ACCESS GRANTED // SESSION ACTIVE

OMAR YOUSEF

Cybersecurity Contractor & ResearcherSecurity+CySA+

CySA+ CERTIFIED//APRIL 2026
> SECTION_02 / EXPERIENCE

Experience

National Science Foundation (NSF)

AI Security Researcher

May 2026 – Present

  • Conducting research on the security of AI/ML systems

Partsol

Cybersecurity Contractor

Jan 2026 – May 2026

  • Implemented IAM best practices using JumpCloud to provision, audit, and manage user roles and permissions
  • Troubleshot endpoint issues by designing and deploying PowerShell scripts across systems to enforce security configurations
  • Administered ThreatLocker (EDR), managing application control/requests, and strengthening malware response

Partsol

IT Cybersecurity Intern

Sep 2025 – Jan 2026

  • Assisted in SOC 2 audit preparation and ISO/IEC 42001 (AI Security Governance) compliance efforts
  • Strengthened email defenses by managing Mimecast policies and tuning AI filtering, reducing phishing and false positives
  • Streamlined project tracking by deploying Jira and Confluence for cross-team planning and IT ticket management
  • Managed IT asset inventory for laptops and hardware, regularly updating devices and maintaining accurate lifecycle tracking

School District of Palm Beach County

Lead IT Security Intern

Jun 2025 – Aug 2025

225K+
ENDPOINTS MONITORED
45+
DAILY ALERTS TRIAGED
30%
MTTD REDUCTION
40%
PHISHING CLICK-RATE DROP
  • Monitored 225,000+ endpoints via EDR platforms Carbon Black and CrowdStrike for threat detection
  • Triaged 45+ daily alerts in the Gurucul SIEM platform, reducing MTTD by ~30% and documenting root-cause analyses
  • Conducted vulnerability assessments with Nessus, NodeZero, and ExtraHop RevealX, delivering remediation plans
  • Penetration testing and malware analysis using Kali Linux, Metasploit, SQLmap, Burp Suite, Ghidra, and Autopsy
  • Led phishing and cybersecurity awareness training for 23,000+ staff via Infosec IQ, lowering click-through rates by 40%
  • Configured LightSpeed content filtering, blocking malicious domains to reduce phishing incidents

Basmah

Technical Office Manager

May 2022 – Jul 2023

  • Delivered Tier 1 IT support for hardware, software, and network issues
  • Managed ticketing systems to track incidents, ensuring SLA compliance and faster resolution times
> SECTION_03 / EDUCATION

Education

University of South Florida

Bachelor of Science in Cybersecurity

Tampa, FLExpected May 2028

> RELEVANT COURSEWORK

  • Object-Oriented Programming
  • Programming Concepts
  • Intro to Databases
  • Physics

> HONORS & AWARDS

  • University of Cambridge AICE Diploma
  • Full Bright Futures Scholarship Recipient
  • AP Scholar
> SECTION_04 / TECHNICAL SKILLS

Technical Skills

> LANGUAGES

  • Python
  • MySQL
  • Bash
  • PowerShell
  • HTML
  • CSS
  • TypeScript
  • JavaScript

> SECURITY PLATFORMS

  • OpenVAS
  • NodeZero
  • Tenable Nessus
  • Carbon Black
  • Gurucul
  • CrowdStrike
  • ThreatLocker
  • Mimecast

> SECURITY TOOLS

  • Nmap
  • Kali Linux
  • Wireshark
  • Metasploit
  • BloodHound
  • Burp Suite
  • SQLMap
  • John the Ripper
  • Autopsy
  • YARA
  • Ghidra

> INFRASTRUCTURE & DEVOPS

  • Docker
  • Git
  • FastAPI
  • Next.js
  • React
  • Tailwind CSS
  • JumpCloud
  • Jira
  • Confluence
  • ServiceNow

> NETWORKING

  • TCP/IP
  • DNS
  • DHCP
  • VPN
  • SMB
  • SSH
  • RDP
  • HTTPS
  • SFTP
  • Firewalls
  • IDS/IPS
> SECTION_05 / PROJECTS

Projects

PROJECT_01
BEST USE OF GEMMA 4 · GOOGLE

SPOTTED

AI-Powered Retail Theft Detection & Response

HackABull 2026

AI security cameras that catch shoplifting without falsely accusing anyone. The system spots when an item looks like it's being hidden, sends that clip to a staff member to confirm, and only then plays a calm AI-generated voice announcement in the store. Video never leaves the building, and staff can search past events by asking questions in plain English.

> TECH STACK

Frontend
Next.js 16React 19TypeScriptTailwind CSSThree.js / R3F
Backend
Python (FastAPI)UvicornNext.js API routes
Computer Vision
YOLOv8ByteTrackResNet18OpenCVFFmpeg
AI
Gemma 4 (Ollama)GeminiElevenLabs (TTS)
Data & RAG
MongoDB Atlas (GridFS)SnowflakeSnowflake Cortex Search
PROJECT_02
1ST PLACE CTF4TH PLACE HACKATHON

Fragments

AI-Powered Network Security Platform

Hack the Bay 2026 • Built in 6 hours

A security tool that finds every device on a network, scores how risky each one is from 0 to 100, and draws a live map that updates the moment something connects. You can ask it questions like "which devices are riskiest and why?", watch a simulated attacker move through the network, and export a full PDF security report. Built in 6 hours, with all AI running on the local machine so sensitive network data never leaves it.

> TECH STACK

Frontend
Next.js (TypeScript)ReactTailwind CSSD3.js
Backend
Python (FastAPI)SQLite
AI
OllamaClaude APIChromaDB (RAG)
Real-time
WebSockets
PROJECT_03
2ND PLACE · NEXTERA ENERGY CHALLENGE

Raven

AI-Powered Malware Analysis Platform

HackUSF 2026 • Built in under 24 hours

An AI malware analyst. Upload a suspicious file and an AI agent takes it apart inside a sealed container: unscrambling the code, cracking the encryption hiding the payload, and reporting exactly what the malware does, what it steals, and where it sends the data. On a real malware sample it recovered the entire four-stage attack chain without ever running the malware, the safest way to analyze it. Every step streams live, and you can ask questions about the findings in plain English.

> TECH STACK

Frontend
Next.jsReact
Backend
FastAPI
Infrastructure
Docker
AI
Claude Agent SDKClaude Sonnet
Security Tooling
pefileILSpy (ilspycmd)Python cryptographyrestringer
PROJECT_04

ScopeUSF IoT Camera System

Raspberry Pi 5 Surveillance Platform

SCOPE Club • Production Deployment

A Raspberry Pi camera platform built for USF's SCOPE engineering club and running in production. It streams live video and allows remote hardware control from anywhere over a secure private VPN, and starts itself automatically on boot.

> TECH STACK

Streaming
Pythonaiohttppicamera2 (MJPEG)
Hardware
Raspberry Pi 5gpiozero (GPIO)
Networking
Tailscale VPN
Deployment
systemd
> SECTION_06 / CVE DISCLOSURES

CVE Disclosures

// I find and report security vulnerabilities in widely used open-source AI platforms. Three credited disclosures so far, including a Critical (CVSS 9.8) remote command execution and a published High-severity CVE, with more under coordinated disclosure. Identifiers appear here once their public records are live.

  • CVE-2026-59219GHSA-855v-hq7w-jmjw
    HIGH · 7.1
    PUBLISHED CVEPublished 2026-07-09 · Patched in 0.10.0

    Open WebUI · realtime authentication[pip · open-webui]

    Affected
    ≥ 0.9.0, < 0.10.0 (Redis configured)
    Patched
    0.10.0
    Weakness
    CWE-613 · Insufficient Session Expiration

    With Redis-backed revocation configured, JWTs revoked at sign-out or via OIDC back-channel logout were still accepted by Open WebUI's realtime endpoints. A stolen token could keep opening Socket.IO and terminal-websocket sessions after the account had logged out.

    • Realtime connection and room-join paths validated token signature and expiry only, skipping the Redis-backed revocation check the normal HTTP layer enforced.
    • Impact was scoped to realtime surfaces (session rooms, channel events, collaborative notes, and terminal websocket auth); REST APIs correctly rejected revoked tokens.
    • Fixed in 0.10.0 by applying the shared is_token_revoked() check (per-token jti and per-user revoked_at) across realtime authentication.
    • Reported and credited to huslayer826; remediation coordinated with Classic298. CVE record published by the GitHub CNA on 2026-07-09.
  • GHSA-p75f-6fp4-p57w
    CRITICAL · 9.8
    PUBLISHED ADVISORYCVE assigned · pending Registry propagation · Patched in 4.6.59

    PraisonAI · bundled UI (MCP management)[pip · praisonai]

    Affected
    ≤ 4.6.48
    Patched
    4.6.59
    Weakness
    CWE-78 · CWE-306 · Cmd Injection + Missing Auth

    PraisonAI's bundled UI exposed an unauthenticated MCP management endpoint that accepted caller-provided process-launch configuration, letting network-reachable attackers execute chosen local commands as the UI service user.

    • Default UI hosting bound to all interfaces with no authentication on the management API.
    • Reachable through `praisonai ui`, `praisonai ui agents`, `praisonai claw`, and apps built on the hosted-UI integration.
    • Reported and credited to huslayer826; GitHub-reviewed advisory public since 2026-06-18. A CVE is assigned; the identifier will be listed once the Registry record is publicly live.
// IN COORDINATED DISCLOSURE
  • PraisonAI · second disclosure (High)

    Authentication bypass accepted and patched upstream. CVE assigned; the identifier and full details will be listed once the public Registry record and advisory are live.

    CVE ASSIGNED · PROPAGATING
  • Undisclosed open-source AI platform

    High-severity finding accepted by the maintainers; fix in progress upstream. Advisory and CVE will be published after the vendor's coordinated-disclosure window closes.

    UNDER EMBARGO
> SECTION_07 / LEADERSHIP

Leadership

Society for Critical Operations and Preparedness Engineering (SCOPE)

Software Engineer Lead

Aug 2025 – Present

  • Led software engineering team by delegating tasks, coordinating code reviews, and ensuring code quality across contributors
  • Developing drone flight capabilities through software, implementing control logic and integration for stable navigation

> COMPETITION HIGHLIGHTS

  • 1st Place CTF

    Hack the Bay 2026

  • 2nd Place Hackathon

    HackUSF 2026

    NextEra Energy Challenge

  • 4th Place Hackathon

    Hack the Bay 2026

> SECTION_08 / CONTACT

Contact