Systems over demos
A detection is one part of a control. I build the inputs, validation, deployment, and failure handling around it, then document them so another engineer can follow the path.
About
I'm Rasheed Farhat, a security engineer in Chico, California. My work sits where detection logic, software behavior, and operational constraints have to function together.
How I work
A detection is one part of a control. I build the inputs, validation, deployment, and failure handling around it, then document them so another engineer can follow the path.
I prefer a bounded, reproducible result to a broad one. Corpus limits and evasion gaps are published next to the numbers they qualify.
The identity deception case study lists its own webhook authentication and source-attribution gaps. Finding those is part of the work, not a footnote.
Every project ships with the trace, the threat model, or the report another person needs to verify or challenge the result.
Record
Detection-as-Code, MCP security review, identity deception, and a published Android malware investigation.
Security+ active October 2025 to October 2028. CySA+ active May 2026 to May 2029.
Incident detection, containment, and escalation with Falcon EDR, Splunk, and Wireshark in simulated red-team and blue-team scenarios.
Timed OSINT, network traffic, log review, cryptography, and incident-handling challenges. Top-percentile national ranking across the Spring and Fall seasons.
Dean's List, and the ISACA Foundation NCL Games Scholarship.
What I'm seeking
Junior roles in detection engineering, security automation, SOC engineering, or cloud and application security, where I can own detection content and the systems around it.