Cybersecurity leadership · GRC · Assurance · SOC/CSIRT · Resilience · Open Source
| STATUS | PRIMARY MODE | BASE | REACH |
|---|---|---|---|
OPEN TO ENGAGEMENTS |
BUILD · LEAD · ASSURE |
ALGERIA |
GLOBAL |
I work where cybersecurity, governance, assurance, operations and leadership meet — helping organizations turn standards, risk, technology and executive intent into security programs that are measurable, resilient, auditable and usable in the real world.
INPUT Risk · Complexity · Regulation · Operational reality
METHOD Govern · Defend · Assure · Enable
OUTPUT Security programs that survive audits and incidents
STANDARD Evidence over theatre
Most organizations do not have a security problem.
They have a governance problem that manifests as security.
|
Open Algerian Data Protection Governance & Compliance Toolkit. A self-hostable privacy governance platform built around Algeria's Law 18-07 and Law 25-11 — combining legal requirements, processing activities, DPO operations, rights requests, risks, evidence, privacy-by-design, ANPDP readiness, reporting and executive visibility in one operational workspace.
Operating model: self-hosted · privacy-first · evidence-driven · multilingual · secure-by-default · open source |
|
|
Built for me. Shared with the community. A dark-first, local-first personal operations command center for projects, tasks, focus, follow-ups, deadlines, milestones, notes and daily execution. It began as a private tool built around my own workflow and is now available as an open-source project.
Operating model: single-user · local data ownership · secure-by-default · no telemetry · no cloud dependency |
|
|
Inspect release artifacts before they become security incidents. A local-first defensive CLI for scanning release packages before publication or deployment.
Trust model: local · offline · read-only · no telemetry · no artifact execution |
Share incident data without exposing the incident. A local-first privacy engineering tool for sanitizing, pseudonymizing, auditing and packaging cybersecurity evidence before it is shared.
Security model: local-first · policy-driven · source-preserving · review-oriented |
|
Strategy · GRC · vCISO Security governance, enterprise risk, ISMS/BCMS/PIMS, operating models, executive reporting, compliance and maturity roadmaps. |
SOC · CSIRT · Resilience Security operations, incident response, crisis management, threat intelligence, SIEM/SOAR, DFIR, VAPT and red/purple teaming. |
Audit · Controls · Certification Accredited audits, security assurance, certification readiness, control assessments, framework mapping and evidence-led improvement. |
Training · Exercises · Mentoring Certification training, executive awareness, practitioner workshops, tabletop exercises, mentoring and capacity building. |
Explore professional services and engagements →
|
Professional learning, certification and applied cybersecurity practice.
|
Free community editions built from official objectives, authoritative references and practical context.
|
A podcast about the decisions behind security programs — governance, ownership, risk, controls, operations and resilience.
|
| Project | Mission | Access |
|---|---|---|
| 🧭 DZ Privacy Compass | Open Algerian data protection governance and compliance toolkit for Law 18-07, Law 25-11, DPO operations, evidence, assurance and privacy workflows. | Repository → · v1.0.0 → |
| ⚡ TAE Command Center | Local-first personal operations system for projects, tasks, focus, follow-ups and deadlines. | Repository → |
| 🕶️ EvidenceVeil | Privacy engineering for controlled cybersecurity evidence sharing. | Repository → |
| 🛡️ Release Sentry | Defensive release-artifact inspection before publication or deployment. | Repository → |
| 🧠 Cyber Master Series Guides | Free professional certification guides and governed community releases. | Repository → |
| 🎤 Conferences | Selected presentation, workshop and technical-session materials. | Repository → |
| 🔬 CVE-2018-10583 | Vulnerability research and proof-of-concept work. | Repository → |
| 🔐 Strong Password Generator | Lightweight Python password-generation utility. | Repository → |
Explore the complete repository portfolio →
| 15+ | 300+ | 4 | 50+ | 3 | Top 10 |
|---|---|---|---|---|---|
| Years in IT & Cyber | Certifications & Credentials | Continents | Training Programs | Chapters Founded | International CTF Finishes |
|
|
Governance, assurance and standards
ISO/IEC 27001 · ISO/IEC 27002 · ISO/IEC 27005 · ISO 22301 ·
ISO/IEC 27701 · ISO/IEC 42001 · NIST CSF · NIST SP 800-53 ·
CIS Controls · PCI DSS · SWIFT CSP · SOC 2 · RNSI
Security operations, response and resilience
SOC · CSIRT · Incident Response · DFIR · Threat Intelligence ·
SIEM/SOAR · VAPT · Red Team · Purple Team · Crisis Management
Cloud, technology and emerging security
ISO/IEC 27017 · ISO/IEC 27018 · CSA CCM / STAR · Cloud Assurance ·
IEC 62443 · OWASP · Secure Architecture · AI Governance
building:
- DZ Privacy Compass — continued hardening and community-driven iteration
- TAE Command Center — continued iteration from real-world use
- Open-source security and privacy engineering tools
- Cyber Master Series
- Professional cybersecurity books and practitioner toolkits
recent_releases:
- DZ Privacy Compass v1.0.0
- TAE Command Center v1.0.0
- EvidenceVeil v1.0.0
- Release Sentry
publishing:
- Free certification study guides
- Applied cybersecurity resources
- Research and conference material
broadcasting:
- The InfoSec Control Room
open_to:
- Executive cybersecurity advisory
- Accredited audit and assurance engagements
- Training, speaking and strategic collaborationSerious conversations are welcome across cybersecurity governance, GRC, assurance, SOC/CSIRT, resilience, cloud security, professional training, research and open-source security.
LEARN IT · CERTIFY IT · APPLY IT · MASTER IT
© 2000–2026 Taher Amine ELHOUARI · Built with purpose for the global cybersecurity community.
