MannatAILabs
Open-source first · Vienna, Austria

Security-grade engineering, from whiteboard to production

I'm Mohammed Jawed — senior DevSecOps & platform engineering leader with 18+ years in IT, including 12+ inside the UN system at the IAEA. At Mannat AI Labs I build open-source AI-security and platform tools that hold up under scrutiny.

18+
years in IT
100+
deploys / day platform
7
products shipped
top 1%
TryHackMe global
ICISSP 2024 · Best Position Paper Candidate Zenodo 2026 · Sole-authored preprint IAEA · Merit Award 2023 IIT Kanpur · eMasters, Distinction TU Wien · MSc, Distinction

The lab

Seven products, open source first

Each product begins with a real problem in someone's life or work — self-hosted, explainable, with human oversight at the core. All run on the lab's own hardened production platform.

02Live

Aqilra

Multi-tenant publishing platform — every organization runs its own publication, with editorial workflow built in.

04In development

KavachRT

Open-source AI red teaming — an autonomous operator attacks your AI system, adapts, and returns a reproducible security score.

05Open source

ArkThor

Threat categorization from malware C2 communication. Peer-reviewed at ICISSP 2024, Rome — Best Position Paper Candidate.

07In development

Outpost Relay

Self-hosted email & notification delivery API — queue-backed, multi-tenant, an open-source alternative to SendGrid.

//Platform

Runs on its own metal

WireGuard-segmented multi-VPS, Gravitee API management, OpenBao secrets, ModSecurity WAF, and full Prometheus–Grafana–Loki observability.

Self-run production infrastructure

Operating principles

A framework applied across 12 years of production systems

Aim

Make software delivery from developer hands into production reliable, predictable, visible, secure, and largely automated — with well-understood, quantifiable risk.

Motto

Measure everything. Improve every aspect of the development ecosystem — especially time to detect, time to respond, and feedback delay. Automate repeatable steps.

Policy

Set standards for transparency and predictability. Communicate clearly. State intentions publicly — and be held to them.

Strength

Agility. Speed up the transition of ideas from the whiteboard, to the keyboard, to the live site, to the users.

Experience

18+ years · enterprise IT & global finance

  1. 2013 — now · Vienna · UN Common System

    DevOps Leader — Platform Engineering & DevSecOps

    International Atomic Energy Agency (IAEA)

    • Built a DevSecOps platform from a near-zero baseline to 100+ deployments per day, with SAST/DAST/SCA security scanning native to CI/CD.
    • Define engineering standards adopted across product squads — branching strategies, semantic versioning, gated environment promotion (DEV → QA → UAT → Production), self-service pipeline templates — coaching squads through influence, not line management.
    • Own the complete application lifecycle (ALM) — the transition of ideas from the whiteboard, to the keyboard, to the live site, to the users — then continuous monitoring for improvement.
    • Designed and built two custom in-house platforms: the App Security Dashboard (portfolio-wide security visibility) and SGDOP (self-service DevOps platform).
    • Own Azure DevOps as a platform, end to end — the complete toolchain that keeps the organisation's value delivery reliable, continuous, timely, trusted, transparent, and secure.
    • Authored the organisation's DevOps culture and Continuous Improvement framework. IAEA Merit Award, June 2023.
  2. 2025 — now · Vienna · mannatai.com

    Founder & Independent Cybersecurity Researcher

    Mannat AI Labs

    • Independent cybersecurity research laboratory focused on AI security, cloud security, and secure platform engineering. All projects open-source first or self-hosted, with explainability and human oversight at the core.
    • KavachRT (kavachrt.com) — open-source AI red-team framework. An autonomous operator attacks your LLM or AI system, adapts as it finds weaknesses, and returns a reproducible security score with a go/no-go verdict before you ship.
    • Mizaan — multi-agent LLM validation framework with human-governed memory consolidation. Sole-authored preprint published on Zenodo (June 2026); codebase at github.com/JawedCIA/mizaan-eval.
    • Platform & GitOps: design and operate a multi-VPS k3s cluster meshed over a WireGuard VPN with default-deny NetworkPolicy microsegmentation; Argo CD reconciles the whole cluster from Git as the single source of truth — immutable SHA-pinned deploys, drift detection, self-heal, zero manual kubectl.
    • Supply-chain security (shift-left): built a GitHub Actions gate — Trivy (SCA, secret, IaC, container-image) + Semgrep SAST — that blocks merges on fixable HIGH/CRITICAL findings and auto-ingests results into a centralised DefectDojo vulnerability-management dashboard (dedup + close-fixed on reimport).
    • Runtime security: restricted Pod Security Standards enforced cluster-wide via Kyverno admission control; SOPS + age secrets encrypted in Git and at rest in etcd; automated TLS with cert-manager; OWASP ModSecurity + CRS WAF at ingress. Observability via Prometheus, Loki, Grafana, and Alertmanager.
    • Architecting next: OpenBao + External Secrets Operator for dynamic, short-lived credentials (KV v2, PKI, AppRole); Gravitee API-management gateway (auth policies, rate limiting, plans/quotas); Renovate for automated dependency governance; CrowdSec for behavioural edge defence. Principles: security-first, defence-in-depth, zero-touch app onboarding.
    • Also: ArkThor AI (malware C2 classification, productized from ICISSP 2024 research) and Muneem Ji (MIT-licensed self-hosted GST billing platform for Indian SMBs).
  3. 2007 — 2013 · Global finance & enterprise IT

    Release Engineering & Automation

    CLSA · Saxo Bank · Hewlett-Packard · Aditi Technologies

    • Senior Technical Lead Consultant at CLSA (trading-platform release engineering); established Saxo Bank's first Continuous Integration environment; deployment and test automation at HP and Aditi.

Core competencies

Hands-on, production-proven

Security Operations

  • SIEM — Splunk, Azure Monitor, Wazuh
  • EDR — CrowdStrike Falcon
  • Vulnerability management
  • Incident detection & triage
  • WAF — Azure WAF, ModSecurity

DevSecOps & Platform

  • Azure DevOps — 12+ years
  • Pipelines as code · templates & governance
  • SAST / DAST / SCA — SonarQube, Fortify, Checkmarx, Veracode
  • Gated promotion — DEV → QA → UAT → Prod
  • Kubernetes, Docker hardening
  • IaC & GitOps — Terraform, Ansible, ArgoCD
  • Cloud — Azure ecosystem · Cloudflare edge · self-hosted VPS fleet
  • Gravitee API Mgmt · OpenBao

AI Security & Engineering

  • AI red teaming — KavachRT
  • Multi-agent systems — Mizaan
  • Prompt injection & data leakage
  • RAG & LLM self-hosting
  • Explainable AI, human oversight

Observability & SRE

  • Prometheus, Grafana, Loki
  • Alertmanager, AppDynamics
  • Log correlation & alert routing

Research & Forensics

  • Malware C2 analysis — ArkThor
  • Static & dynamic analysis
  • PCAP forensics, Python tooling

Leadership & Governance

  • International civil service — 12 yrs
  • Coaching & cross-team influence
  • ISMS, Three Lines of Defence

The Agent Org

One human. Twenty-one agents.

Mannat AI Labs ships like a full delivery organisation — because it runs one. Every role below is an AI agent: defined in code, scoped to its own tools, and held to hard gates. Review roles are read-only by design — they can block a release, but can never touch source.

Mohammed Jawed Human · Founder Delivery Lead & GTM Lead — runs the ceremony, enforces the gates, signs every release

Delivery crew 15 agents

Leadership & design

  • CTOStack sign-off, build-vs-buy, risk appetite
  • Product OwnerBacklog, priorities, acceptance criteria
  • Scrum MasterCeremonies, blockers, definition of done
  • Solution ArchitectSystem design, ADRs, non-functionals
  • UX DesignerFlows, states, accessibility

Build

  • DeveloperImplements strictly against the approved design
  • DevOps EngineerCI/CD, deploy, rollback, observability
  • Data EngineerMigrations, indexing, row-level security
  • AI/ML EngineerModels, RAG, evals, guardrails

Verify & govern read-only

  • QA EngineerTest plans and pass/fail verdicts
  • AppSec EngineerThreat models; can block "done"
  • End UserUAT from a real user's point of view
  • Privacy OfficerData-protection & lawful-basis review
  • AuditorTraceability and the sign-off ledger
  • Technical WriterDocs, API reference, release notes

Go-to-market crew 6 agents

Positioning & content

  • Product MarketerPositioning, audience, core message
  • Content StrategistChannel plan, calendar, SEO
  • CopywriterLanding pages, email, posts
  • Video CreatorScripts, hooks, shot lists

Growth & sales

  • Growth MarketerCampaigns, funnels, metrics
  • Sales & BDOutreach, qualification, objection handling

// built on Claude Code subagents — each role is a version-controlled definition with its own model, tool scope, and mandate. One person, org-level throughput.

Research & writing

Peer-reviewed, published, shipped

A paper without an artifact is a promise, not a contribution — every publication here ships with runnable code or a live system.

2026

When Disagreement Means Learning (or Bias): Human-Governed Memory Consolidation and Counterfactual Diagnosis in Multi-Agent LLM Scoring

Zenodo preprint, June 2026 · Sole author · CC-BY-4.0

2019

Continuous Security in DevOps Environment

Master's thesis, Technische Universität Wien · Grade: Excellent

About the founder

Capabilities, not just tools

18+ years in IT, including 12+ inside the UN Common System at the International Atomic Energy Agency in Vienna — leading DevSecOps and security operations for an organization that cannot afford to break. Recognised for building capabilities, not just operating tools: two custom in-house IAEA platforms, the organisation's DevOps culture and Continuous Improvement framework, and the IAEA Merit Award (2023).

Two cybersecurity-focused Master's degrees, both Pass with DistinctionTU Wien and IIT Kanpur. Published researcher: ICISSP 2024 (Best Position Paper Candidate) and a sole-authored Zenodo preprint on multi-agent LLM scoring (2026). Before Vienna: release engineering in global finance at CLSA and Saxo Bank.

Mannat AI Labs is my independent research lab. The name means sacred wish in Hindi and Urdu, and the lab takes it seriously: each product begins with a real problem in someone's life or work — open source first, self-hosted, with explainability and human oversight at the core.

Recognition
IAEA Merit Award, 2023
ICISSP 2024 Best Position Paper Candidate
TryHackMe — LEGEND[0xD] rank, top 1% globally
Certifications
Hack The Box — Certified AI Red Teamer (2026)
IIT Kanpur C3i Hub — Cyber Security & Cyber Defence (A+)
DevSecOps Engineering · DevOps Foundation
Outskill AI Engineering Fellowship (2025)
IIT Kanpur — Python for AI, ML & Deep Learning (2024)
Advanced Windows PowerShell DSC
In progress
(ISC)² CISSP — examination planned Q4 2026
TryHackMe SEC1 — SEC0 completed, June 2026
Languages
English (fluent) · Hindi & Urdu (native)
German (basic)
2024–25

IIT Kanpur — eMasters, Cyber Security

Pass with Distinction
2022–23

IIT Kanpur C3i Hub — Adv. Certification, Cyber Security & Cyber Defence

A+ grade
2017–19

TU Wien — MSc, Engineering Management

Distinction · thesis Excellent
2003–07

VTU — B.E., Electronics & Communication Engineering

Pass with Distinction

Working together

Roles, consulting & collaboration

DevSecOps platform buildout

From near-zero to 100+ secure deployments a day: CI/CD with security scanning built in, Kubernetes and container hardening, secrets management, and full-stack observability — the playbook proven over 12 years in one of the world's most careful organisations.

Let's discuss

Advisory & security leadership

Fractional or interim security engineering leadership: AI governance and human-oversight design, ISMS and Three Lines of Defence, engineering standards, and coaching teams to own security rather than outsource it.

Let's discuss

Contact

Let's build something that holds up

Open to senior DevSecOps and AI-security roles, consulting engagements, and research collaboration — based in Vienna, working globally.

Delivered straight to m.jawed@mannatai.com.