moghit-eou Abdelmoughit EL Ouaad

Open source Contributor · Backend & infrastructure engineer · DevSecOps and CI/CD security

Engineering student at Hassan II University (FSTM Mohammedia), Casablanca, and open source contributor to EBRAINS, where I secure the CI/CD supply chain of the Medical Informatics Platform. I build backend systems in Go and Java, and security pipelines that run the same way on a laptop and in CI. My data science and ML background means I also understand the pipelines that ship models.

~/experience

Open Source DevSecOps Contributor

Mar 2026 – Present

EBRAINS / Medical Informatics Platform ↗

Google Summer of Code 2026 ↗ under INCF, May – Oct 2026. Selected as 1 of 1,141 contributors from 15,245 applicants (7.5%).

EBRAINS is Europe's digital research infrastructure for neuroscience. Its Medical Informatics Platform lets hospitals analyze harmonized clinical data without moving patient records off local servers. I started contributing before GSoC, was selected to secure the platform's CI/CD supply chain against the OWASP DevSecOps Maturity Model, ahead of the EU Cyber Resilience Act and NIS2, and keep contributing beyond the program.

  • Assessed the platform against OWASP DSOMM and turned the gaps into an implementation roadmap.
  • Shipped SAST (OpenGrep), SBOM-based SCA (Trivy and OSV-Scanner over CycloneDX SBOMs) and container scanning (Hadolint, Trivy, OSV-Scanner) into the Spring Boot backend, the Angular UI and the data catalog, where one build matrix covers Maven, npm and Python services.
  • Added Gitleaks secret scanning in pre-commit hooks and CI.
  • Designed one fail-closed security gate: every scanner is normalized to SARIF, builds are blocked at CVSS 8.0 or on ERROR-level SAST rules, a crashed scanner never counts as a pass, and reports are GPG-encrypted before upload because findings in a public repository are sensitive.
  • Secured the pipelines themselves: GitHub Actions pinned to commit SHAs, Renovate and Dependabot with a 7-day cooldown, and containers running as non-root.
  • Packaged the work as a reusable blueprint and the EBRAINS DevSecOps Handbook, and upstreamed the gate design to the OWASP DevSecOps Guideline.
  • Now hardening the Kubernetes GitOps repository (Argo CD, HAProxy ingress) so Checkov IaC scanning can become a blocking gate.

13 merged PRs platform-backend #15 #19 #23 #25 · platform-ui #20 #23 #27 #31 #34 #38 · datacatalog #18 · mip-infra #2 #6

See a pipeline in production ↗ · Read the handbook ↗

OWASP DSOMM SAST SCA SBOM SARIF Gitleaks Checkov Kubernetes Argo CD GitHub Actions Python

AI Automation Intern

Apr – Jun 2025

NUITEE · Casablanca

  • Trained and deployed an NLP email classifier, served as a Flask REST API on AWS.
  • Automated email handling and recruitment workflows with n8n, AI agents and a Pinecone RAG index.
  • Built a TF-IDF / Word2Vec resume scoring pipeline.

~/projects

Reusable DevSecOps CI Pipelines

Built during GSoC 2026 · running in the CI of 3 Medical Informatics Platform repositories

Three security pipelines, SAST, SCA and container scanning, that run the same way on a laptop and in GitHub Actions, so a finding reproduced locally is the finding CI reports.

  • Pipeline logic lives in Python scripts, not vendor YAML: make runs them in Docker locally, GitHub Actions runs them natively.
  • SCA scans a CycloneDX SBOM rather than the dependency cache, so adding a language means teaching the SBOM step, not touching the scanners. Sample targets in Go, Maven, npm, Python and Rust.
  • One shared gate: CVSS thresholds for vulnerabilities, ERROR-level rules for SAST, and an ERROR status when a scanner crashes.
  • Adopted by copying one folder and a workflow, then editing an env: block.
Python Bash Docker Make GitHub Actions OpenGrep Trivy OSV-Scanner Hadolint SARIF CycloneDX

Node-Agent

A remote code execution agent built from scratch in Go, designed as the worker node of a distributed code execution engine.

  • Raw TCP server with a goroutine per connection and a JSON job protocol.
  • Separate network, control and execution layers; each job runs in an ephemeral Alpine container through the Docker SDK, which returns its stdout and stderr.
  • CI builds every pull request, enforces gofumpt and uploads gosec results to the GitHub Security tab.
  • Reviewed and merged pull requests from 3 outside contributors.
Go Linux TCP Docker SDK Concurrency

SkyBook: Flight Booking Platform

Flight search and booking web app with an Angular frontend and a Spring Boot REST API, backed by a local PostgreSQL cache layer for the AviationStack API and fully containerized with Docker.

  • Caching engine serves matching routes from PostgreSQL before falling back to the external AviationStack API.
  • End to end booking flow with dynamic pricing, seat and baggage options, and booking history.
  • Admin dashboard with revenue stats, booking management, and role based access control.
Angular Spring Boot Java PostgreSQL Docker

Email Classification & HR Automation

NLP pipeline for email classification and automated resume screening deployed on AWS, with workflow orchestration in n8n and vector similarity search in Pinecone.

Python AWS NLP n8n Pinecone Flask

Audio Classification, Spectrograms & Neural Nets

End to end supervised pipeline turning raw audio into Mel spectrograms, fed into a custom neural network, packaged with Docker and served on Hugging Face Spaces.

Python TensorFlow Docker Librosa

Google Drive Clone

File management system backed by the Google Drive API, with OAuth 2.0 auth, folder navigation, upload and download, and file type filtering.

Python Flask Google Drive API OAuth 2.0

Resume Screening

Scrapes job descriptions and ranks candidate resumes using TF-IDF, Word2Vec, and cosine similarity.

Python Selenium NLP

~/open-source-contributions

OWASP DevSecOps Guideline ↗

  • Contributed Section 2-3-5 (Security Gates): SARIF normalization and unified exit-code logic, so CVSS-based and severity-based tools gate consistently. Merged September 2026. PR #107 ↗

Unikraft / KraftKit ↗

Delivered issue #673 (global toolchain configuration) end to end across three PRs, reworking the approach after maintainer feedback. All three merged into the stable branch.

  • Added a global toolchain config map, injected into every make invocation of the Unikraft build. PR #2672 ↗
  • Extended the config manager so kraft system set supports map fields, such as toolchain.CC=clang, with unit tests. PR #2685 ↗
  • Added kraft system list, which walks the config struct to print every option and its current value. PR #2719 ↗

jwilder / dockerize ↗

  • My container scan flagged 4 high-severity CVEs in the dockerize binary shipped in the platform's images. I traced them to an outdated Go toolchain and reported them upstream; the maintainer shipped the fix in v0.15.0. Issue #339 ↗

~/education

MSc in Engineering, Data Science & Software Engineering

Sep 2025 – Jun 2028

Hassan II University · FSTM Mohammedia

Advanced engineering cycle focused on data science, computer science, and software engineering.

Algorithms & DS Operating Systems Networks Distributed Systems OOP (C++, Java)

BSc, Data Science & Business Intelligence

2021 – 2025

Hassan II University

Mathematics, statistics, computer science, and business intelligence, with practical work in data analysis, machine learning, and BI tools.

Calculus & Linear Algebra Probability & Statistics Power BI Machine Learning Big Data

~/certificates

Google Cloud Certified, Associate Cloud Engineer Credly ↗
Oracle Cloud Foundations Associate Oracle ↗
Machine Learning Specialization Stanford / DeepLearning.AI ↗
Data Science Professional Certificate IBM ↗

~/interests

Cloud Computing

Building on the certifications above with hands on infrastructure work.

Competitive Programming

69 rated contests in C++, sharpening problem solving and algorithmic thinking. Codeforces ↗ · AtCoder ↗