airport systems. Owned security, performance, and 24/7 availability for 10+ core aviation platforms serving international stakeholders.

ATU Duty Free
Medina, Saudi Arabia • 2015 – 2016
Information Technologies Specialist

Provided 24/7 production support for critical business systems while managing endpoint security, system administration, and access controls across the organization.

YASREF
Yanbu, Saudi Arabia • 2015
Cooperative Education Student

Designed and built a Java-based information system that automated mobile billing for 2,000+ employees, reducing processing time from several weeks to real-time.

Sky Spectrums Est.
Yanbu, Saudi Arabia • 2013 – 2015
Computer Network Officer (Part-time)

Performed network testing, troubleshooting, and maintenance while maintaining detailed documentation and network diagrams for compliance and operational reliability.

HOW I WORK

I reduce risk without adding friction.

Security only works when it enables teams instead of blocking them. My focus is always on high-signal automation and clear communication.

Application Security & Testing

Threat modeling, manual penetration testing (Burp Suite), secure code review, and OWASP Web Security Testing Guide application.

Burp Suite • Postman • OWASP WSTG
Security Automation & Tooling

Building internal tools that eliminate repetitive work — reachability analysis, reputation services, and custom static analyzers.

Python • Java • Bash • GitHub Actions
DevSecOps & Pipeline Security

Embedding SAST/DAST/SCA into CI/CD with meaningful gates, WAF management, and infrastructure-as-code security reviews.

Snyk • Jenkins • GitHub Actions • Terraform
Cloud & Container Security

Securing Kubernetes workloads, container image scanning, and applying security-as-code principles across AWS and GCP environments.

AWS • GCP • Kubernetes • Docker • Terraform
Vulnerability Management

Prioritizing findings with reachability and context, driving remediation, and producing clear risk narratives for engineering and leadership.

CVSS • Risk Scoring • Stakeholder Reporting
Security Enablement

Mentoring engineers, creating secure coding standards, and building a culture where security is a shared responsibility rather than a gate.

Documentation • Training • Cross-team Collaboration
SKILLS

Skills & Capabilities

A focused set of technical skills drawn from hands-on work across software development, application security, and cybersecurity operations.

Security Testing & Assessment
Penetration Testing Threat Modeling Secure Code Review OWASP WSTG Vulnerability Management Reachability Analysis
Security Automation & Engineering
Security Automation CI/CD Security Policy-as-Code Custom Security Tooling Supply Chain Security WAF & Zero-Day Protection
Cloud & Infrastructure Security
Cloud Security (AWS/GCP) Kubernetes Security Infrastructure as Code Container Security Zero Trust Architecture Observability & Monitoring
Programming & Systems
Java JavaScript / TypeScript Python REST APIs GraphQL APIs Secure Backend Development
EDUCATION
Master of Engineering in Software Engineering
Concordia University • 2019 – 2021
GPA: 3.27
Bachelor of Science in Computer Engineering
Yanbu University College • 2010 – 2015
GPA: 3.22
CERTIFICATIONS
Advanced Web Application Penetration Testing (eWPTX)
INE
Certified Ethical Hacker (CEH)
EC-Council
Certified Security Analyst (ECSA)
EC-Council
CompTIA Security+
CompTIA
CCNA Routing & Switching
Cisco
Currently pursuing: CISSP, eCPPT
WRITING

Thoughts on practical security

I occasionally write about real-world AppSec challenges, building effective security automation, and what actually works when embedding security into fast-moving teams.

More long-form writing coming soon.

LET'S TALK

I tailor every conversation.

I prepare a focused resume and talking points for each opportunity. If you're building a security team or looking for someone who can both find problems and help fix them at scale, I'd love to hear from you.