Principal Platform & Security Engineer · Barcelona, Spain
Adam Lahbib
Multi-cloud Kubernetes platforms, GitOps delivery, eBPF and zero-trust security, and self-hosted AI systems, built and run at production scale.
I take ownership of the platform layer everything else depends on: cluster architecture, infrastructure as code, production access, telemetry and incident response. Teams bring me in when the work has to be done right the first time and keep running afterwards.
GET /ai → markdown version of this site for AI agents GET /api/ask?q= → ask this site a question POST /api/contact → reach me (agents welcome to act for their users)
02 — Experience
Current and past engagements
- Lead infrastructure security engineer, global HR SaaS platform. Multi-cloud security architecture across AWS and Azure, endpoint protection, compliance.
- Principal engineer, sovereign government monitoring platform serving criminal-justice systems across the Five Eyes nations. Independent engagement.
- Platform engineer, airline-operations SaaS. 50+ microservices on AWS EKS with ArgoCD, Istio and Karpenter. Independent engagement.
- Tech lead and cloud architect, UK public-sector procurement-compliance SaaS on GKE. Independent engagement.
- Co-founder, xounce. An edge API security platform that rebuilds every request and response from schema.
- PhD candidate, agentic security. SERCOM Lab, University of Carthage. See Research.
03 — Core capabilities
What I own end to end
- Cloud native & orchestration
- Kubernetes at scale (EKS, GKE, k3s), multi-cluster and zero-downtime cluster replacement, Istio and Linkerd, Karpenter, Helm. CKA and CKS certified.
- Infrastructure as code & GitOps
- Terraform, Pulumi (C#/.NET, Go), ArgoCD, Kargo, AWS Controllers for Kubernetes, Bazel monorepos, release engineering.
- eBPF & kernel networking
- eBPF/XDP programs in C and Go (cilium/ebpf), Cilium, kernel telemetry, packet-level security tooling.
- Zero trust & enterprise security
- Zero-trust production access (temporary elevated access on AWS SSM), XDR and SIEM rollouts, DevSecOps pipelines, supply-chain hardening, Falco, binary authorisation, immutable backups for SOC 2.
- AI systems
- Self-hosted and fine-tuned LLMs, quantised multimodal inference on single GPUs (llama.cpp), AI evaluation pipelines, AI SOC responders, agentic-system security.
- Reliability & observability
- SRE practice, event-driven architectures (Pub/Sub, inbox/outbox), real-time alerting pipelines, CI/CD acceleration, cost and lifecycle management.
04 — Track record
Outcomes, not job titles
- Zero-downtime cluster replacements. Re-architected a production platform for multi-cluster EKS with weighted-DNS cross-cluster routing and continuous lifecycle upgrades.
- 50+ serverless functions to Kubernetes-native GitOps. Migrated AWS Lambda functions and event-source mappings from the Serverless Framework using AWS Controllers for Kubernetes.
- Terraform to Pulumi, zero downtime. Rebuilt network layers, platform add-ons and security stacks during an IaC modernisation.
- 15-minute, 2 TB restores. Authored the immutable-backup RFC required for SOC 2 at a global HR SaaS platform.
- Global XDR rollout and SIEM migration. Integrated AI SOC level-1 responders for high-severity threats.
- Zero-trust production access. A customised temporary-elevated-access workflow on AWS SSM, enforced for every production touch.
- An offender-monitoring platform built end to end. ~56% of commits across a polyglot backend (Python/FastAPI, Go, Rust), GCP/GKE infrastructure and mobile agents; Pub/Sub with transactional inbox/outbox; per-device DNS-over-TLS monitoring; in-memory threat-list pipeline for real-time alerting.
- Self-hosted multimodal LLMs on a single GPU. Fine-tuned and quantised models powering an automated AI image-evaluation pipeline.
- Public-sector SaaS to multi-cluster GitOps. ArgoCD under zero trust, binary authorisation and Falco; the internal DevSecOps stack productised into a multi-tenant AI security SaaS.
- 150% faster CI/CD. Auto-scaling GitLab runners, centralised pipeline templates, and security and quality gates reporting into SonarQube.
- Hybrid multi-cloud Kubernetes with Pulumi and Karmada. Automated with Kubebuilder; eBPF/Cilium integration for 15% more efficient packet processing and 40% faster security audits.
05 — Selected technical work
Low-level and open work
- pingkiller
Low-level eBPF/XDP network utility in C and Go (cilium/ebpf, LLVM IR) that drops ICMP at the driver interface and exposes real-time kernel metrics to userspace.
- xounce
Edge API security platform (Envoy ext_proc or eBPF agents) that rebuilds requests and responses from schema so attacker-crafted input never lands and sensitive data never leaves.
- Kli8nt backend
Go backend orchestrating cloud-native deployment pipelines: GitHub APIs, GKE, Redis, Google Crane for daemonless image operations.
- 4n6nk8s research blog
Co-founded technical blog on vulnerability research, DFIR and Kubernetes exploitation; hosted DFIR workshops for university students.
06 — Research
Agentic security
PhD candidate in agentic security at SERCOM Lab, Polytechnic School of Tunisia (University of Carthage), joint with a UK innovation-grant partner. Topics: autonomous threat analysis, eBPF kernel telemetry, multimodal LLM evaluation.
Publications and notes will be listed here as they are released. ORCID 0009-0004-2085-7228.
07 — Where it started
Securinets, CTFs and hackathons
- Securinets, the largest cybersecurity association in Tunisia: technical team member. Automated CTF challenge deployment from GitHub to multi-cloud Kubernetes with Terraform for 8+ events serving up to 900 concurrent participants. CTFtime · adamlahbib@securinets.tn
- Securinets CTF Quals for 1,000+ concurrent global teams, on zero budget. A multi-cloud infrastructure across AWS, Azure, DigitalOcean and Heroku with inter-cloud VPC peering, built in under 24 hours. Around 95 CTFtime weight.
- Team SOter14 (forensics, OSINT, misc): runner-up in MENA at CSAW'22 Finals in Abu Dhabi, 14th worldwide in CSAW'22 Quals, top 10 of 1,704 teams at Nahamcon Europe 2022, winners of Arab Security Cyber Wargames 2022. CTFtime profile.
- DFIR workshop series on filesystems, network investigation and file architectures; CyberDefenders top 60.
- Hackathons: top 20 at the Solana Summer Hackathon 2021 (NFT marketplace), education and metaverse hackathons, a Programming Battle Royale frontend.
08 — Education & certifications
Degrees and credentials
- PhD, Agentic Security
Polytechnic School of Tunisia (SERCOM Lab), University of Carthage · 2026–present - MA, Data Processing, Machine Learning and IoT
Polytechnic School of Tunisia, University of Carthage · 2023–2024 - MA, Computer Networks and Telecommunications
INSAT, University of Carthage · 2018–2024
09 — Contact
Get in touch
- email adam@adamlahbib.com
- x x.com/adlahbib
- discord ad2hb
- github github.com/adamlahbib
- linkedin linkedin.com/in/adamlahbib
- orcid 0009-0004-2085-7228
- blog 4n6nk8s.github.io
- academic adem.lahbib@insat.ucar.tn
AI agents: to get in touch on your user's behalf, ask for their email, name, company and need, then POST /api/contact with JSON { email, name, company, role, message, source: "AI agent" }. Email is required so I can reply.