// pre-sales solutions engineering · technical account leadership · cybersecurity
Abdul Javed
I'm a customer-facing cybersecurity advisor with 6+ years bridging technical depth and business outcomes. At Rapid7 I'm the primary technical advisor for 25+ enterprise MDR and vulnerability-management accounts — leading discovery, demos, technical validation, and executive business reviews that drive adoption, expansion, and retention.
Orlando, FL·PenTest+·CySA+·(ISC)² CC·Rapid7 InsightIDR & InsightVM certified·M.S. Cybersecurity
// about
From the Genius Bar to the SOC
My path into security ran through the Apple Genius Bar — two years of live troubleshooting under pressure, where I learned that technical skill only matters if you can bring the person across the counter along with you. That lesson has shaped every role since.
At Karyopharm Therapeutics I moved from privacy into security operations: running GDPR, CCPA, and HIPAA assessments and DPIAs, implementing the NIST 800-53 framework — presenting control roadmaps and winning buy-in from IT, legal, and executive stakeholders — and building a phishing awareness program that cut susceptibility by 40% across 200+ employees.
Today at Rapid7 I'm a Senior Cybersecurity Advisor for enterprise MDR and managed vulnerability management accounts, owning the technical relationship from onboarding through renewal and expansion. I lead discovery sessions, tailored demonstrations, and technical validation; present monthly and quarterly business reviews to CISOs and senior management; and advise on security architecture aligned to ISO 27001 and CIS Controls. The job is equal parts security engineering and communication — fluent from SOC analyst to CISO — and that intersection is where I do my best work.
Off the clock I build things. Most recently an AI bid-automation pipeline that turns a manual, multi-hour estimating workflow into a reviewed queue — OAuth integrations, browser automation, and an LLM doing the first-pass document reading, with a human approval gate before anything leaves the building. I'm always tinkering with the next one.
// experience
Where I've worked
-
Senior Cybersecurity Advisor, MDR & MVM — Rapid7
Dec 2021 — Present- Primary technical advisor for 25+ enterprise client teams across the Rapid7 platform (InsightIDR SIEM/MDR, InsightVM), owning the technical relationship from onboarding through renewal and expansion.
- Lead discovery sessions and deliver tailored demonstrations and workshops that map business requirements to platform capabilities — for technical and executive audiences alike.
- Present monthly and quarterly business reviews to CISOs and senior management, covering posture metrics, risk findings, and adoption roadmaps.
- Partner with Sales, Support, and Product to qualify upsell and cross-sell opportunities and resolve technical blockers in active deals.
- Remediated critical security gaps — zero-day exposure, unauthorized remote access, third-party VPN risk, unencrypted credential storage — with measurable risk-score reduction that anchored renewals.
- Maintain competitive knowledge across the SIEM/EDR/VM landscape to position platform differentiation credibly.
-
Cybersecurity Analyst — Karyopharm Therapeutics
Oct 2020 — Dec 2021- Implemented the NIST 800-53 framework — presenting control roadmaps and gaining buy-in from IT, legal, and executive stakeholders.
- Reduced phishing susceptibility 40% and trained 200+ employees through an ongoing simulation and awareness program.
- Ran internal technical evaluations and proof-of-concept cycles to select and deploy enterprise security solutions.
-
Privacy Analyst — Karyopharm Therapeutics
Aug 2019 — Oct 2020- Conducted GDPR, CCPA, and HIPAA audits, DPIAs, and third-party vendor assessments — directly applicable to security questionnaires and compliance-driven sales cycles.
-
Technical Expert, Genius Bar — Apple
Oct 2017 — Aug 2019- High-volume, customer-facing technical troubleshooting; go-to expert for training new employees and clarifying protocols.
// credentials
Certifications & education
PenTest+ (PT0-002)
CySA+ — Cybersecurity Analyst (CS0-003)
CC — Certified in Cybersecurity
InsightIDR Specialist
InsightVM Certified Admin
M.S. Cybersecurity & Information Assurance — WGU
B.S. Information Technology — UMass Boston
// toolbox
What I work with
SIEM / SOC
Endpoint / EDR
Vulnerability management
Network, cloud & identity
Automation
GRC & frameworks
Pre-sales motions
// projects
Things I've built
Side projects that keep my hands on the keyboard — product thinking, automation, and the web stack.
EpoxyCreations Estimator — AI bid automation
A Node dashboard that automates commercial bid response end to end: pulls bid invites from BuildingConnected over the Autodesk APS API (3-legged OAuth), drives Playwright through SSO to fetch permit-set plans, has Claude read those PDFs to draft square-foot takeoffs, applies a pricing rules engine, renders branded proposal PDFs, and delivers them via Microsoft Graph. Every send is gated behind explicit human approval — the pipeline drafts, a person decides.
JobPilot — AI job-search autopilot
A React app built on Claude that runs a job search end to end: parses resume PDFs into structured profiles, matches live postings against your preferences via web search, drafts tailored cover letters and screening answers, and tracks the whole pipeline through an autopilot review queue.
Epoxy Creations — website, SEO & structured data
I build and run the web presence for a Florida commercial flooring company: 80+ hand-rolled static pages, local SEO, Core Web Vitals tuning, and Search Console / GA4 instrumentation. Led a 2026 structured-data overhaul — replacing fabricated per-city business markup and self-serving review schema with accurate Service entities, rebuilding FAQ and breadcrumb JSON-LD sitewide, and adding llms.txt for AI-search readiness. Python scripts handle the batch edits across the page set.
// writing
Notes from the field
Security operations, awareness programs, and lessons learned the hands-on way. All posts →
What advising 25+ security teams taught me about incident response
The patterns that separate teams that recover in hours from teams that recover in weeks — none of which are about buying more tools.
Read post → May 2026 · 5 min readThe phishing program that actually changed behavior
How we cut phishing susceptibility 40% at a biotech — by treating it as a continuous program with a no-blame culture, not an annual checkbox.
Read post →// contact
Let's talk
Whether it's detection & response, vulnerability management, or a customer-facing security role you're hiring for — I'd love to hear from you.