class LaylaKaddani:
# Identity
name = "Layla KADDANI"
location = "Amiens, France | Nationwide mobility | Driving licence"
languages = ["French (Advanced)", "English (Advanced)", "Arabic (Native)"]
# Education
current = "EiJV — Engineering Degree in Cybersecurity (CTI, SecNumedu, RNCP40947)"
level = "Diplôme d'ingénieure Bac+5 — expected 2028"
I understand connected systems from both their hardware logic and their vulnerabilities.
End-to-end Windows / Active Directory security lab covering IAM, hardening, security monitoring and detection
- Built and configured a complete Active Directory environment (
cyberlab.local) with OUs, users, security groups and privileged roles - Implemented Group Policy controls including Password Policy, Account Lockout Policy and workstation security policies
- Applied Least Privilege and (SoD) using dedicated IT and Direction roles, with access-control validation
- Hardened SMB by disabling SMBv1 and enforcing SMB Signing
- Configured and reviewed Windows Defender Firewall, Windows services and remote administration exposure through WinRM
- Collected and parsed Windows Security Event ID 4625 using PowerShell, including Logon Type and source IP analysis
- Developed a PowerShell-based detection workflow to identify repeated network authentication failures and automatically generate security alerts
- Produced structured security reports and CSV outputs for Security Monitoring and Detection Engineering
Windows Server Active Directory GPO IAM PowerShell SMB WinRM Windows Defender Firewall Security Logging Detection Engineering
Location-based event sharing app — Security Lead on a team of 3
- Defense in Depth — 7 independent security layers
- Firestore Security Rules — server-side data protection independent of client code
- Privacy by Design — user location never stored, only used locally for distance filtering
- Runtime GPS permissions, unexported activities, API keys protected via
.gitignore
Java Firebase Auth Firestore Google Maps SDK Cloudinary GitHub
Demonstrated a model swap attack on a cardiac risk detection AI — then built the defense
- Attack: silent model replacement inverting all diagnoses with no visible UI change
- Defense: SHA-256 integrity verification at every inference call — blocks diagnostic and triggers alert if tampering detected
- Model: Random Forest, 98.5% accuracy on Heart Disease UCI dataset
Python React scikit-learn Flask SHA-256
Real-time biometric access control deployed on Raspberry Pi
- Facial recognition with liveness detection (eye-blink EAR — anti-spoofing)
- Multi-page admin interface (PyQt5): user management, live video feed, access logs, CSV export
- Automated email alerts on intrusion attempts
- MongoDB for user and event log storage
- 🔧 Hardware: PIR sensor, servo motor, LED, buzzer
Python OpenCV dlib PyQt5 MongoDB Raspberry Pi
Full IoT smart city prototype with MQTT architecture and real-time supervision
- Flood management (ultrasonic sensor + pump relay)
- Adaptive street lighting (LDR + PIR)
- Bus tracking via RFID on ESP32
- Waste classification with YOLOv8 (Raspberry Pi + camera)
- Django web dashboard with RBAC (citizen / admin) and real-time alerts
Python Django MQTT Mosquitto ESP32 ESP8266 YOLOv8 Tkinter RFID
Python dashboard developed during my internship at Alpamare Saïdia to monitor water quality and chemical consumption
- Interactive dashboard for water quality analysis
- Monitoring of chemical consumption (chlorine, pH-, flocculant, anti-algae, etc.)
- Automatically calculates key performance indicators (chemical consumption, cost per customer, and pH compliance)
- Data cleaning and transformation from Excel
- Standalone executable generated with PyInstaller
Python Pandas Matplotlib Seaborn Excel PyInstaller
| Certification | Issuer | Date |
|---|---|---|
| Google Security Risk Management | Google / Coursera | August 2026 |
| Introduction EBIOS Risk Manager | Club EBIOS | April 2026 |
| SecNumAcadémie | ANSSI | February 2026 |
| CCNA Networking Essentials | Cisco NetAcad | February 2026 |
| Programming For Everybody (Getting Started With Python) | University of Michigan / Coursera | May 2024 |
Diplôme d'ingénieure Cybersécurité 2025 → 2028
EiJV — École d'Ingénieurs Jules Verne, Amiens
CTI-accredited | SecNumedu | RNCP40947
Completed (Bac+3 — Year 1):
S5 : Advanced Algorithms & Programming | Databases | Computer Architecture
Networks & Communication | System Administration
Project Management | Enterprise Law
S6 : OOP | Web Development | Introduction to Cybersecurity
Operating Systems | Network Infrastructure & Services
Mobile Development | IoT & Embedded Systems
Upcoming:
S7 : Cryptography | Risk Analysis | Secure Software Dev | OS Security
S8 : Pentest & Social Engineering | Network Security | Governance
Forensic Analysis | IAM | Data Privacy
S9 : Cyber Defense & SOC | IoT Security | Hardware Security
AI for Security | Reverse Engineering | Mobile Security
DUT Informatique option Embarquée 2023 → 2025
EST — École Supérieure de Technologie, Oujda
Key Coursework:
Year 1 : Algorithms & C Programming | Python Data Structures
Linux Operating Systems & Networks
Microprocessors, Microcontrollers & Applications
Electronics
Year 2 : Arduino & Embedded C |
Embedded Systems Design & Applications
Intelligent Systems & IoT
Image Processing & Applications
Java & Embedded Systems | Android & Web dev
Mention Très Bien (16.82/20 — Y1 | 17.34/20 — Y2)