Product Security Consultant & Software Engineer

Security you can prove,
not just claim.

I assess complex multi-tenant platforms end to end: reconnaissance, authorized penetration testing, and source-informed threat modelling. You get an evidence-backed verdict on what's ready, what isn't, and exactly what to fix before you host customer data.

PUBLIC / UNTRUSTEDEDGE · PKIINTERNAL ENTERPRISE NETWORKRemote operatorVPN clientPartner servicecontracted partnerexternalunauthenticatedVPN concentratorWireGuard · tunnelPartner ingressmTLS · IP allowlistSecure gatewayTLS terminationWAF · policyIssuing CAonline · rotationRoot CAoffline · air-gappedAPI gatewaytokens · routingIdentityOIDC · authzRegistry / CIApplicationservicesQueue brokerRedis · NATSWorkersconsumersPostgreSQLObject storageMonitoringmetrics · logsenqueueout-of-bandinternal service certsagent-based telemetry from all workloadsinternal request (mTLS)untrusted ingresscert issuanceout-of-band (offline)telemetry (agent-based)

Flagship engagement

Multi-Phase Product Security Assessment

Confidential European B2B software platform

A multi-phase engagement covering external reconnaissance, authorized penetration testing, source-informed threat modelling, and target-state security architecture.

The assessment established what an attacker could reach, tested which controls held up under live adversarial use, identified the risks that genuinely had to block production, and translated those risks into implementation-ready engineering work.

ReconnaissancePenetration testingThreat modellingSecurity architectureIR validation
Delivered
  • Reconnaissance and live penetration-test reports
  • 135-page threat model
  • Risk register and remediation roadmap
  • Target-state security architecture
  • Implementation and verification specifications
“We did not receive a scanner dump or a generic list of findings. Haroun reconstructed the system, tested the controls that mattered, and separated confirmed weaknesses from assumptions. The final deliverable gave us a prioritized remediation plan, a target security architecture, and acceptance criteria precise enough for our engineers to implement and independently verify.”
Co-founder and Platform Owner
Confidential European Software Company
pending client approval

Security software

OpenVPN Management Suite

A certificate-authority and VPN administration system designed around explicit trust boundaries: an offline root CA, an isolated intermediate CA, and a local AF_UNIX control interface mediating every issuance, revocation, and CRL operation behind a role-based administrative interface.

  • Offline root CA
  • Intermediate CA isolation
  • Certificate issuance & bundles
  • Revocation & CRL lifecycle
  • AF_UNIX control interface
  • Role-based administration
View the system design →
OFFLINE ROOTRoot CAoffline signingMANAGEMENT HOSTIntermediate CAisolated serviceControl daemonpolicy checksAdmin UIrole-basedIssuancecerts · CRLsmanual signingAF_UNIX

Consulting

What I offer

Independent security engineering for teams building or operating complex software platforms. Commission one focused review or combine several assessment areas into a broader, multi-phase engagement. Adversarial incident-response exercises are commissioned separately under a dedicated contract with signed scope and rules of engagement.

Product security assessment

Source-informed review of architecture, authorisation, tenant isolation, data flows and security controls across the application and deployment.

Typical deliverables

Executive risk verdict, evidence-backed findings, attack-surface analysis, confirmed-controls register, prioritised risk register and remediation roadmap.

Application security testing

Authorised live testing of web and API surfaces, authentication, authorisation, tenant isolation, uploads, CSRF, injection and business logic.

Typical deliverables

Reproducible findings with supporting evidence, coverage and verification log, test-data and mutation ledger, cleanup runbook and retest results.

Threat modelling and security architecture

Evidence-disciplined analysis of assets, trust boundaries, attack paths, abuse cases, credentials, data lifecycle, deployment and recovery.

Typical deliverables

Threat model, risk register, target-state security architecture, implementation-ready control specifications, acceptance tests, migration and rollback plan, and ownership matrix.

Secure infrastructure review

Review of network exposure, reverse-proxy and TLS boundaries, containers, deployment provenance, PKI, secrets, service privileges, backups, logging and monitoring.

Typical deliverables

Infrastructure findings, exposure and trust-boundary analysis, hardening backlog, backup and recovery requirements, deployment recommendations and closure criteria.

SEPARATE ENGAGEMENT

Adversarial incident-response exercise

Authorised adversarial simulation against an agreed live environment, including controlled service disruption and bounded destructive scenarios, to test detection, containment, backup restoration and recovery.

Typical deliverables

Signed scope and rules of engagement, evidence-backed attack and response timeline, detection and containment assessment, measured recovery performance, revised risk register and live debrief.

Requires a separate contract, signed scope and rules of engagement.

Exact scope, access, evidence handling and final deliverables are agreed in writing before each engagement.

About

Haroun Ahmad

Portrait of Haroun Ahmad, product security consultant and software engineer
  • Product security
  • Security architecture
  • Secure infrastructure
  • Zürich, Switzerland

I approach security as a systems problem. Application code, infrastructure, credentials, deployment, operations, and human processes all shape the real security posture of a product. Looking at any one of them in isolation produces an incomplete picture.

My background is in software engineering, with a focus on product security, threat modelling, and secure architecture. I assess systems end to end, but I also build them: PKI tooling, self-hosted infrastructure, and security-sensitive services designed around explicit trust boundaries and failure modes.

My goal is not simply to identify vulnerabilities. It is to understand why they exist, how they interact, and what engineering changes meaningfully reduce the risk.

Contact

Need an independent security review of a product, platform, or infrastructure?

Straightforward scoping, evidence-disciplined reporting, no sales pressure.

Typically a reply within two business days.

Minimum 20 characters
Complete the verification to enable sending.

Your information will be used to process and respond to your enquiry. See the Privacy Policy for details.