Research Systems Real-world impact

Osama Al-Wardi

Exploring how to make software,
systems, and AI agents more secure.

Cyber Security Engineer at PROGNOST Systems GmbH

Security research
for complex systems

Portrait of Osama Al-Wardi

01 / Selected work

Research & publications

More research in my CV
01Software security / 2022–2023

GraphQL taint analysis

Combining static and dynamic analysis to investigate broken access control and data leakage in GraphQL APIs.

Read about the research

My master’s research at BTU Cottbus-Senftenberg modeled GraphQL schemas and operations using typed graphs and graph-transformation rules. Dependency analysis identified security-relevant source/sink operation pairs.

I designed an evaluation using GitHub’s GraphQL API, implemented Python-based dynamic tests across users with different privileges, and compared the approach with Schemathesis. This work developed into the ICGT 2024 paper.

02AI agents & security / 2023

KanAxe: AI agents for cyber security

A research-transfer project exploring LLM-based agents for penetration testing, cloud security, and compliance workflows.

Read about the project

I helped develop early LangChain-based agents that used security tools, interpreted their output, and selected subsequent actions.

The work explored context limitations, retrieval, reliability on specialized security tasks, and orchestration with human supervision. The project developed into an application for EXIST Research Transfer.

Research interests

  • Agentic AI security
  • Systems & software security
  • Access control
  • Information flow
  • Static & dynamic program analysis
  • Isolation
  • Runtime policy enforcement

02 / In practice

Professional experience

From research to real systems
2024 — PresentCurrent role

Cyber Security Engineer

PROGNOST Systems GmbH

Cyber security engineering for operational technology and industrial control systems in industrial environments.

  • Contribute to product certification projects involving IEC 62443-3-3, UR E27, and the EU Cyber Resilience Act.
  • Penetration testing, vulnerability scanning and management, authentication and authorization testing, cloud asset monitoring, and code reviews.
2022 — 2023

IT Security Consultant

Insentis GmbH

Penetration tests and security assessments across web applications, APIs, mobile applications, enterprise environments, and Active Directory.

Validated vulnerabilities, analyzed attack paths, and communicated findings and remediation guidance through technical reports.

2020 — 2022

Penetration Tester

Philotech GmbH / Working student

Security testing in automotive environments, including infotainment systems and embedded attack surfaces.

Contributed to autonomous-driving risk assessments and designs related to automotive security operations centers.

Professional certifications

Certified Azure Red Team Professional (CARTP) · Altered Security

Certified in Cybersecurity (CC) · ISC2

03 / Academic foundation

Education

2020 — 2023 / Cottbus, Germany

M.Sc. Cyber Security

Brandenburg University of Technology
Cottbus-Senftenberg

Master’s thesis

Design and Implementation of Taint Analysis for GraphQL-based Web Applications

Download master’s thesis (PDF)

Final grade: 1.9 · Research-oriented program · 124 credits

2017 — 2020 / Bremen, Germany

B.Sc. Computer Science

Constructor University
Formerly Jacobs University Bremen

Bachelor’s thesis

Performing Service Dependency Discovery on Web Application Clients

Download bachelor’s thesis (PDF)

Final grade: 2.77

Sharing knowledge

Teaching &
academic experience

Supporting students through tutorials, practical exercises, and technical guidance.

Advanced Programming in Python

Teaching Assistant · Jacobs University Bremen

Led tutorials and help sessions, supported labs, and graded assignments and exams.

Computer Networks

Teaching Assistant · Jacobs University Bremen

Explained networking concepts, supported tutorials, and graded coursework.

Ethical Hacking Laboratory

Teaching Assistant

Supported hands-on security exercises and learning in practical offensive security.

Simulation library development

Project Assistant

Contributed to porting a simulation library from JavaScript to Python.

04 / Looking ahead

Understanding systems.
Making them more secure.

I’m a security engineer based in Bremen, Germany, with a research background in program analysis and access control, and practical experience across industrial, automotive, cloud, and application security.

I’m interested in PhD research and cybersecurity opportunities that connect rigorous analysis with practical security challenges—particularly the security of software, systems, and AI agents.

[email protected]

The full picture

Curriculum vitae

Research, publications, professional experience, and technical skills.

Download CV PDF