/ my-journey

From Cracking School Wi-Fi
to Securing Enterprise Networks

The story of how a curious kid in Dubai ended up as an OSCP-certified presales consultant helping CISOs across the GCC defend what matters most.

Basim Ibrahim, Cybersecurity Consultant, Dubai
2016
Degree started
6th
University rank
OSCP
Offensive Security cert
5+
Years in enterprise security
Ch. 01

Dubai · 2007 – 2016

The School That Taught Me More Than It Knew

I grew up in Dubai, UAE, at New Indian Model School, Dubai — completing my High School Diploma in Computer and Information Sciences. Station Master at the school radio station, House Captain of Emerald House, active in the Science Expo and IT Marathon. The school was perfectly ordinary in most respects. Its Wi-Fi password was not.

I was maybe fifteen when I first looked at the school's wireless network and wondered: how does it actually decide who gets in? Not in a malicious way. I wasn't trying to stream videos or skip homework. I was genuinely curious about the mechanism. That curiosity led me to read about WPA2, about packet capture, about how authentication works at the protocol level. Eventually, I found a way in.

I told a friend. He looked impressed for about three seconds, then asked if I could get him faster speeds. That wasn't really the point.

The point was that I had learned more in that one evening than in weeks of computer science class. I had gone from using technology to understanding it. Once you make that shift, you can't go back. Cybersecurity wasn't a career option I had seen on a poster. It was just the thing I kept being drawn to, every time.

Ch. 02

Kerala, India · 2016 – 2019

B.Sc. Cyber Forensic at Mahatma Gandhi University

6th Rank, University Batch 2016–19
B.Sc. Cyber Forensic · Mahatma Gandhi University, Kerala

When it came time to choose a degree, the answer was obvious. Mahatma Gandhi University in Kerala offered one of the few dedicated B.Sc. Cyber Forensic programmes available in India at the time, and I enrolled in the 2016 batch.

The programme was rigorous in ways I hadn't anticipated. Digital forensics taught me how to work backwards from a breach: how to read a system's memory, reconstruct deleted files, trace an attacker's steps through log evidence. Network forensics, malware analysis, ethical hacking, cryptography: each module added a new lens through which I could look at the same problem.

I finished the three-year programme ranked 6th in my university batch. That number mattered less to me than what I had built during that time: a mental model for how attackers think, how defenders fail, and why most security problems are fundamentally people problems wearing a technology costume.

Completed during my final year of the degree — covering ethical hacking methodology, penetration testing phases, network scanning, exploitation, and post-exploitation techniques. A structured framework that complemented the practical instincts I had already developed.

University Projects

During my degree I completed several hands-on projects covering network forensics, malware analysis, and vulnerability assessment. The full project list (with descriptions) is on my profile.

View projects →
Ch. 03

Chennai, India · Apr – Aug 2019

First Real Ground: Penetration Testing Internship

Fresh out of the degree, I took my first professional role — a penetration testing internship at TwinTechSolutions in the Greater Chennai Area. Real client environments, end-to-end penetration testing and vulnerability analysis, digital forensic investigations to identify security breaches, and system and server security configuration.

The gap between classroom exercises and production systems is enormous. This is where I learned that. Finding a vulnerability in a lab is straightforward. Writing a clear, actionable report that a client's IT team can actually use — that takes a different kind of precision.

A gruelling 24-hour practical assessment — exploit real machines, not multiple-choice questions. Passing it early in my career confirmed something I had started to suspect: I could do this work at a level that held up under serious scrutiny.

Ch. 04

India · 2019 – 2020

PG Diploma in Artificial Intelligence & Machine Learning — NIELIT

Grade: S — 90% · NIELIT Calicut
National Institute of Electronics and Information Technology · Ministry of Electronics & IT, Govt. of India

I pursued a Post Graduate Diploma in Artificial Intelligence and Machine Learning from NIELIT Calicut — a Government of India institution under the Ministry of Electronics and IT. Graduated with an S grade (90%).

The programme covered Machine Learning, Deep Learning, Reinforcement Learning, and Natural Language Processing for text analysis, with applied work in R and Python. I developed AI systems covering smart surveillance, gene prediction, and census data analysis. Understanding how these models are trained and how they fail has become directly relevant: AI-generated phishing, adversarial ML, and the detection engines inside the security tools I evaluate daily in presales.

CompTIA Certifications — Following the Diploma
CompTIA CySA+ · Cybersecurity Analyst

Threat and vulnerability management, security operations, incident response, and compliance — the defender's complement to the offensive skills I had built.

CompTIA PenTest+ · Penetration Testing

Planning and scoping, information gathering, attacking and exploiting, and reporting — a structured methodology that formalised techniques I had been applying in practice.

Ch. 05

India · Feb 2020 – Jan 2022

Building Enterprise Security Experience — DXC Technology & qSEAp Infotech

Two back-to-back roles across Bangalore and Mumbai gave me a breadth of enterprise security exposure that no single position could have provided.

DXC Technology Feb 2020 – Jan 2021
Network Security Engineer · Bangalore
  • Deep Server Security & XDR implementation
  • Data Leakage Prevention (DLP) & Secure Web/Email Gateways
  • EDR, AV, and vulnerability detection deployment
qSEAp Infotech Jan 2021 – Jan 2022
Information Security Consultant · Mumbai
  • VAPT & application security, banking domain focus
  • Source code review & risk assessments
  • Firewall administration, IDS/IPS, network security monitoring

DXC gave me the enterprise defender's perspective — deploying the tools I had previously been attacking, at global-scale infrastructure. qSEAp deepened the offensive and auditing side, particularly in the banking domain where security standards are non-negotiable. Together, these two years shaped the vendor-neutral, implementation-grounded view of security that defines how I operate today.

Ch. 06

Dubai, UAE · Jan 2022 – Present

iConnect IT — From Consultant to Cyber Security Lead

Back in Dubai, I joined iConnect IT Business Solutions and have been here since, moving through three progressively senior roles over four and a half years.

Cyber Security Lead (Senior Presales) May 2023 – Present

Presales consulting for PAM, EDR/XDR, SIEM, email security, DLP, and cloud security. POCs, RFP/RFI responses, technical workshops, and client-facing presentations for CISOs and IT directors across UAE banking, government, healthcare, and energy sectors.

Advisor — Cyber Security Apr 2022 – Apr 2023

Led multiple VAPT projects. Developed security strategies and roadmaps. Built cyber security teams. Conducted risk assessments and provided strategic guidance to senior management on security investments and compliance frameworks.

Cyber Security Consultant Jan 2022 – Apr 2022

Security assessments, rights management, cloud environment security, and implementation of security solutions across client environments.

Presales puts you in front of CISOs, IT directors, and procurement committees — people making expensive, consequential decisions about which security technologies to invest in. My job is to help them get that right. The background in penetration testing, implementation, and enterprise defence is what makes this possible. When I recommend a detection tool, I've seen what it misses. When I scope a PAM deployment, I've done the rollout. The advice is grounded.

That's the story so far.

If you're a CISO or IT leader evaluating security solutions for a UAE or GCC enterprise, let's talk.

Weekly Cyber Insights

One email per week. UAE/GCC focused. No spam, unsubscribe any time.