Taher Amine ELHOUARI — Cybersecurity Leadership, Assurance and Resilience
Portfolio Professional services Open source portfolio LinkedIn The InfoSec Control Room
Cybersecurity leadership · GRC · Assurance · SOC/CSIRT · Resilience · Open Source
| STATUS | PRIMARY MODE | BASE | REACH |
|---|---|---|---|
OPEN TO ENGAGEMENTS |
BUILD · LEAD · ASSURE |
ALGERIA |
GLOBAL |
I work where cybersecurity, governance, assurance, operations and leadership meet — helping organizations turn standards, risk, technology and executive intent into security programs that are measurable, resilient, auditable and usable in the real world.
INPUT Risk · Complexity · Regulation · Operational reality
METHOD Govern · Defend · Assure · Enable
OUTPUT Security programs that survive audits and incidents
STANDARD Evidence over theatre
Most organizations do not have a security problem. They have a governance problem that manifests as security.
Open Algerian Data Protection Governance & Compliance Toolkit.
A self-hostable privacy governance platform built around Algeria's Law 18-07 and Law 25-11 — combining legal requirements, processing activities, DPO operations, rights requests, risks, evidence, privacy-by-design, ANPDP readiness, reporting and executive visibility in one operational workspace.
Next.js · React · TypeScript · Prisma · PostgreSQL · Docker · FR/AR/EN
Operating model: self-hosted · privacy-first · evidence-driven · multilingual · secure-by-default · open source
Built for me. Shared with the community.
A dark-first, local-first personal operations command center for projects, tasks, focus, follow-ups, deadlines, milestones, notes and daily execution. It began as a private tool built around my own workflow and is now available as an open-source project.
Python · FastAPI · HTMX · SQLite · Local-first · Offline-capable
Operating model: single-user · local data ownership · secure-by-default · no telemetry · no cloud dependency
Inspect release artifacts before they become security incidents.
A local-first defensive CLI for scanning release packages before publication or deployment.
Secrets · Archive safety · Policy checks · Static-site validation
Trust model: local · offline · read-only · no telemetry · no artifact execution
Share incident data without exposing the incident.
A local-first privacy engineering tool for sanitizing, pseudonymizing, auditing and packaging cybersecurity evidence before it is shared.
Discovery · Pseudonymization · Risk audit · Encrypted vault
Security model: local-first · policy-driven · source-preserving · review-oriented
DZ Privacy Compass TAE Command Center Release Sentry EvidenceVeil
Strategy · GRC · vCISO
Security governance, enterprise risk, ISMS/BCMS/PIMS, operating models, executive reporting, compliance and maturity roadmaps.
SOC · CSIRT · Resilience
Security operations, incident response, crisis management, threat intelligence, SIEM/SOAR, DFIR, VAPT and red/purple teaming.
Audit · Controls · Certification
Accredited audits, security assurance, certification readiness, control assessments, framework mapping and evidence-led improvement.
Training · Exercises · Mentoring
Certification training, executive awareness, practitioner workshops, tabletop exercises, mentoring and capacity building.
Explore professional services and engagements →
Professional learning, certification and applied cybersecurity practice.
Study Guides
Professional Books
Practitioner Toolkits
Free Framework Tools
Free community editions built from official objectives, authoritative references and practical context.
Interactive EditionsDownloadable PDFsVersioned Releases
A podcast about the decisions behind security programs — governance, ownership, risk, controls, operations and resilience.
LeadershipApplied SecurityReal Decisions
| Project | Mission | Access |
|---|---|---|
| 🧭 DZ Privacy Compass | Open Algerian data protection governance and compliance toolkit for Law 18-07, Law 25-11, DPO operations, evidence, assurance and privacy workflows. | Repository → · v1.0.0 → |
| ⚡ TAE Command Center | Local-first personal operations system for projects, tasks, focus, follow-ups and deadlines. | Repository → |
| 🕶️ EvidenceVeil | Privacy engineering for controlled cybersecurity evidence sharing. | Repository → |
| 🛡️ Release Sentry | Defensive release-artifact inspection before publication or deployment. | Repository → |
| 🧠 Cyber Master Series Guides | Free professional certification guides and governed community releases. | Repository → |
| 🧰 Cyber Master Series — Free Tools | Free practical cybersecurity, GRC, assurance and resilience tools. Includes RNSI Compass v1.0.0, an interactive Excel toolkit for Algeria's RNSI 2020, with additional framework-specific tools planned. | Repository → · RNSI Compass → |
| 🎤 Conferences | Selected presentation, workshop and technical-session materials. | Repository → |
| 🔬 CVE-2018-10583 | Vulnerability research and proof-of-concept work. | Repository → |
| 🔐 Strong Password Generator | Lightweight Python password-generation utility. | Repository → |
Explore the complete repository portfolio →
| 15+ | 300+ | 4 | 50+ | 3 | Top 10 |
|---|---|---|---|---|---|
| Years in IT & Cyber | Certifications & Credentials | Continents | Training Programs | Chapters Founded | International CTF Finishes |
- Global Advisory Board — EC-Council C|CISO and C|PENT
- Subject Matter Expert / Contributor — ISC2, Hack The Box and AfricaCERT
- Community leadership — OWASP Algiers, CSA Algeria and CAS Algeria
- Knowledge sharing — international speaker, trainer, mentor and program committee contributor
- Global 30 Under 30 in Cybersecurity — 2026
- Best Cybersecurity Thought Leader — Governance, Risk & Resilience, UK 2026
- International CTF performance — multiple Top 10 finishes
- Professional reach — advisory, audit and training across four continents
Governance, assurance and standards
ISO/IEC 27001 · ISO/IEC 27002 · ISO/IEC 27005 · ISO 22301 ·
ISO/IEC 27701 · ISO/IEC 42001 · NIST CSF · NIST SP 800-53 ·
CIS Controls · PCI DSS · SWIFT CSP · SOC 2 · RNSI
Security operations, response and resilience
SOC · CSIRT · Incident Response · DFIR · Threat Intelligence ·
SIEM/SOAR · VAPT · Red Team · Purple Team · Crisis Management
Cloud, technology and emerging security
ISO/IEC 27017 · ISO/IEC 27018 · CSA CCM / STAR · Cloud Assurance ·
IEC 62443 · OWASP · Secure Architecture · AI Governance
building: - DZ Privacy Compass — continued hardening and community-driven iteration - TAE Command Center — continued iteration from real-world use - Cyber Master Series Free Tools — expanding practical framework-specific GRC and assessment tools - Open-source security and privacy engineering tools - Professional cybersecurity books and practitioner toolkits recent_releases: - RNSI Compass v1.0.0 — Cyber Master Series Free Tools - DZ Privacy Compass v1.0.0 - TAE Command Center v1.0.0 - EvidenceVeil v1.0.0 - Release Sentry publishing: - Free certification study guides - Free framework assessment and GRC tools - Applied cybersecurity resources - Research and conference material broadcasting: - The InfoSec Control Room open_to: - Executive cybersecurity advisory - Accredited audit and assurance engagements - Training, speaking and strategic collaboration
Serious conversations are welcome across cybersecurity governance, GRC, assurance, SOC/CSIRT, resilience, cloud security, professional training, research and open-source security.
Website Services LinkedIn Email
LEARN IT · CERTIFY IT · APPLY IT · MASTER IT
© 2000–2026 Taher Amine ELHOUARI · Built with purpose for the global cybersecurity community.