Skip to content
View mekado11's full-sized avatar

Highlights

  • Pro

Block or report mekado11

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mekado11/README.md

Michael Effiong

Security Architecture · Product Security · AI Security Governance · Detection & Response

I build security programs for regulated environments — medical devices, healthcare data, federal and defense authorization, financial-reporting integrity, and converged IT/OT. Ten-plus years taking organizations from "what are our risks?" through architecture, prevention, detection, response, and governance.

This profile is a body of method. Every repository here is a synthetic reference implementation — no employer data, no proprietary architecture, no real findings. What it demonstrates is how the work is actually done.


What this portfolio proves

I can assess it. Threat modeling, security architecture review, product security assessment, medical-device cybersecurity, security risk assessment, configuration baselining, multi-framework compliance.

I can secure it. Identity and privileged access architecture, cloud security, application and pipeline security, supply-chain integrity, OT segmentation, hardening.

I can detect attacks against it. Detection engineering across identity, endpoint, cloud control plane, and network telemetry — with a deliberate telemetry strategy behind it rather than a rule pile.

I can respond when it is compromised. Incident triage, investigation, containment with business cost weighed, eradication, recovery, evidence handling, executive and regulatory communication.

I can govern, fund, sequence, and report on it. Program charters, maturity roadmaps, control libraries crosswalked across regimes, risk acceptance, metrics, and board-level reporting.

Each repository carries a DECISIONS.md. That file — the trade-offs, the constraints, the things deliberately not done — is the point. Implementation shows what can be built. Decision records show what should be.


Repositories

Program and governance

Repository What it contains
security-program-blueprint Full security program design: charter, decision rights, RACI, capability maturity model, 12-quarter roadmap with sequencing rationale, staffing model, metrics catalog, board reporting pack, risk-acceptance records
compliance-control-crosswalk One control library mapped across NIST SP 800-53 Rev 5, CSF 2.0, SOC 2, HIPAA, FedRAMP, CMMC, ISO 27001:2022, ISA/IEC 62443, NERC CIP, SOX ITGC, and GDPR — with evidence reuse and an automated gap-report generator
ai-security-governance Enterprise AI security program: intake and risk-tiering, review pathways, 40+ controls mapped to OWASP GenAI LLM Top 10 2026, NIST AI RMF 1.0, and MITRE ATLAS; threat patterns for RAG, tool-calling, and agents; adversarial test plan; human-approval gate design

Assessment

Repository What it contains
threat-model-library Six fully worked threat models — SaMD device, RAG/agent application, converged IT/OT network, cloud identity plane, CI/CD supply chain, patient-facing API — plus methodology for scaling threat modeling across many teams without becoming the bottleneck
samd-cyber-submission-package Complete premarket cybersecurity documentation package for a fictional Class II connected device, structured to FD&C Act section 524B: threat model, ISO 14971-traced security risk assessment, SBOM, vulnerability analysis, post-market monitoring, coordinated disclosure, traceability matrix
vulnerability-management-program The lifecycle as a program rather than a scanner: risk-based prioritization beyond CVSS, coverage gaps, remediation coordination across teams you don't manage, exception frameworks, OT patching constraints, executive metrics

Prevention

Repository What it contains
appsec-sdlc-controls Security gates as code — SAST, DAST, SCA, container, secret, and IaC scanning — plus the policy layer that makes them stick: thresholds, break-build rules, SLAs, exceptions, and secure repository governance as auditable configuration
sbom-supply-chain-pipeline End-to-end SBOM generation, storage, diffing, and VEX triage on CycloneDX 1.7 and SPDX 3.0.1, with a reachability-and-exploitability prioritization engine and policy-as-code gates
identity-security-architecture Cloud identity plane design: IAM role and permission-boundary patterns, privilege-escalation path analysis, conditional-access matrices, workload and service-account governance, PAM and just-in-time elevation, access certification that isn't rubber-stamping
stig-scap-hardening Configuration baselines as declarative code with SCAP validation, automated evidence generation, compensating-control process, and 800-53 control inheritance
it-ot-security-reference Purdue-model segmentation, ISA/IEC 62443 zones and conduits with security-level targets, IT-to-OT attack paths, NERC CIP evidence mapping, and why standard IT controls fail in OT

Detection and response

Repository What it contains
detection-library 30+ vendor-neutral Sigma detections across identity, cloud control plane, endpoint, and network — each with telemetry prerequisites, ATT&CK mapping, false-positive profile, and analyst response — behind a telemetry strategy with honest coverage-gap analysis
incident-response-playbooks Eight operational playbooks including OAuth consent abuse, device-code and token theft, cloud control-plane compromise, and an AI-application incident — each with containment options priced by business cost — plus communication templates, regulatory notification decision aids, and tabletop packs

Technology and standards

Cloud and identity — AWS · Azure · Microsoft Entra ID · Okta · Delinea · AWS IAM · AWS Config · CIS Benchmarks

Security operations — CrowdStrike · SentinelOne · Tanium · BloodHound · Tenable · Sigma · MITRE ATT&CK

Application and supply chain — SonarQube · SecureFrame · SAST/DAST/SCA · CycloneDX · SPDX · VEX · GitHub Actions

Governance — NIST SP 800-53 Rev 5 · NIST CSF 2.0 · NIST AI RMF 1.0 · OWASP Top 10 · OWASP GenAI LLM Top 10 2026 · MITRE ATLAS · ISO 27001:2022 · ISO 14971:2019 · IEC 62304 · ISA/IEC 62443 · NERC CIP · FDA 524B / 510(k) · FedRAMP · DoD RMF · CMMC · SOC 2 · HIPAA · GDPR · SOX ITGC


Background

M.Sc. Cybersecurity · B.Sc. Information Technology · ISA/IEC 62443 Cybersecurity for Industrial Automation and Control Systems · CISSP (in progress) · Databricks Generative AI Fundamentals · Databricks AI Security

Experience spans regulated medical-device software and FDA premarket submissions, enterprise AI governance for a large technology organization, multi-business-unit HIPAA and SOX audit readiness, FedRAMP readiness and DoD RMF authorization, and security of converged IT/OT infrastructure in the energy sector.

Popular repositories Loading

  1. hubcys hubcys Public

    Base44 App: HubCyS

    JavaScript 1

  2. lecture0 lecture0 Public

    JavaScript

  3. apphosting-adapters apphosting-adapters Public

    Forked from firebase/apphosting-adapters

    Experimental addon to the Firebase CLI to add web framework support

    JavaScript

  4. manuscriptlens manuscriptlens Public

    Author's Best Buddy - Fiction analysis & editing tool

  5. Onboardly Onboardly Public

  6. subscription-doom subscription-doom Public

    JavaScript