Peter Abiya

Initializing Security Console...

Cybersecurity Engineer • Security Operations • Detection Engineering

Peter Abiya
Engineering Secure Systems.

Detection Engineering Security Operations Cloud Security Security Automation

I design and build practical security solutions that improve visibility, accelerate threat detection, and strengthen organizational resilience. My work spans Security Operations, Detection Engineering, Cloud Security, Malware Analysis, Application Security, and Security Automation, combining hands-on engineering with a deep understanding of how modern attacks unfold.

Peter Abiya
Currently Building Enterprise security monitoring, threat detection, cloud security, security automation, and application security projects.
Security Operations Console
Alerts Today 143 Critical 3 Investigating 2 Playbooks 18
15:02:11 HIGH SSH brute-force detected (MITRE T1110)
15:02:28 MEDIUM Privilege escalation attempt identified
15:02:46 HIGH CloudTrail root account login detected
15:03:14 LOW PowerShell execution outside baseline
15:03:39 HIGH SQL injection attempt blocked
15:04:02 INFO Automated response completed successfully
Wazuh • Suricata • AWS CloudTrail • MITRE ATT&CK
01 About

Hi, I'm Peter Abiya, a cybersecurity engineer passionate about designing and building practical security solutions that help organizations detect threats, strengthen defenses, and improve their overall security posture. My work combines security engineering with a hands-on approach to solving real-world cybersecurity challenges across modern enterprise environments.

My journey into cybersecurity has been shaped by experience in technical operations, web development, technical instruction, and cybersecurity content creation. Those experiences influence how I approach security today—combining technical depth with clear communication, structured problem-solving, and the belief that effective security should be understandable, scalable, and built with the people using it in mind.

I enjoy building security from design through operations, starting with threat modeling, engineering detection capabilities, strengthening cloud and application security, and automating incident response to improve visibility, resilience, and operational efficiency.

Think Like an Attacker

Understand attack paths, trust boundaries, and adversary techniques before designing defensive controls.

Engineer for Visibility

Build meaningful telemetry, detection logic, and monitoring capabilities that enable rapid threat identification and investigation.

Design for Resilience

Create scalable, maintainable, and automated security solutions that strengthen operational resilience without sacrificing usability.

8+

Security Projects

15+

Technical Articles

20+

Detection Rules

40+

Technologies

02Technical Expertise

Security Operations & Monitoring

Designing and operating security monitoring capabilities using SIEM, IDS, endpoint telemetry, and cloud logs to improve visibility, accelerate detection, and support effective incident response.

Detection Engineering & Incident Response

Developing detection logic, correlation rules, IOC-driven analytics, and MITRE ATT&CK-aligned alerting while investigating security events through structured triage and forensic analysis.

Application Security & Threat Modeling

Assessing applications from design through deployment using STRIDE threat modeling, architecture reviews, OWASP methodologies, and risk-driven security assessments.

Cloud & Infrastructure Security

Securing cloud and hybrid environments through identity management, infrastructure hardening, centralized logging, container security, and least-privilege access control.

Security Automation & DevSecOps

Building automation that integrates security into engineering workflows, enriches security findings, streamlines analyst operations, and reduces response time through repeatable playbooks.

AI Security & Security Research

Exploring adversarial machine learning, malware behavior, firmware security, and emerging attack techniques to strengthen defensive strategies and improve cyber resilience.

02 Interactive Security Console

Explore my portfolio using a few familiar terminal commands.

PeterOS Security Console
Welcome to PeterOS Security Console Type help to view available commands.
peter@security:~$
03Projects

Featured Security Engineering Projects

A selection of hands-on cybersecurity engineering projects spanning security operations, detection engineering, malware analysis, cloud security, application security, and security automation. Each project reflects real-world engineering, research, and defensive security practices.

OpsShield: Secure Multi-Tenant Application Security Platform
COMPLETED
Contributed as a Cybersecurity Engineer on a cross-functional capstone project alongside Application, DevOps, and Cloud teams to deploy and secure a live multi-tenant SaaS platform. Led Wazuh SIEM detection engineering, manual penetration testing, GitHub Actions security validation, software supply chain security, vulnerability management, and security documentation. Designed and validated detection rules mapped to the MITRE ATT&CK framework while assessing authentication, authorization, webhook security, session management, and application resilience through structured penetration testing.
Wazuh SIEM Detection Engineering MITRE ATT&CK Penetration Testing Application Security GitHub Actions DevSecOps OWASP Docker Software Supply Chain Security Vulnerability Management
SecOpsAI: AI-Powered Behavioral Threat Detection Platform
COMPLETED
Served as the DevOps Engineer while contributing to the Security Architecture team for an enterprise-scale AI-powered behavioral threat detection platform. Designed and maintained the Docker-based infrastructure, supported CI/CD integration, developed threat modeling documentation, and collaborated across four engineering teams to deliver a Security-by-Design platform integrating machine learning, detection engineering, monitoring, and automated response.
Docker Compose Kafka FastAPI PostgreSQL MLflow Prometheus Grafana GitHub Actions STRIDE MITRE ATT&CK DevSecOps
FireOps: Enterprise Security Monitoring Platform
COMPLETED
Designed and deployed a centralized enterprise security monitoring platform providing visibility across endpoints, network traffic, and AWS infrastructure. Integrated SIEM, IDS, cloud monitoring, custom detection rules, and automated incident response workflows.
Wazuh Suricata Docker AWS CloudTrail MITRE ATT&CK Incident Response
ShieldFlow: AppSec Pipeline & SOAR Automation
COMPLETED
Built an automated application security pipeline integrating static analysis, dependency scanning, DAST, secret detection, CVE enrichment, and automated SOAR playbooks to reduce Mean Time to Triage from hours to minutes.
Python Semgrep Trivy OWASP ZAP GitHub Actions SOAR
Project Ghostwire: Adversary Simulation & Network Hardening
COMPLETED
Simulated covert data exfiltration techniques, conducted packet-level forensic analysis, and designed kernel-level firewall controls that successfully blocked all simulated attack scenarios while preserving legitimate traffic.
tcpdump iptables Linux Packet Analysis Threat Detection Network Security
WannaCry Malware Behaviour Analysis
COMPLETED
Executed and analysed WannaCry ransomware within an isolated laboratory environment to investigate process execution, registry modifications, file encryption workflow, attacker behaviour, and Indicators of Compromise.
Procmon Regshot Wireshark Malware Analysis Digital Forensics
IoT Firmware Reverse Engineering & Vulnerability Assessment
COMPLETED
Reverse engineered TP-Link firmware to identify hardcoded credentials, insecure configurations, outdated software, and missing exploit mitigations while documenting realistic attack paths and remediation guidance.
Binwalk Firmwalker John the Ripper checksec Firmware Analysis
04Toolkit
Security tools
Wazuh SIEMSuricata IDSWireshark Burp SuiteOWASP ZAPNmap HydraJohn the RipperTrivy SemgrepGitleaksProcmon RegshotBinwalkFirmwalkerChecksec
Cloud & infrastructure
AWS IAMAWS CloudTrailDockerTailscale VPN
Scripting & systems
PythonGitHub ActionsLinux (Ubuntu, Kali)Windows
Governance & compliance
ISO/IEC 27001ISO 22301ISO 31000ISMSNDPR Awareness
05Certifications
Foundations of CybersecurityCoursera
ISO/IEC 27001:2022 ISMS FoundationStandards & Best Practice
ISO 31000:2018 Risk ManagementStandards & Best Practice
ISO/IEC 27032:2023 Cybersecurity GuidelinesStandards & Best Practice
ISO 22301:2019 Business Continuity (BCMS)Standards & Best Practice
ISO 9001:2015 Quality ManagementStandards & Best Practice
Certificate in CybersecurityHagital Consulting
English for IT 1 & 2Cisco Networking Academy
06Contact

Let's talk security.

I'm always open to discussing cybersecurity, security engineering, research collaborations, and exciting opportunities.