← Home

Chima Anthony Ukachukwu

Cybersecurity Analyst  |  AI Red Teamer & LLM Security  |  SOC & Blue Team  |  Incident Response

Oklahoma City, OK  ·  Open to Remote (U.S.)  ·  U.S. Green Card Holder  ·  Eligible for Secret Clearance

chima.ukachukwu.sec@gmail.com  ·  LinkedIn  ·  GitHub  ·  Portfolio

Download PDF

Professional Summary

Cybersecurity analyst spanning security operations and AI security, built on IT infrastructure and systems administration since 2014. Ran endpoints, Active Directory, networking and Microsoft 365 identity before moving into SOC work on a corporate Network Security team: Splunk Enterprise Security alert triage, Nessus vulnerability scanning, and a containerised MISP platform with Python feed automation that removed an estimated 40% of manual feed handling. Now 1.5+ years of contract AI evaluation and red teaming across multiple frontier LLM platforms, testing for prompt injection, jailbreak and agent reward hacking. M.Sc. Computer Science, Cybersecurity (GPA 3.7), Cisco CyberOps Associate, SC-900, AWS Cloud Practitioner, BTL1 in progress. U.S. Green Card holder, eligible for Secret clearance.

Technical Skills

Security Operations
SOC alert triage, log analysis, threat detection, incident response, vulnerability management, security monitoring
AI / LLM Security
AI red teaming, prompt injection testing, jailbreak taxonomy design, AI agent evaluation, reward-hacking detection, adversarial test design, OWASP Top 10 for LLM Applications, OWASP Agentic AI Top 10, NIST AI RMF
SIEM & Security Tools
Splunk Enterprise Security, Microsoft Defender, MISP, Nessus, Nmap, Wireshark, Imperva
Threat Intelligence
MISP administration, community feed ingestion (CIRCL OSINT, abuse.ch, AlienVault OTX), indicator normalisation, IOC handling
Programming & Automation
Python, PowerShell, Bash, JavaScript, Git and GitHub Actions
Systems & Infrastructure
Windows Server, Linux, Active Directory, Docker and Docker Compose, networking fundamentals, VPN
Cloud & Identity
Microsoft Entra ID (Azure AD), conditional access, MFA, Intune, Microsoft 365 security administration, AWS fundamentals
Frameworks & Compliance
NIST CSF, NIST AI RMF, ISO 27001, HIPAA, OWASP Top 10, MITRE ATLAS, risk assessment, access control policy

Professional Experience

AI Evaluation & Safety Specialist

2024 – Present

Independent / Contract  ·  Remote (United States)

  • Design and execute adversarial test cases against frontier LLMs targeting prompt injection, jailbreak and behavioural manipulation, documenting findings in NDA-compliant evaluation reports used to inform safety guardrails.
  • Audit autonomous AI agent scenarios for reward hacking and evaluator manipulation: review YAML task specifications and scoring rubrics, verify PASS/FAIL trajectories reflect legitimate task completion, and analyse execution logs for world-agent response consistency.
  • Evaluate model and agent behaviour against the OWASP Top 10 for LLM Applications, the OWASP Agentic AI Top 10 and NIST AI RMF across multiple frontier model families.
  • Contract across frontier-LLM evaluation and safety platforms including Snorkel AI, Alignerr, Mercor, Meridian (Invisible) and RemoteXperts, and selected for LinkedIn's expert verification program.
  • Publish an NDA-compliant AI Evaluation & Safety portfolio on GitHub, including a rubric validation toolkit that identified a scale-anchor defect affecting eight dimensions across my own published rubrics.

Cybersecurity Intern – Corporate Information Systems

May 2024 – Aug 2024

Hobby Lobby  ·  Oklahoma City, OK · On-site

  • Deployed and documented a containerised MISP threat-intelligence platform using Docker and Docker Compose, giving the corporate Network Security team a working system for ingesting and operationalising threat indicators.
  • Automated community threat-feed ingestion in Python across CIRCL OSINT, abuse.ch and AlienVault OTX, normalising per-source schemas and scheduling indicator pushes into MISP, removing an estimated 40% of the manual feed-handling effort.
  • Triaged alerts and analysed logs in Splunk Enterprise Security alongside the corporate Network Security team.
  • Ran vulnerability scans with Nessus and contributed to secure architecture reviews.
  • Presented project outcomes to senior IT staff and authored internal process documentation.

Technical Support Specialist – Microsoft Windows & Office 365

Jan 2021 – Sep 2024

Authorized Microsoft Support Vendor (via Upwork) · Contract  ·  Remote (United States)

  • Supported Microsoft 365 environments for customers globally across Exchange, SharePoint, Teams and OneDrive, building endpoint security and identity management depth at enterprise scale.
  • Resolved Tier-2 identity and access issues covering conditional access policies, MFA enrolment, account recovery and Active Directory permissions.
  • Automated recurring support workflows in PowerShell, reducing manual ticket-handling time and improving first-response times.
  • Supported Intune deployment and patch enforcement, and coordinated with internal security teams to maintain endpoint compliance and system hardening.

Student Library Assistant (Research & Information Support)

Sep 2023 – Apr 2025

Oklahoma City University · Part-time  ·  Oklahoma City, OK · On-site

  • Resolved patron-facing identity and access issues across Microsoft 365 services (Teams, SharePoint, Exchange, OneDrive) for students and faculty.
  • Documented recurring workflows to streamline support handover and student onboarding.

IT Support & Systems Administrator

2014 – Jan 2021

Catholic Church of the Resurrection Magodo · Contract  ·  On-site

  • Ran day-to-day IT operations for a multi-user site over seven years, delivering Tier 1 and Tier 2 support across endpoints, networking and access management and resolving helpdesk tickets end to end.
  • Implemented security protocols, managed user access and advised on procurement of secure IT equipment, the systems grounding that later underpinned SOC and cloud identity work.

Projects

  • Prompt Injection Simulator and AI Red Team CTF. Browser-based security exhibits. Models prompt-injection attack paths against a deterministic agent and shows which defence layers stop which attack, plus a six-level progressive CTF. Vanilla JavaScript with no backend or model calls, so every result is reproducible. Demonstrates injection attack surface, defence in depth and secure client-side design.
  • ai-red-teaming-frameworks (Python, MIT). Jailbreak taxonomy of 10 categories and 64 patterns published as an installable classifier with a command-line interface, a documented threat model and parity tests that hold the Python and JavaScript implementations to the same behaviour.
  • MISP Feed Ingest (soc-defensive-portfolio). Python pipeline that normalises multi-source threat feeds into MISP-ready indicators, with noise suppression for RFC1918 and loopback addresses, Docker Compose deployment and an operator runbook. The test suite caught three defects before release, including a malformed-feed parsing bug.
  • Adverse Insight (Streamlit, OpenAI). Three-agent pipeline that extracts contract clauses, scores them for hidden risk and drafts negotiation language. Built in 48 hours for the Codex Creator Challenge, then red-teamed against its own prompt-injection surface with the findings published as a case study. Hosted on Streamlit's free tier, so the demo sleeps when idle. One click wakes it, about 30 seconds. [GitHub]
  • Rubric Toolkit (Python). Inter-rater agreement and rubric validation: Cohen's and Fleiss' kappa, Krippendorff's alpha and per-rater calibration offsets, with statistics checked against published worked examples. Found a scale-anchor gap across eight dimensions of my own rubrics.
  • Hands-On Labs & Competitions. National Cyber League 2023: log analysis, packet inspection, cryptography. TryHackMe and Hack The Box: SOC Level 1, Pre-Security and Junior Penetration Tester paths completed. M.Sc. capstone: identified and remediated network vulnerabilities using Nessus and Nmap. Home lab: Active Directory simulation on Windows Server and Ubuntu with Microsoft 365 configuration.

Certifications

  • Cisco CyberOps Associate
  • Microsoft SC-900, Security, Compliance & Identity Fundamentals
  • AWS Certified Cloud Practitioner
  • Google Cybersecurity Certificate
  • CCEP, Certified Cybersecurity Educator Professional (Red Team Leaders)
  • CTIGA, Certified Threat Intelligence & Governance Analyst (Red Team Leaders)
  • AI Security, Securiti AI
  • Microsoft 365 Fundamentals (MS-900)
  • Microsoft Azure Fundamentals (AZ-900)
  • Microsoft AI Fundamentals (AI-900)
  • BTL1 (Blue Team Labs One) (in progress)

Education & Training

  • M.Sc. Computer Science, Cybersecurity, Oklahoma City University  ·  May 2025 · GPA 3.7 / 4.0
  • Cybersecurity Mentorship Program (Defensive Security Track), Cybersecurity Clarity  ·  Dec 2023 – Dec 2025
    Defensive security fundamentals, ethical hacking, OWASP Top 10 and CTF-style labs. Capstone: automated OWASP Top 10 vulnerability tests in Python.
  • IT Support Graduate, Per Scholas  ·  2024
  • Junior Cloud Practitioner, ChooseU  ·  2022