Skip to main content
Mohiuddin Sohel

Security Researcher · NGFW Configuration Analysis · Vulnerability Analytics

Mohiuddin Sohel

Analyzes next-generation firewall configurations, vulnerability data, and cyber threat intelligence to identify control gaps, prioritize exposure, and support remediation.

Current work prioritizes NGFW configuration analysis, followed by vulnerability analytics and CTI analytics, with AI-assisted workflows supporting investigation and validation.

NGFW Configuration Analysis Vulnerability Analytics CTI Analytics Risk Prioritization Agentic AI Workflows

At a glance

Current focus
NGFW configuration gaps, vulnerability exposure and prioritization, and CTI enrichment and analysis.
Background
PhD in Computing and Information Systems with research focused on threat hunting, security analytics, and cyber threat intelligence.
Location
Melbourne, Florida, USA

About

NGFW, Vulnerability & CTI Analysis

Security researcher specializing in NGFW configuration analysis, vulnerability analytics, and cyber threat intelligence.

Current work examines firewall policy behavior and configuration gaps, connects vulnerability findings to exposure and remediation priorities, and enriches CTI for investigation.

AI-assisted workflows use few-shot prompting, structured reasoning, and LLM-as-a-judge approaches to support analysis and validation.

Selected work

Areas of Focus

Focused work across firewall configuration assessment, vulnerability prioritization, CTI enrichment, and control validation.

NGFW Configuration Analysis

NGFW

Analyzes next-generation firewall configurations to identify policy gaps, unintended exposure, ineffective controls, and remediation opportunities.

  • • Evaluates rule behavior, coverage, and control effectiveness
  • • Identifies configuration gaps and exposure paths
  • • Connects findings to prioritized policy remediation

Vulnerability Analytics & Risk Prioritization

Exposure

Interprets vulnerability, asset, and exposure context to distinguish urgent risk from low-value findings and guide remediation decisions.

  • • Analyzes CVE/CWE context and affected assets
  • • Relates technical severity to exposure and impact
  • • Prioritizes mitigation using actionable risk context

CTI Analytics & Agentic AI Workflows

CTI

Transforms cyber threat intelligence into structured signals for investigation, enrichment, ATT&CK mapping, and AI-assisted reasoning.

  • • Threat context interpretation and enrichment
  • • Agentic workflows using few-shot prompting, chain-of-thought reasoning, and LLM-as-a-judge techniques
  • • Supports analysis, reasoning, and prioritization workflows

Security Control Enforcement Assessment

Controls

Developed approaches to determine what to measure, how to measure it, and which metrics best assess the enforcement of critical security controls.

  • • Maps observables, tools, and metrics to specific safeguards
  • • Uses LLM-assisted extraction from control guidance
  • • Bridges research methods with practical assessment needs

Public-Key Cryptography & Smart Card Systems

PKI

Worked on cryptographic middleware libraries and smart payment card solutions involving PKI integration, authentication workflows, and secure system interoperability.

  • • Public-key cryptography middleware supporting symmetric/asymmetric key generation, hashing, MAC, encryption/decryption, and X.509 certificate operations
  • • Worked with PKCS#7, PKCS#11, JavaCard OS, and certificate-based authentication workflows
  • • System-level development using Java, C++, JNI, and OpenSSL with FIPS/KISA-oriented cryptographic support

Experience

Career summary

Member of Technical Staff

Stealth Security Startup · Current

  • • Analyzing NGFW configurations to identify policy gaps, control weaknesses, and unintended exposure
  • • Evaluating vulnerability findings using asset, exposure, and remediation context
  • • Enriching and interpreting CTI with AI-assisted investigation and validation workflows

Research Assistant · Teaching Assistant

University of North Carolina at Charlotte

Aug 2016 – Apr 2024
  • • Conducted research in threat hunting, security analytics, cyber threat intelligence, and security control assessment
  • • Published work spanning CTI extraction, threat intelligence analysis, and LLM-assisted control validation
  • • Supported teaching across information security, enterprise protection, secure programming, and related computing courses

Team Lead · Software Engineer

Kona Software Lab Ltd., Dhaka, Bangladesh

Mar 2014 – Jun 2016
  • • Built public-key cryptography middleware, certificate authority toolkits, and smart-card authentication support across multiple platforms
  • • Worked across Java, C++, OpenSSL, JNI, and system-level development
  • • Led a small engineering team on NFC-based authentication solutions for Windows

Junior Software Engineer

Nascenia, Dhaka, Bangladesh

Mar 2013 – Feb 2014
  • • Developed sports analytics APIs and backend integrations for web platforms
  • • Worked with REST APIs, backend integrations, JSON, and XML-based systems

Publications

Selected publications

Research spanning security-control validation, distributed threat hunting, CTI extraction, and adversarial analysis.

Prompting LLM to Enforce and Validate CIS Critical Security Control

2024

ACM SACMAT

LLM-assisted extraction of measures, metrics, and implementation guidance for validating critical security controls.

Distributed Hierarchical Event Monitoring for Security Analytics

2024

PhD Dissertation

A distributed monitoring architecture for scalable threat hunting with timely detection and lower resource overhead.

A Poisoning Attack Against Cryptocurrency Mining Pools

2018

ESORICS CBT

Analysis of a poisoning attack capable of disrupting public cryptocurrency mining pools by implicating benign miners.

TTPDrill: Automatic and Accurate Extraction of Threat Actions from Unstructured Text of CTI Sources

2017

ACSAC

Automated extraction of threat actions from unstructured cyber threat intelligence reports.

Education

Academic background

PhD in Computing and Information Systems

University of North Carolina at Charlotte

2024
  • • Research focused on threat hunting, security analytics, and cyber threat intelligence
  • • Worked on distributed security analytics, CTI extraction, and security control assessment
  • • Published research in cybersecurity analytics and AI-assisted security analysis

BSc in Computer Science and Engineering

Bangladesh University of Engineering and Technology (BUET)

2013

Focused on computer science fundamentals, software systems, and applied computing.

Skills

Core competencies

Programming & Development

  • Python
  • Java
  • C++
  • C
  • Prolog
  • SQL
  • Shell Scripting

Security & Analytics

  • NGFW Configuration Gap Analysis
  • Vulnerability Analytics
  • CTI Analytics
  • Risk Prioritization
  • MITRE ATT&CK
  • CVE/CWE Analysis
  • CIS Benchmarks
  • OWASP · NIST CSF · CIS CSC

AI & CTI

  • Prompt Engineering
  • Few-shot Prompting
  • Chain-of-thought Reasoning
  • LLM-as-a-judge Workflows
  • IOC Analysis & CTI Enrichment
  • LangChain · NLP · Scikit-learn

Platforms & Security Tooling

  • Elasticsearch
  • RabbitMQ
  • Docker & Kubernetes
  • OpenSSL
  • Wireshark
  • IDA Pro
  • Git

Contact

Let’s connect.

Open to conversations around NGFW configuration analysis, vulnerability analytics, CTI analytics, and applied cybersecurity research.