Skip to content

01 / about me — Doha, Qatar

Ayesha Erum outdoors in Doha, framed by a green face-detection HUD reading: Cyber Security grad 2027 — status active, seeking full time roles

I build projects out of curiosity,explore AI and cybersecurity,and enjoy learning by creating.

Now: AI/LLM security research — QCRI

I'm a Data and Cyber Security student at the University of Doha for Science and Technology (GPA 3.98, Class of 2027). I build projects for fun, constantly explore new technologies and enjoy solving problems that push me to learn something I didn't know yesterday.

scroll

How I work

I learn by building

Documentation gives me context; building gives me understanding. When a project needs a technology I've never touched, I learn it by shipping the real thing.

I design for failure

Any system that runs long enough will crash mid-write, hit a rate limit, or lose its connection. Good engineering assumes interruption and makes recovery boring.

Security should enable systems

I'm interested in how systems fail, why attackers succeed and how better engineering reduces risk.

If I can't explain it, I don't understand it yet

Teaching helps me see if I really understand something. Explaining it to different people shows me what I still need to learn.

02 / projects

Built, not listed

Four systems I'd put in front of any engineering team. Each one is a full case study with the architecture, the decisions, and what went wrong.

01 / Personal Project · Cloud Automation

Content Automation Pipeline

Every morning at 6 AM, a cloud-hosted n8n workflow researches trending Reddit topics, writes a script with Gemini, gathers stock footage and narration, files everything into Drive, and emails me the results.

Illustration of the n8n workflow as a conveyor belt: a figure sips coffee at 6 AM while Reddit topics flow through Gemini, script, Pexels, voiceover, and subtitles into a final video and email summary
  • Runs itself at 6 AM daily
  • Validates before it spends
  • Email alerts on failure
  • Every run logged
  • Survives laptop-off
n8nRailwayGemini FlashPostgreSQL
Read Full Case Study

02 / QCRI · Cybersecurity Department

LLM Security Research Pipeline

Open-source maintainers are drowning in AI-written bug reports. I built the fault-tolerant pipeline creating the first large-scale dataset to measure it.

Illustration of a detective cat examining a flood of GitHub and GitLab issues, classifying them into human-written and AI-generated bins
  • Resumes after any crash
  • GitHub + GitLab, one model
  • CWE auto-tagging
  • Runs in production today
PythonPostgreSQLDockerGitHub APIGitLab APILinux
Read Full Case Study

03 / Fanar Hackathon 2026 · QCRI / HBKU

Murshid

Murshid watches your screen, listens in Arabic, remembers your goal, and guides you through complex apps one step at a time. Six Fanar models, one agentic loop.

Illustration of Murshid as a friendly lantern character running a perceive → reason → act loop between an eye, a brain, and a screen
  • Sees your screen
  • Speaks & listens in Arabic
  • Goal held across the session
  • One step at a time
  • Cited Islamic references
ElectronReactTypeScriptFanar APIs
Read Full Case Study

04 / Digibit Strategic Intelligence & Advisory Unit

Threat Intelligence Workstream

I owned the intelligence layer behind an AI security dashboard: threat simulations, kill chains, and a structured MITRE feed another team's code consumed directly.

Illustration of an analyst turning attack simulation reports into a MITRE ATT&CK heatmap feeding a security dashboard
  • Strict ATT&CK notation
  • Kill chains with IOCs
  • ISO 27001 mapping
  • P1/P2/P3 alert logic
  • Live capstone demo
MITRE ATT&CKATT&CK NavigatorISO 27001:2022Threat Modelling
Read Full Case Study

Also built

Web Security

Real-Time XSS Detection Extension

A browser extension that flags XSS exposure as you browse: client-side input inspection and severity classification, grown out of an earlier Python scanner.

JavaScriptBrowser APIsWeb Security

Security Engineering

Secure Email System

An encrypted email platform with AES-256 confidentiality, RSA-2048 key exchange, SHA-256 integrity checks, and PKI authentication.

PythonNode.jsAES-256RSA-2048PKI

03 / experience

Where I've done the work

Research infrastructure, threat intelligence, applied AI, and teaching. Real ownership in each, not a list of job descriptions.

  1. May 2026 — Sep 2026Doha, Qatar · On-site

    QCRI logo

    AI/LLM Security Research Intern

    Qatar Computing Research Institute (QCRI) · Cybersecurity Department, HBKU

    Built the data infrastructure for research into AI-generated vulnerability reports: a resumable scraper collecting from 4,646 GitHub and GitLab repositories into PostgreSQL.

    • Production scraper: ~2M output files, atomic writes, item-level resume
    • 17-table PostgreSQL schema, learned by building the real thing
    • Docker services deployed on a remote Linux research server
    PythonPostgreSQLDockerGitHub REST APIGitLab APILinuxBash

    I can translate a research question into a production-quality engineering system.

  2. 2026 · 12 weeksRemote

    Digibit logo

    Network Threat Intelligence Analyst

    Digibit Strategic Intelligence & Advisory Unit · Cyber, Threat Intelligence & Resilience Team

    Owned the threat intelligence layer behind an AI-powered security dashboard in a 15-member programme. My deliverables were live integration inputs, not standalone documents.

    • MITRE heatmap feed: 20 techniques, accepted without reformatting
    • 3 threat simulations with kill chains in strict ATT&CK notation
    • ISO 27001 control mapping + P1/P2/P3 alert logic for 15+ techniques
    MITRE ATT&CKATT&CK NavigatorISO 27001:2022Threat ModellingTechnical Writing

    I can turn threat research into structured intelligence that engineering teams consume directly.

  3. Jan 2026 — PresentDoha, Qatar

    UDST logo

    Applied AI & NLP Researcher

    University of Doha for Science and Technology · Student Research Program

    Building an LLM-powered system that routes free-text clinical referrals to the right medical specialty: prompt engineering, classification pipelines, and model evaluation.

    • Poster presented at UDST's first Student Research Program Showcase
    • Evaluation benchmarked against real deployment requirements
    PythonLLMsPrompt EngineeringNLPModel Evaluation

    Research is measurement. A model that can't be evaluated can't be deployed.

  4. Jul 2025 — PresentDoha, Qatar

    Be My Sense logo

    Content & Copywriting Intern → Marketing Lead

    Be My Sense · AI accessibility startup, Qatar

    Be My Sense builds real-time speech-to-sign and sign-to-speech translation with a 3D signing avatar, covering ASL, BSL, and Qatari Sign Language. I started as a content intern writing website, LinkedIn, and campaign copy. Six months in, I was promoted to Marketing Lead.

    • Set the marketing strategy and lead a six-person team: planning, delegation, content review, deadlines
    • Represent the company at events like Web Summit Qatar, pitching and demoing the product live
    • Test the AI product, report bugs to the developers, and run accessibility awareness activities on campus
    Marketing StrategyTeam LeadershipPublic SpeakingProduct DemosAccessibility Advocacy

    Explaining technology to strangers, in person, is a skill you only build by doing it.

  5. Jan 2024 — PresentDoha, Qatar

    UDST logo

    Peer Tutor — Programming, Mathematics & AI

    University of Doha for Science and Technology

    15 hours a week and 20+ students supported since 2024, across programming, mathematics, and AI coursework.

    • One-to-one and group tutoring; recognised for academic learning support
    PythonJavaMySQLMongoDBCalculusStatistics

    Explaining a concept in different ways is how you find out whether you actually understand it.

04 / research

Measuring what others assume

Research is how I learn. I like problems where the literature is thin, the data doesn't exist yet, and the first job is building the instrument that makes measurement possible.

Data collection · targeting a top-tier security venue

AI-Generated Vulnerability Reports in Open-Source Software

QCRI Cybersecurity Department · supervised by Dr. Ahmed Lekssays

Question
How prevalent are AI-generated vulnerability reports, and what do they cost the maintainers who triage them?
Method
Empirical measurement across 4,646 repositories, case studies, maintainer interviews, and a detection classifier.
My part
I built the entire data collection infrastructure the study stands on.
The infrastructure behind it

Ongoing · presented at the first UDST SRP Showcase

Automated Clinical Referral Triage Using Large Language Models

UDST Student Research Program · supervised by Dr. Ahmad Abdel-Hafez

Question
Can LLMs classify free-text clinical referrals accurately enough to automate real triage?
Method
Prompt-engineering and classification pipelines for clinical text, evaluated against deployment requirements.
My part
I work on the NLP pipeline end to end: preprocessing, prompts, and evaluation.

05 / leadership

Leadership

Building the system is only half the job; people still have to understand it. I've spent as much time on that half, in classrooms and at event booths, as I have writing code.

Ayesha speaking on stage at a UDST peer tutoring event

Peer Tutor

Helping students with programming, cybersecurity, and mathematics.

Ayesha wearing the Computing & IT Representative sash at a UDST event

College Representative

Representing computing students across university initiatives.

Ayesha at the Be My Sense booth at Web Summit Qatar

Be My Sense

Presenting accessibility technology at Web Summit Qatar.

Ayesha beside the automated clinical referral triage research poster at the SRP Showcase

Student Research Program

Presenting our AI clinical referral triage research.

06 / achievements

Achievements

This is the part of a portfolio you can verify: competition placements, academic awards, and the certifications behind the skills section.

Ayesha receiving a medal on stage at the UDST Academic Awards Ceremony 2024

Academic Excellence

UDST Academic Awards, 2024

Ayesha holding her certificate at the UDST Dean's List celebration

Dean's List

UDST, 2025

Ayesha holding the oversized 12,000 QAR second place cheque at the LifeLines Hackathon 2026

LifeLines Hackathon

2nd place · CMU Qatar, 2026

Competitions

  • 2026

    LifeLines Hackathon

    2nd place · Carnegie Mellon University Qatar

  • 2026

    Fanar Hackathon

    Built Murshid: six AI models, one agentic loop, demoed live

    Case study
  • 2026

    Build for QSTP

    Qatar Science & Technology Park hackathon program

  • 2026

    Qatar Innovation Program

    Artificial Intelligence Association team participation

Recognition

  • 3.98 / 4.00

    GPA, B.Sc. Data and Cyber Security

  • 2025

    3rd Place — Capture The Flag Competition

  • 2025

    3rd Place — Mobile App Development Competition

  • 2024

    1st Place — Skills Day Mathematics Competition

    UDST

Certifications

  • Splunk Core Certified User

    Splunk · Valid through 2029 · Credly verified

    2026
  • CCNA: Switching, Routing & Wireless Essentials

    Cisco Networking Academy

    2026
  • Network Security Fundamentals

    Palo Alto Networks Cybersecurity Academy

    2025
  • Cybersecurity Foundation

    Palo Alto Networks Cybersecurity Academy

    2025
  • Introduction to Penetration Testing

    Security Blue Team

    2025

Hands-on training: Incident Forensics Workshop (6h, hands-on lab) (NetWitness, 2025) · Cybersecurity Analyst Job Simulation — IAM (Tata / Forage, 2025)

07 / skills

Where I've used them

Every skill listed here points at the project or role where it was actually applied.

Languages

  • PythonQCRI pipeline · XSS scanner · secure email
  • TypeScript / JavaScriptMurshid · XSS extension · this site
  • PHPsecure e-commerce app
  • Bashserver ops · pipeline tooling

Cybersecurity

  • Threat Intelligence & MITRE ATT&CKDigibit workstream
  • Vulnerability ResearchQCRI research · XSS tooling
  • Web SecurityXSS extension · secure e-commerce
  • SIEM & Log AnalysisSplunk-certified · coursework
  • Applied Cryptographysecure email system
  • Digital ForensicsNetWitness lab · coursework

AI

  • LLM Integration & Prompt EngineeringMurshid · clinical triage
  • Agentic SystemsMurshid · automation pipeline
  • Model Evaluationclinical triage research

Cloud & Automation

  • DockerQCRI pipeline containers
  • Linux & SSHQCRI remote research server
  • Railwaycontent automation deployment
  • n8ncontent automation pipeline

Databases

  • PostgreSQLQCRI 17-table schema
  • MySQL / MongoDBcoursework · tutoring

Tools & Frameworks

  • ReactMurshid overlay UI · this site
  • ElectronMurshid desktop app
  • GitHubQCRI scraper · all projects
  • GitLabQCRI multi-platform collection
  • SplunkSIEM coursework

08 / contact

Working on something difficult?

I'm looking for internships and roles in security engineering, AI security, and security research. If the problem is real and the system has to hold up, I'm interested.

ayeshaerum2006@gmail.com