> Hello, I'm

Fahad Al-Summan

Cybersecurity Specialist

I build secure systems and automate cybersecurity workflows. Currently creating innovative security solutions at DYNEX Arabia, with expertise in penetration testing, governance frameworks, and compliance automation for Saudi Arabia's evolving cybersecurity landscape.

Connect:
Fahad Al-Summan

> Experience

Building secure systems and helping organizations navigate the complex landscape of cybersecurity compliance

Full-time

Cyber Security Specialist

DYNEX Arabia
August 2025 - Present
Al Khobar, Saudi Arabia
  • Initiated and led the creation of "Security Edge," an innovative cybersecurity and compliance management platform that automated all procedures related to risk assessment, GRC, incident response, and employee awareness
  • Transformed manual cybersecurity tasks into automated digital workflows, improving accuracy, audit readiness, and compliance tracking across NCA ECC, ARAMCO CCC, and PDPL frameworks
  • Mitigated two critical risks by executing remediation actions and verifying control effectiveness through ServiceNow workflows
  • Enforced MFA and deployed key defense mechanisms (WAF, IDS/IPS, SPF)

Technologies:

ServiceNowPythonNext.jsPostgreSQLDockerWAFIDS/IPS

Frameworks & Standards:

NCA ECCARAMCO CCCPDPLISO 27001
Freelance

Cyber Security Consultant

Freelance
March 2025 - March 2025
Saudi Arabia
  • Performed offensive security/penetration testing engagements to emulate real-world attacker techniques and validate defensive controls
  • Executed end-to-end testing: reconnaissance, vulnerability discovery, exploitation, post-exploitation validation, and cleanup
  • Discovered and validated critical vulnerabilities, produced reproducible PoCs, and prioritized fixes based on business impact
  • Produced clear, actionable technical and executive reports with remediation steps and risk ratings aligned to NCA and PDPL requirements

Technologies:

Burp SuiteMetasploitNmapOWASP ZAPKali Linux

Frameworks & Standards:

NCAPDPLOWASP Top 10
Full-time

Cyber Security Analyst

Etressy Network Solutions LLC
February 2024 - October 2024
Chicago, IL
  • Monitored and triaged SIEM and IDS/IPS alerts, reducing incident response time by 30%
  • Executed vulnerability assessments and penetration testing to uncover and mitigate threats
  • Investigated 3+ high-severity security incidents in coordination with SOC2 and DevOps teams
  • Resolved 15+ security tickets monthly, ensuring SLA compliance

Technologies:

SplunkWiresharkMetasploitBurp SuiteNessus

Frameworks & Standards:

SOC2NIST
Full-time

Info Security Analyst Associate

Etressy Network Solutions LLC
August 2023 - February 2024
Chicago, IL
  • Performed vulnerability scans using Nessus and maintained risk registers
  • Integrated job portal APIs to automate job listing and candidate workflows
  • Documented incident tickets, timelines, and root cause analyses
  • Automated security scans cut manual effort by 40%

Technologies:

SplunkQRadarNmapNessusREST API

Frameworks & Standards:

NISTCIS Controls
Full-time

PHP Developer

Women Health Associate in Asser
December 2020 - April 2022
Remote
  • Developed a secure, user-friendly CMS platform with file upload features
  • Integrated a job portal API to automate job listings and candidate management
  • Conducted post-launch security testing and patched discovered vulnerabilities

Technologies:

PHPLaravelREST APIMySQLBootstrap

Frameworks & Standards:

MVCRESTful
Internship

Systems Analyst Intern

King Khalid University
October 2018 - March 2019
Abha, Saudi Arabia
  • Gathered and documented user requirements through interviews and surveys
  • Contributed to improving the Student Registration portal speed by 35%

Technologies:

Systems AnalysisDocumentationSQL

Frameworks & Standards:

SDLC

> Certifications

Industry-recognized credentials demonstrating expertise in offensive security, defensive strategies, and governance frameworks

offensive
eWPTX

eWPTX

eLearnSecurity

Web Application Penetration Tester eXtreme

August 2025
offensive
eJPT

eJPT

eLearnSecurity

Junior Penetration Tester

January 2025
defensive
ISC2 CC

ISC2 CC

ISC2

Certified in Cybersecurity

December 2024

> Featured Projects

Building innovative security solutions that automate compliance and strengthen cybersecurity posture

● Liveplatform

Security Edge

Comprehensive GRC & Risk Management Platform

In-house cybersecurity platform automating risk assessment, GRC workflows, incident response, and employee awareness training. Built to streamline compliance with NCA ECC and PDPL requirements for Saudi organizations.

Key Features

Risk Assessment Engine
NCA ECC Compliance Tracker
Incident Response Workflow
Employee Awareness Training
PDPL Compliance Dashboard

Technology Stack

Next.jsTypeScriptPrismaPostgreSQLTailwind CSS
Security Edge
Platform screenshot coming soon
70%
Time Saved
50+
Workflows

Want to see more of my work?

> Get In Touch

I'm always open to discussing cybersecurity projects, consulting opportunities, or just having a chat about security. Feel free to reach out!

Secure Communication

Need to send sensitive information?