Hi, I'm
Faisal AlRomaihi
I'm a Cybersecurity Specialist at the National Cyber Security Center (NCSC) in Bahrain. I completed my MSc in Cyber Security, Privacy, and Trust at the University of Edinburgh, where my research focused on privacy-preserving systems and applied machine learning.
02.
Experience & Education
Cyber Security Specialist
National Cyber Security Center (NCSC), Bahrain
Feb 2026 – Present
- ▸Designing and managing enterprise-grade WAF policies to protect national-level digital infrastructure
- ▸Developing and maintaining network security architecture standards across government entities
- ▸Contributing to national cybersecurity policy frameworks and security architecture reviews
- ▸Advising on security controls, threat modeling, and risk mitigation strategies
MSc in Cyber Security, Privacy, and Trust
University of Edinburgh
Sept 2024 – Sept 2025
- ▸Dissertation: Privacy for Hire – Incentivising Scalable, Secure, and Fair Anonymous Communications
- ▸Supervisor: Dr Tariq Elahi
MSc Dissertation
Privacy for Hire – Incentivising Scalable, Secure, and Fair Anonymous Communications
May 2025 – Aug 2025
- ▸Analyzing volunteer, commercial, and cryptoeconomic models to evaluate their impact on privacy guarantees, decentralization, and network sustainability
- ▸Uses game-theoretic modeling and simulation to study relay operator behavior, Sybil resistance, and reward fairness
Software Engineer Intern
GBM
July 2023 – Aug 2023
- ▸Built and deployed a company-wide meeting room booking system using PHP, MySQL, and JavaScript, adopted in production
- ▸Implemented room availability search, calendar integration, conflict resolution, and admin controls
BS in Software Engineering
University of Bahrain
Sept 2020 – May 2024
- ▸GPA: 3.58/4.0 (Excellent)
03.
Projects
A selection of academic and personal projects spanning security research, systems programming, and ML.
Revealing Weaknesses in Google reCAPTCHA Using Adversarial ML
Assessed vulnerabilities in Google reCAPTCHA (v2/v3) using adversarial ML techniques (FGSM, PGD, SimBA). Demonstrated model extraction and membership inference attack risks. Proposed mitigations: adversarial training, federated learning hardening, privacy-aware design.
BlazeDB: Custom SQL Engine with Query Optimization
Built a modular SQL engine in Java with operators for SELECT, JOIN, GROUP BY, and aggregation. Used JSqlParser and relational algebra to generate optimized left-deep join trees. Integrated a custom query planner for projection/selection pushdown and schema-aware evaluation.
ML for Genre Clustering and Popularity Forecasting from Spotify Charts
Clustered 7,700+ songs using PCA and GMM based on genre and audio characteristics. Trained classifiers to predict hit songs and popular artists (F1-score: 0.89). Forecasted top 2024 artists using ARIMA, Prophet, XGBoost, and LightGBM.
FairPlay: Secure Two-Player Smart Contract on Ethereum
Developed a commit-reveal smart contract game on Ethereum Sepolia ensuring fairness and state consistency. Prevented reentrancy and cheating with pull-payment patterns and refund logic. Optimized gas usage with efficient storage and full game cycle testing.
Secure Programming: Vulnerability Analysis & Defense
Exploited CVEs (CVE-2024-3094, CVE-2020-11899) to demonstrate memory and logic vulnerabilities. Hardened a Flask-based VPN system against STRIDE-modeled threats. Applied AES encryption, PBKDF2, RBAC, and session security for backend defense.
HR.IO – DevOps-Integrated HR Management System with AI Chatbot
Built a bilingual (English/Arabic) HR platform with CPR smart card verification. Integrated an AI chatbot using GPT-3.5-turbo for Labor Law queries. Deployed with CI/CD (Vercel), monitored with Prometheus & Grafana.
04.
Certifications
AWS Certified Solutions Architect – Associate
Amazon Web Services
Issued: March 13, 2026
View on Credly05.
Skills & Technologies
Tools, languages, and frameworks I work with across security, ML, and software engineering.
Languages
AI / ML
Cybersecurity
Web & Frameworks
Databases & Tools
Cloud
06.
Get In Touch
Whether it's a collaboration, opportunity, or just a hello — my inbox is open.