Mannat·AI·Labs

Senior DevSecOps & platform leader · Founder, Mannat AI Labs · Vienna

Mohammed Jawed

Security operations, platform engineering, and AI security — 18+ years in IT, including 12+ inside the UN system at the IAEA. I build capabilities, not just operate tools: platforms, frameworks, and AI systems that hold up under scrutiny.

Now building KavachRT and Mizaan · ICISSP 2024 · IIT Kanpur '25 · TU Wien '19 · IAEA Merit Award

Mohammed Jawed
Vienna, Austria 18+ yrs IT · 12+ yrs IAEA

Experience

18+ years · enterprise IT & global finance
  1. 2013 — now Vienna · UN Common System

    DevOps Leader — Platform Engineering & DevSecOps

    International Atomic Energy Agency (IAEA)

    • Built a DevSecOps platform from a near-zero baseline to 100+ deployments per day, with SAST/DAST/SCA security scanning native to CI/CD.
    • Define engineering standards adopted across product squads — branching strategies, semantic versioning, gated environment promotion (DEV → QA → UAT → Production), self-service pipeline templates — coaching squads through influence, not line management.
    • Own the complete application lifecycle (ALM) — the transition of ideas from the whiteboard, to the keyboard, to the live site, to the users — then continuous monitoring for improvement.
    • Designed and built two custom in-house platforms: the App Security Dashboard (portfolio-wide security visibility) and SGDOP (self-service DevOps platform).
    • Own Azure DevOps as a platform, end to end — the complete toolchain that keeps the organisation's value delivery reliable, continuous, timely, trusted, transparent, and secure.
    • Authored the organisation's DevOps culture and Continuous Improvement framework. IAEA Merit Award, June 2023.
  2. 2025 — now Vienna · mannatai.com

    Founder & Platform Engineering Lead

    Mannat AI Labs

    • Independent research lab for AI security, cloud security, and secure platform engineering — open-source first, with explainability and human oversight at the core.
    • Architect and operate the lab's entire production platform hands-on: a WireGuard-segmented multi-VPS environment with hardened Ubuntu baselines, non-root Docker containers, Gravitee API gateway (OAuth 2.0 / JWT, rate limiting), OpenBao secrets management (vault-issued, short-lived credentials), ModSecurity WAF, Fail2ban, automated TLS, and full Prometheus–Grafana–Loki–Alertmanager observability.
    • Ships Command Center, Aqilra, Mizaan, KavachRT, ArkThor, Muneem Ji, and Outpost Relay — seven products designed, built, and operated end to end by one founder.
  3. 2007 — 2013 Global finance & enterprise IT

    Release Engineering & Automation

    CLSA · Saxo Bank · Hewlett-Packard · Aditi Technologies

    • Senior Technical Lead Consultant at CLSA (trading-platform release engineering); established Saxo Bank's first Continuous Integration environment; deployment and test automation at HP and Aditi.

Core competencies

hands-on · production-proven

Security Operations

  • SIEM — Splunk, Azure Monitor, Wazuh
  • EDR — CrowdStrike Falcon
  • Vulnerability management
  • Incident detection & triage
  • WAF — Azure WAF, ModSecurity

DevSecOps & Platform

  • Azure DevOps — 12+ years
  • Pipelines as code · templates & governance
  • SAST / DAST / SCA — SonarQube, Fortify, Checkmarx, Veracode
  • Gated promotion — DEV → QA → UAT → Prod
  • Kubernetes, Docker hardening
  • IaC & GitOps — Terraform, Ansible, ArgoCD
  • Cloud — Azure ecosystem · Cloudflare edge · self-hosted VPS fleet
  • Gravitee API Mgmt · OpenBao

AI Security & Engineering

  • AI red teaming — KavachRT
  • Multi-agent systems — Mizaan
  • Prompt injection & data leakage
  • RAG & LLM self-hosting
  • Explainable AI, human oversight

Observability & SRE

  • Prometheus, Grafana, Loki
  • Alertmanager, AppDynamics
  • Log correlation & alert routing

Research & Forensics

  • Malware C2 analysis — ArkThor
  • Static & dynamic analysis
  • PCAP forensics, Python tooling

Leadership & Governance

  • International civil service — 12 yrs
  • Coaching & cross-team influence
  • ISMS, Three Lines of Defence

Operating principles

applied across 12 years of production systems
Aim
Make software delivery from developer hands into production reliable, predictable, visible, secure, and largely automated — with well-understood, quantifiable risk.
Motto
Measure everything. Improve every aspect of the development ecosystem — especially time to detect, time to respond, and feedback delay. Automate repeatable steps.
Policy
Set standards for transparency and predictability. Communicate clearly. State intentions publicly — and be held to them.
Strength
Agility. Speed up the transition of ideas from the whiteboard, to the keyboard, to the live site, to the users.

The Agent Org

one human · 21 AI agents

Mannat AI Labs ships like a full delivery organisation — because it runs one. Every role below is an AI agent: defined in code, scoped to its own tools, and held to hard gates. No build starts without an approved design; nothing is "done" without QA and security sign-off. Review roles are read-only by design — they can block a release, but can never touch source. The only human is at the top of the tree.

Mohammed Jawed Human · Founder Delivery Lead & GTM Lead — runs the ceremony, enforces the gates, signs every release

Delivery crew 15 agents

Leadership & design

  • CTOStack sign-off, build-vs-buy, risk appetite
  • Product OwnerBacklog, priorities, acceptance criteria
  • Scrum MasterCeremonies, blockers, definition of done
  • Solution ArchitectSystem design, ADRs, non-functionals
  • UX DesignerFlows, states, accessibility

Build

  • DeveloperImplements strictly against the approved design
  • DevOps EngineerCI/CD, deploy, rollback, observability
  • Data EngineerMigrations, indexing, row-level security
  • AI/ML EngineerModels, RAG, evals, guardrails

Verify & govern read-only

  • QA EngineerTest plans and pass/fail verdicts
  • AppSec EngineerThreat models; can block "done"
  • End UserUAT from a real user's point of view
  • Privacy OfficerData-protection & lawful-basis review
  • AuditorTraceability and the sign-off ledger
  • Technical WriterDocs, API reference, release notes

Go-to-market crew 6 agents

Positioning & content

  • Product MarketerPositioning, audience, core message
  • Content StrategistChannel plan, calendar, SEO
  • CopywriterLanding pages, email, posts
  • Video CreatorScripts, hooks, shot lists

Growth & sales

  • Growth MarketerCampaigns, funnels, metrics
  • Sales & BDOutreach, qualification, objection handling

Built on Claude Code subagents — each role is a version-controlled definition with its own model, tool scope, and mandate. One person, org-level throughput.

Research & writing

peer-reviewed · published
  • 2026

    When Disagreement Means Learning (or Bias): Human-Governed Memory Consolidation and Counterfactual Diagnosis in Multi-Agent LLM Scoring

    Zenodo preprint, June 2026 · Sole author · CC-BY-4.0

  • 2024

    ArkThor: Threat Categorization Based on Malware's C2 Communication

    ICISSP 2024, Rome · Best Position Paper Candidate · with C3i Hub, IIT Kanpur

  • 2019

    Continuous Security in DevOps Environment

    Master's thesis, Technische Universität Wien · Grade: Excellent

  • 2026

    MIZAAN — The Balance

    Memoir · Notion Press · Amazon, Flipkart

About the founder

18+ years in IT, including 12+ inside the UN Common System at the International Atomic Energy Agency in Vienna — leading DevSecOps and security operations for an organization that cannot afford to break. Recognised for building capabilities, not just operating tools: two custom in-house IAEA platforms, the organisation's DevOps culture and Continuous Improvement framework, and the IAEA Merit Award (2023).

Two cybersecurity-focused Master's degrees, both Pass with DistinctionTU Wien and IIT Kanpur. Published researcher: ICISSP 2024 (Best Position Paper Candidate) and a sole-authored Zenodo preprint on multi-agent LLM scoring (2026). Before Vienna: release engineering in global finance at CLSA and Saxo Bank.

Mannat AI Labs is my independent research lab. The name means sacred wish in Hindi and Urdu, and the lab takes it seriously: each product begins with a real problem in someone's life or work — open source first, self-hosted, with explainability and human oversight at the core.

Recognition
IAEA Merit Award, 2023
ICISSP 2024 Best Position Paper Candidate
TryHackMe — LEGEND[0xD] rank, top 1% globally
Certifications
Hack The Box — Certified AI Red Teamer (2026)
IIT Kanpur C3i Hub — Cyber Security & Cyber Defence (A+)
DevSecOps Engineering · DevOps Foundation
Outskill AI Engineering Fellowship (2025)
IIT Kanpur — Python for AI, ML & Deep Learning (2024)
Advanced Windows PowerShell DSC
In progress
(ISC)² CISSP — examination planned Q4 2026
TryHackMe SEC1 — SEC0 completed, June 2026
Languages
English (fluent) · Hindi & Urdu (native)
German (basic)

Education

  • 2024–25

    IIT Kanpur — eMasters, Cyber Security

    Pass with Distinction

  • 2022–23

    IIT Kanpur C3i Hub — Advanced Certification, Cyber Security & Cyber Defence

    A+ grade

  • 2017–19

    TU Wien — MSc, Engineering Management

    Pass with Distinction · thesis graded Excellent

  • 2003–07

    VTU — B.E., Electronics & Communication Engineering

    Pass with Distinction

Working together

roles · consulting · collaboration

AI security assessment & red teaming

Adversarial testing of LLM applications and agentic systems — prompt injection, data leakage, tool abuse — with a reproducible security score and a go/no-go verdict before you ship. The practice behind KavachRT.

DevSecOps platform buildout

From near-zero to 100+ secure deployments a day: CI/CD with security scanning built in, Kubernetes and container hardening, secrets management, and full-stack observability — the playbook proven over 12 years in one of the world's most careful organisations.

Advisory & security leadership

Fractional or interim security engineering leadership: AI governance and human-oversight design, ISMS and Three Lines of Defence, engineering standards, and coaching teams to own security rather than outsource it.

Contact

Open to senior DevSecOps and AI-security roles, consulting engagements, and research collaboration — based in Vienna, working globally.

Or write from here

Delivered straight to [email protected].