OSCP & OSWE certified security engineer — application security, penetration testing, and LLM security. M.S. in Information Security, Carnegie Mellon University.
I work across offensive security, detection/defense, and DevSecOps - from breaking web/mobile/network targets to building the pipelines and detections that catch the next attacker.
ninajafli.github.io · LinkedIn
| Project | What it is |
|---|---|
| llm-redteam-harness | Prompt-injection red-team harness for local LLMs, scored with Wilson CIs and mapped to OWASP LLM Top 10 + MITRE ATLAS |
| threatflow | Real-time + batch threat-analytics platform on GCP (Kafka, Spark Streaming, Dataproc, Terraform, k8s) |
| DotCMS-CVE-2022-45782 | Full PoC for predictable dotCMS password-reset tokens, including a token cracker |
| browser-sec-labs | Dockerized, genuinely cross-origin labs for CORS and CSP-bypass attacks |
Burp Suite · Semgrep · Snyk · Metasploit · Frida · Splunk · Wazuh · Cortex XDR · Docker · Kubernetes · Terraform · GitHub Actions
Languages: Python · Go · C · Bash · JavaScript · SQL · PowerShell
OSCP · OSWE · eCPPTv2 · CRTO · Certified DevSecOps Professional (CDP)
📫 Reach me at nnajafli@alumni.cmu.edu
