AVAILABLE6-month end-of-studies internship from February/March 2027

// M2 Reliability & Cybersecurity · Aix-Marseille University

MOHAMEDFHAFAH

End-of-studies internship (PFE), 6 months: security audit and GRC

Identity & Access Management (IAM/PAM), Security Audit & GRC, Active Directory Pentest, Secure Development

Master's student in Reliability and Cybersecurity (M2, SecNumEdu-labelled) at Aix-Marseille University. During my internship, I ran an ISO 27001 / 27002 gap analysis of a port operator's security policies and procedures: CMM maturity assessment, 15 prioritised recommendations, 12-month roadmap and audit report for the IT department. Seeking a 6-month security audit or governance, risk and compliance (GRC) internship from February/March 2027.

Key facts

  • 15.25/20

    M1 validated, mention Bien

  • 15

    prioritised recommendations from an ISO 27001/27002 audit (internship)

  • SAML · SCIM

    Entra ID to GitLab federation (M1 research project)

  • Pro Hacker

    Hack The Box: 36 machines, 5 Fortresses (September 2026)

// 01. FOCUS

Three target areas

The internship topics I am looking for, each with what I can already show.

  • IAM / PAM

    Identity & access

    • SAML 2.0 SSO federation and SCIM provisioning (Entra ID to GitLab)
    • RBAC / ABAC, Conditional Access, governance of non-human accounts
    • PAM: basics only (access policy, CyberArk / BeyondTrust comparison)
    See the evidence
  • Security audit / GRC

    Audit & compliance

    • ISO 27001 / 27002 gap analysis, CMM maturity assessment
    • 15 prioritised recommendations, 12-month roadmap, audit report
    • GDPR and HDS requirements in an IAM/PAM specification
    See the evidence
  • Active Directory pentest

    Offensive

    • Kerberoasting, AS-REP roasting, DCSync, AD CS abuse (pair lab)
    • BloodHound, Impacket, Certipy, Responder, Hack The Box practice
    • Hardening: tiered administration model, GPOs
    See the evidence

// 02. PROJECTS

Projects

Each project states what I did myself: solo, in a team, or provided by a course.

// CASE STUDIES

Three pieces of work in detail

What the work was, what I did myself, and how it fits together. Diagrams illustrate the general flow; they are not copies of a configuration.

IAM / PAMSupervised research project (M1), team, May to July 2026

SSO and automatic provisioning between Entra ID and GitLab

Context

A team answered an IAM/PAM specification for a MedTech SME: risk analysis, a comparison of Entra ID, Okta, BeyondTrust and CyberArk, and an access policy aligned with ISO 27002 (controls 8.2 and 8.4), HDS health-data rules and GDPR.

What I did

  • Set up SAML 2.0 federation with Entra ID as identity provider (IdP) and GitLab as service provider (SP).
  • Set up SCIM provisioning: accounts are created, updated and deactivated automatically (joiner-mover-leaver lifecycle).
  • Designed governance for AI-agent identities: non-human accounts, ABAC with dynamic groups, blocking of legacy authentication.

Note: PAM was covered through the access policy and the vendor comparison, not through a deployment.

See the project card
Sign-in with SAML 2.0 (generic flow)
  1. The user opens GitLab (SP)
  2. GitLab redirects to Entra ID (IdP)
  3. Entra ID authenticates and sends a SAML assertion
  4. GitLab opens the session
Account lifecycle with SCIM
  1. Joiner: the account is created in GitLab
  2. Mover: attributes and groups are updated
  3. Leaver: the account is deactivated
Non-human identities
  • Governance of technical accounts
  • ABAC with dynamic groups
  • Legacy authentication blocked
AD pentestPair project, three virtual machines on Proxmox

Attack and hardening of an Active Directory lab

Context

A domain of three virtual machines: a Windows Server domain controller, a client workstation and an attack machine. The goal was to attack the domain, then fix what made the attacks possible.

What I did

  • Exercised Kerberoasting, AS-REP roasting, DCSync and AD CS abuse.
  • Mapped attack paths with BloodHound.
  • Remediated with a tiered administration model and group policy objects (GPOs).

Note: The same techniques are practised on Hack The Box; the figures are dated in the Hack The Box section.

See the project card
From attack to fix
  1. Lab: domain controller, client workstation, attack machine
  2. Attacks: Kerberoasting, AS-REP roasting, DCSync, AD CS abuse
  3. Fixes: tiered administration model, GPOs
Audit / GRCInternship at Tanger Alliance (port operator), April to June 2025

ISO 27001 / 27002 gap analysis of three security policies

Context

As a cybersecurity analyst intern in the IT department, I assessed a port operator's policies and procedures on passwords and vulnerability management against ISO 27001 / 27002.

What I did

  • Reviewed three security policies and procedures (passwords, vulnerabilities).
  • Ran the gap analysis against ISO 27001 / 27002 and assessed maturity with the CMM model.
  • Wrote 15 prioritised recommendations (MFA, PAM, KPIs) and a 12-month roadmap, and presented the audit report to the IT department.
  • Built a security awareness platform with simulated phishing as a follow-up to the audit (Flask).

Note: Findings specific to the company are confidential and are not published here.

See the project card
Deliverables of the assignment
  1. Review of three policies
  2. Gap analysis, ISO 27001 / 27002
  3. Maturity assessment, CMM
  4. 15 prioritised recommendations
  5. 12-month roadmap
  6. Audit report to the IT department

// NOTES

Short technical notes

Explanations in my own words, written to organise what I learned. They explain the topics; they do not claim more experience than the projects above.

SAML or OIDC for single sign-on to GitLab?Two ways to let GitLab trust Entra ID instead of storing passwords, and what changes in practice.SAML 2.0OIDCSCIMGitLabEntra IDRead

Single sign-on means the application (the service provider, SP) trusts an identity provider (IdP) to authenticate users, so it never handles their passwords. Entra ID can play the IdP for GitLab with either SAML 2.0 or OpenID Connect (OIDC).

How they differ

  • SAML 2.0 exchanges signed XML assertions through the browser. It is long established in enterprise applications, and it is what I used in my team project.
  • OIDC is a layer on top of OAuth 2.0: the application receives a signed ID token (a JWT) and calls standard endpoints. It is lighter to implement and fits modern web, mobile and single-page applications.

What you actually maintain

  • SAML: signing certificates (and their rotation), the NameID format, the attribute and group mapping.
  • OIDC: client secrets (and their rotation), exact redirect URIs, the scopes and claims that are requested.

Provisioning is a separate question

SSO only handles the sign-in. Creating, updating and deactivating accounts is the job of SCIM. In my project the pair was SAML for sign-in and SCIM for the joiner-mover-leaver lifecycle. Which provisioning and group-sync features are available depends on the GitLab edition, so check the documentation of the edition in use.

Common causes of failure

  • An expired certificate or secret, or one rotated on one side only.
  • A NameID or email attribute that does not match the existing account.
  • Clock skew between the two systems, which invalidates short-lived assertions.
  • Groups that are mapped in one direction only, so roles drift.

How I would choose

OIDC for a new application or a modern stack; SAML when the application only supports it or when a SAML federation already exists. In both cases, enforce SSO, remove local passwords where possible, and deprovision through SCIM so that leavers lose access.

Kerberoasting: how it works, how to detect it, how to hardenA classic Active Directory attack seen from both sides, the one I exercised in my lab.Active DirectoryKerberosDetectionHardeningRead

In Active Directory, any authenticated user can ask the domain controller for a Kerberos service ticket for an account that has a service principal name (SPN). Part of that ticket is encrypted with a key derived from the service account's password. An attacker takes the ticket away and tries to guess the password offline, without further traffic to the domain.

Why it works

  • No special privilege is needed to request the ticket.
  • Service accounts often have weak, old or never-rotated passwords.
  • Tickets encrypted with RC4 (encryption type 0x17) are the cheapest to crack.

Detection

  • Windows event 4769 (a Kerberos service ticket was requested), filtered on RC4 encryption type 0x17.
  • One account requesting tickets for many different SPNs in a short time.
  • A decoy account with an SPN that no real service uses: any request for it is suspicious.

Hardening

  • Group managed service accounts (gMSA): long random passwords managed and rotated by Active Directory.
  • Long random passwords on the service accounts that cannot be gMSA.
  • Allow AES only and disable RC4 for Kerberos where applications permit it.
  • No SPN on privileged accounts, and a tiered administration model, so that a cracked service account does not lead to domain admin.

Its close cousin

AS-REP roasting targets accounts that have Kerberos pre-authentication disabled: the attacker only needs the account name to request material to crack, without knowing any password. The fix is to find and re-enable pre-authentication on those accounts. In my lab I exercised both attacks, then remediated with a tiered administration model and group policy objects.

ISO 27002 controls 8.2 and 8.4 in an access policy for a Git platformPrivileged access rights and access to source code, turned into concrete rules.ISO 27002PAMAccess controlGitRead

ISO/IEC 27002:2022 groups technology controls in chapter 8. Two of them matter most for a Git platform such as GitLab: 8.2 (privileged access rights) and 8.4 (access to source code).

8.2, privileged access rights

  • Keep the number of administrators and owners small, and give each a separate administration account.
  • Grant elevated rights for a limited time and for a reason, then remove them (the idea behind privileged access management).
  • Review privileged accounts on a schedule, and log what they do.

8.4, access to source code

  • Give repository access by role and by need, through groups rather than by individual.
  • Protect the main branches and require review before a merge.
  • Govern the tokens and service accounts that read or write code: they are identities too.
  • Enforce SSO and deprovision automatically, so that leaving the organisation removes access.

What I did with it

In my team project, the access policy for a MedTech SME was aligned with these two controls, together with HDS and GDPR requirements. PAM was covered at the level of the policy and a comparison of vendors (Entra ID, Okta, BeyondTrust, CyberArk), not through a deployment.

// 03. JOURNEY

Experience and education

Experience

  1. InternshipApril 2025 — June 2025 (2 months)

    Cybersecurity Analyst Intern

    Tanger Alliance (TC3 container terminal)Tangier, Morocco

    • ISO 27001 / 27002 gap analysis of 3 security policies and procedures (passwords, vulnerabilities): CMM maturity assessment, 15 prioritised recommendations (MFA, PAM, KPIs), 12-month roadmap and audit report presented to the IT department
    • Developed a security awareness platform following the audit (Flask, SQLAlchemy, Flask-Login): training and quizzes, simulated phishing campaigns tracking opens, clicks and reports
  2. Student jobAugust 2023 — March 2024

    Équipier Polyvalent

    Burger KingMarseille, France

    • Fast-paced, high-throughput operational environment
    • Teamwork, coordination, and prioritization
    • Customer-flow and order-flow management
    • Reliable execution and respect of standards

Education

  1. In progress2025 — 2027

    Master Informatique — Fiabilité et Sécurité Informatique (M2)

    Aix-Marseille Université, Marseille, France

    • M1 validated with honours (mention Bien, 15.25/20)
    • M2 in progress: cloud security, cryptography, software reliability, advanced networks
    • SecNumEdu-labelled programme (ANSSI)
    • M1: Application Security, Cryptography, Networks, Software Engineering
  2. Completed2022 — 2025

    Licence Informatique (180 ECTS)

    Aix-Marseille Université, Marseille, France

    • Java, Databases, Web, Unix/Systems
    • Cybersecurity, Network Applications, Compilation
    • Intro to NLP/TAL, Formal Verification
    • Mention Assez Bien
  3. Completed2021 — 2022

    DEUST Sciences et Techniques

    Université Abdelmalek Essaadi, Tangier, Morocco

    • Science and Technology foundations

// 04. SKILLS

Skills

Grouped by what I can explain in an interview. Tools I have not used in real work are not listed.

  • Defensive security & audit

    • ISO 27001 / 27002 gap analysis
    • CMM maturity assessment
    • Audit reporting & roadmaps
    • Risk analysis
    • GDPR & HDS requirements
    • Remediation planning
    • Security awareness & phishing simulation
  • Identity & Access Management

    • Entra ID (ex-Azure AD)
    • SSO SAML 2.0
    • OIDC / OAuth 2.0
    • SCIM provisioning
    • RBAC / ABAC
    • Conditional Access
    • Joiner-Mover-Leaver lifecycle
  • Offensive security

    • Active Directory attack paths
    • Kerberos (Kerberoasting, AS-REP roasting, delegation)
    • AD CS abuse
    • DCSync
    • NTLM relay
    • ACL abuse
    • Privilege escalation
  • Security tooling

    • Nmap
    • BloodHound
    • Impacket
    • Certipy
    • bloodyAD
    • Responder
    • John the Ripper

// 05. HACK THE BOX

Hack The Box

Offensive practice on a public platform. Headline figures come from the public profile of 27 September 2026.

  • Pro Hacker

    RANK

  • 36

    MACHINES

  • 7

    CHALLENGES

  • 3

    SHERLOCKS

  • 5/6

    FORTRESSES

  • 2

    MINI PRO LABS

Public profile

Fortresses

Jet (11/11)100/100
Akerva (8/8)100/100
Context (7/7)100/100
Synacktiv (7/7)100/100
Faraday (7/7)100/100
AWS (7/10)70/100

Challenges solved

  • ProtectedMobileMedium
  • CallfuscatedReversingHard
  • HexecutionReversingHard
  • SocratesPanelWebHard
  • Infinity BankMobileInsane
  • PyDomeMiscMedium

Practice areas

  • AD / AD CS / Kerberos attack paths
  • BloodHound mapping and hardening (tiering, GPO)
  • Reverse engineering practice
  • DPAPI artifact analysis
  • MFT extraction and recovery helpers
  • Remediation-oriented technical write-ups
  • HTB Sherlock investigations
  • Phishing-awareness workflows
Detailed breakdown (snapshot of 14 March 2026)

// DIFFICULTY BREAKDOWN

Easy11/154
Medium9/182
Hard5/118
Insane4/66

// OS BREAKDOWN

Linux19/348
Windows10/158

// MACHINE INVENTORY [29]

  • Cap
  • Expressway
  • Eloquia
  • Academy
  • MonitorsFour
  • Imagery
  • Eighteen
  • Signed
  • Conversor
  • Giveback
  • Gavel
  • DarkZero
  • NanoCorp
  • Hercules
  • Browsed
  • AirTouch
  • Fries
  • Soulmate
  • CodePartTwo
  • Facts
  • Overwatch
  • Guardian
  • Cobblestone
  • Sorcery
  • Pterodactyl
  • WingData
  • Interpreter
  • Pirate
  • CCTV

// RANK PROGRESSION

  1. 27 Dec 2025 · rank

    Script Kiddie

    First HTB rank achieved — start of the offensive security practice journey.

  2. 31 Dec 2025 · rank

    Hacker

    Hacker rank reached in under a week, demonstrating rapid progression through machine exploitation.

  3. 02 Jan 2026 · fortress

    Jet Fortress — 11/11

    First fortress fully completed. 100% flag capture across all 11 flags.

  4. 20 Jan 2026 · rank

    Pro Hacker

    Pro Hacker rank reached in 24 days — top-tier rank reflecting deep exploitation and post-exploitation skills.

  5. 07 Feb 2026 · fortress

    Akerva Fortress — 8/8

    Second fortress completed at 100%. All 8 flags captured.

  6. 07 Feb 2026 · lab

    Mythical Mini Pro Lab

    Completed the Mythical Mini Pro Lab — 3/3 flags, 3 machines, 100% completion.

  7. 09 Feb 2026 · lab

    Puppet Mini Pro Lab

    Completed the Puppet Mini Pro Lab — 4/4 flags, 3 machines, AD and pivoting-focused environment.

  8. 21 Feb 2026 · fortress

    Faraday Fortress — 7/7

    Third fortress completed in February. All 7 flags captured.

  9. 22 Feb 2026 · fortress

    Synacktiv Fortress — 7/7

    Fourth fortress completed. All 7 flags captured — back-to-back fortress completions.

  10. 23 Feb 2026 · fortress

    Context Fortress — 7/7

    Fifth fortress completed in 3 consecutive days. 5/6 fortresses now fully owned.

  11. 11 Mar 2026 · milestone

    29 Machines Owned

    Latest machines: Pirate & CCTV. Machine breakdown: 11 Easy, 9 Medium, 5 Hard, 4 Insane. 19 Linux, 10 Windows.

// BADGE HIGHLIGHTS [18]

  • Script Kiddie
  • Hacker
  • Pro Hacker
  • Took The Spotlight
  • Is There Anybody Out There?
  • Just Another Brick in the Wall
  • Comfortably Numb
  • Completed the Twelve Labours
  • Found Diamonds
  • Outspelled the Wizard
  • Powering Up
  • Jet Fortress
  • Akerva Fortress
  • Faraday Fortress
  • Synacktiv Fortress
  • Context Fortress
  • Mythical Mini Pro Lab
  • Puppet Mini Pro Lab

// 06. ABOUT

About me

I'm a Marseille-based Master's student in Reliability and Cybersecurity (M2) at Aix-Marseille University. I validated my M1 with honours (mention Bien), after a Bachelor's degree in Marseille and a DEUST in Tangier. I'm looking for a 6-month end-of-studies internship from February/March 2027 in identity and access management (IAM/PAM), security audit and GRC, or Active Directory pentest.

In my M1 supervised research project, I worked in a team on an IAM/PAM specification for a MedTech SME: I set up SAML 2.0 SSO federation and SCIM provisioning between Entra ID and GitLab, and designed governance for AI-agent identities (ABAC, dynamic groups, legacy-authentication blocking). PAM is a topic I have studied through the access policy and the CyberArk/BeyondTrust comparison, not yet in production.

During my 2-month internship at Tanger Alliance I ran an ISO 27001/27002 gap analysis of three security policies and built an awareness platform with phishing simulation. In parallel, I practise penetration testing on Hack The Box, mostly on Active Directory, and I build secure software in Java and Python. The common thread: understand a system, test it, document it, and propose a fix that can be applied.

Availability

  • End-of-studies internship6 months, from February/March 2027 (end-of-studies internship)
  • MobilityMarseille-Aix first, then all of France; open to Europe
  • Driving licenseB

Languages

  • ArabicNative
  • FrenchC2
  • EnglishC1 (self-assessed)

What I bring

  • Identity engineering + hands-on offensive practice
  • Coding + Security, not security-only
  • Remediation-oriented thinking
  • Clear technical writing and restitution
  • Analytical mindset
  • Autonomous
  • Rigorous
  • Synthesis capability
  • Clear written communication
  • Clear oral communication
  • Problem solving
  • Fast learning

AI as a work tool

I use AI assistants for code, research and documentation, and I always check their output. Two projects use it directly: a job-search pipeline built on AG2/autogen and Gemini, and MangaLab, a SaaS with a Gemini/Vertex AI pipeline.

  • ChatGPT
  • Claude
  • Codex
  • Gemini API
  • Vertex AI
  • AG2 / autogen
  • MCP
  • Streamlit
  • Playwright
See the projects