Rafiou Diallo

Cybersecurity & Machine Learning

Security Consulting · Penetration Testing · Applied ML

I secure and stress-test real-world systems, blending a background in machine learning and interpretability with hands-on penetration testing, and a strong interest in security consulting.

GitHubLinkedIn
Scroll

Featured Projects

NIST Cybersecurity Q&A System (RAG)

Retrieval-Augmented Generation system delivering grounded cybersecurity guidance from official NIST publications.

Query
FAISS
Context
Mistral
Answer

Query flows through FAISS retrieval to Mistral LLM with automatic source attribution

  • Built end-to-end RAG pipeline using Mistral-7B-Instruct, LangChain, and FAISS
  • Implemented 4-bit quantization for memory-efficient inference (~4GB VRAM)
  • Engineered recursive PDF scraping and validation for NIST SP 1800 documents
  • Generated semantic embeddings with Sentence Transformers for sub-100ms retrieval
  • Enabled automatic source attribution for every answer
PythonLangChainFAISSMistralNLPWeb Scraping
View on GitHub

Malware Image Classification using CNNs

Interpretable deep learning system for malware family classification from raw binaries.

High attention
Structure

Model attention highlights structural fingerprints used for classification

  • Converted malware binaries into 128x128 RGB images
  • Designed custom CNNs and fine-tuned ResNet50, achieving 98.4% test accuracy
  • Optimized architectures with Optuna
  • Implemented Grad-CAM for per-family interpretability
  • Built misclassification analysis pipeline for edge-case discovery
PyTorchCNNsResNet50OptunaGrad-CAM
View on GitHub

ML Network Intrusion Detection (CICIDS2017)

Production-scale ML system detecting real-world network attacks across millions of flows.

Flows
Features
LightGBM
SHAP
Protocol
Duration

SHAP reveals protocol-level attack signatures across 2.2M+ flows

  • Processed 2.2M+ network flows across 10 attack categories
  • Achieved 98% macro-F1, 99% recall on Bot attacks
  • Addressed extreme class imbalance with targeted resampling
  • Optimized LightGBM across 40+ configurations
  • Applied SHAP to reveal protocol-level attack signatures
PythonLightGBMSHAPPandasNetwork Security
View on GitHub

Semi-Supervised Anomaly Detection in System Logs

Sequence-based anomaly detection system for large-scale distributed logs.

p95 threshold
Block sequence
Anomaly
Normal

Long-tail anomalies prioritized for investigation, not hard classification

  • Built LSTM next-event prediction model using PyTorch
  • Learned normal execution patterns from unlabeled data
  • Scaled analysis to millions of HDFS log lines
  • Aggregated losses using p95 / max / mean for block-level detection
  • Emphasized exploratory analysis over brittle classification
PyTorchNLPLSTMPandasNumPy
View on GitHub

Experience

Packetlabs

Associate Ethical Hacker · Co-op

May 2026 – Aug 2026·Ottawa, ON
  • Performed web application, infrastructure, and cloud retests to verify vulnerability remediation
  • Conducted external penetration tests and vulnerability assessments for enterprise clients
  • Ran OSINT-driven vishing, phishing, and pretexting campaigns to test security awareness
  • Communicated findings with clients and delivered clear, client-ready penetration testing reports
  • Helped standardize client-facing testing methodology documentation in a fast-paced consulting environment
Burp SuitePenetration TestingOSINTPhishingWeb Application SecurityConsultingKali LinuxReporting

Carleton University

Information Security Co-op

Sep 2025 – Apr 2026·Ottawa, ON · Hybrid
  • Conducted 100+ vulnerability assessments using Tenable Nessus and Qualys, prioritizing critical CVEs
  • Built Python and PowerShell automation for compromised credential parsing, account lockout monitoring, and IP organization
  • Designed Microsoft Defender phishing simulations for 30,000+ users, achieving a 5% compromise rate
  • Reviewed WAF traffic, investigated DNS/SPF misconfigurations, and researched DDoS mitigation practices
  • Modernized security awareness training and documented vulnerability management, phishing, WAF, and authentication procedures
NessusQualysDefenderPythonPowerShellWAFBrightspace

myAIpathway.ORG

Developer · Internship

Feb 2025 – Sep 2025·Ottawa, ON · Remote
  • Built full-stack web applications and automation scripts using Python, React, and Node.js
  • Contributed to FRED, a platform connecting farmers with buyers to reduce food waste
  • Worked in an agile team to plan features, test releases, improve performance, and maintain clean code with Git
ReactNode.jsPythonGitAgileAutomation

Société Générale

Intern

May 2024 – Jul 2024·Conakry Region, Guinea · On-site
  • Supported network security operations by monitoring firewall configurations, antivirus software, and intrusion detection systems
  • Built RESTful database management applications that reduced paper usage by 50% and improved document workflows by over 40%
  • Implemented Chart.js visualizations, Axios data flows, and advanced search and filtering for banking documents
  • Resolved technical issues to support 95% uptime and mentored junior interns
JavaScriptCakePHPHTMLChart.jsAxiosNetwork Security

The UPS Store

Sales Assistant · Contract Part-time

Sep 2023 – Mar 2024·Ottawa, ON · On-site
  • Delivered customer service while protecting customer privacy and handling sensitive personal information
  • Balanced competing customer needs, corporate policies, and daily operational responsibilities
  • Collaborated with team members to keep store operations organized and responsive
Customer ServiceCommunicationOrganizationPrivacy

Skills & Tooling

Security Consulting

  • Security assessments & client advisory
  • Risk management & remediation planning
  • Governance, Risk & Compliance (GRC)
  • Threat modeling & security awareness
  • Vulnerability management programs
  • Technical reporting & stakeholder communication

Web Application Security

  • Web application security testing
  • Burp Suite & OWASP methodology
  • Penetration testing & vulnerability validation
  • Authentication, authorization & access control
  • API security & input validation
  • Security findings, evidence & remediation guidance

Security & Dev Tooling

  • Kali Linux & Linux / CLI workflows
  • Tenable Nessus, Qualys
  • Microsoft Defender
  • Burp Suite, Nmap & Wireshark
  • Python, PowerShell & Bash automation
  • Jira, Git & technical documentation

Machine Learning & AI

  • PyTorch, Scikit-Learn
  • Deep Learning (CNNs, LSTM, Transformers)
  • Natural Language Processing (NLP)
  • Retrieval-Augmented Generation (RAG)
  • Model Interpretability (SHAP, Grad-CAM)
  • Representation Learning & Embeddings

Data & Software Engineering

  • Python, JavaScript, SQL
  • React, Node.js, FastAPI
  • REST APIs & backend systems
  • Pandas, NumPy & data preprocessing
  • System design & performance optimization
  • Git, Agile development & documentation

Education

Carleton University

B.C.S. Honors Computer Science

Minor in Mathematics

GPA: 3.5

Expected Graduation: 2027

Certifications

Burp Suite Certified Practitioner

PortSwigger

Issued Aug 2026 · Expires Aug 2032

Web Application Security · Penetration Testing

CompTIA Security+

CompTIA

Issued Mar 2026 · Expires Mar 2029

Network Security · Risk Management · Security Operations

International Baccalaureate

International Baccalaureate

Issued May 2022

International Baccalaureate Diploma Programme

Let's Connect