Fatih Serdar
Çakmak.
SOC intern at a bank, building AI security tools on the side.
Computer Engineering student at ITU. I triage alerts and write SOC automation at Fibabanka, and outside that I build Tamga, an LLM security proxy, and MCPRadar, an MCP server scanner.
Built to defend.
Security thinking, working code.Tamga
Open sourceOpen-source proxy you host yourself, sitting between your app and the LLM provider (OpenAI, Anthropic, Azure, Vertex). Redacts PII inline (TC Kimlik, IBAN, credit cards), blocks leaked secrets, and catches prompt injection with sub-millisecond static scanning via an Aho-Corasick DFA. Ships KVKK / BDDK / GDPR / PCI-DSS compliance mappings, hash-chained audit logs, a Next.js incident dashboard, and a 309-prompt adversarial suite gated in CI.
tools/listmcpradar scanMCPRadar
Open sourceCatches tool poisoning, prompt injection, and supply-chain rug pulls in Model Context Protocol servers before your agent runs them. 6 detection rules (zero-width Unicode, injection patterns, encoded blobs, hidden HTML/Markdown, permission scope mismatch, dangerous tool names), SARIF output that drops straight into the GitHub Security tab, and SQLite snapshot diffing to flag silent schema changes. One-shot run with uvx, no install needed.
İTÜ MCP ↗
Local MCP server that connects an ITU student's Ninova (LMS) and OBS (student portal) accounts to Claude, Cursor, Codex, and other MCP clients. Ask about assignments, deadlines, grades, transcripts, or attendance in natural language; reads PDF/DOCX files, uploads homework only with explicit confirmation. Local-first: credentials never leave the machine and are sent only to ITU endpoints.
SOC Simulation ↗
End-to-end SOC simulation: 127 alerts, 126 false positives, 1 real threat. Maps multi-stage attacks to MITRE ATT&CK TTPs, with a React dashboard for real-time alert visualization, realistic log datasets to test SIEM correlation rules, and Python-based SOAR playbook flows for automated triage and enrichment.
Open demo ↗SOC n8n Workflows ↗
10 production-shaped SOC automation playbooks for n8n: LLM-assisted alert triage, phishing analysis, IOC enrichment, human-approved containment, CVE watch, and SOC reporting. Import-ready JSON, zero secrets.
İTÜ Ders Arşivi ↗
Independent archive of ITU's course schedule and academic calendar. OBS (the university portal) only publishes the current term, so this scrapes and persists the data daily: 27 terms back to 2016, 64,000+ section records. Search past and current sections, instructors, and quotas; build a weekly schedule with conflict detection and export to ICS/CSV; browse a department's prerequisite map and exam calendar. GPA calculation from a transcript preview runs entirely client-side.
Open demo ↗In the field.
Hands-on security operationsFibabanka
Cyber Security Operations (SOC) Intern · Part-time
- Triage production SIEM and EDR alerts in a BDDK-regulated banking SOC, escalating confirmed incidents to senior analysts
- Design and run n8n automation workflows for the SOC · LLM-assisted alert triage, IOC enrichment, and phishing analysis to cut manual L1 steps
- Review CTI feeds and track daily alert volumes; write incident documentation used in shift handovers and audit records
Doğuş Teknoloji
Cybersecurity and Incident Response Intern
- Triaged alerts and filtered false positives across SIEM, SOAR, EDR, and NDR platforms on a live SOC shift
- Wrote and tuned Cortex XSOAR playbooks for phishing and recurring threat patterns together with senior analysts
- Handled L1 incident response tasks and prepared case reports within SLA targets
- Monitored Active Directory and Windows/Linux logs; supported basic network segmentation work
Curiosity, applied.
Computer Engineering student at Istanbul Technical University (class of 2027). Started in Industrial Automation at Kocaeli ENKA, which turned out to be solid prep for OT/IT security. At Doğuş Teknoloji I worked across SIEM, SOAR, EDR and NDR platforms: L1 incident response, SOAR playbook writing (phishing playbooks especially), EDR alert tuning, and IT/OT segmentation. Now part-time at Fibabanka doing daily alert triage, CTI review, and n8n SOC automation (LLM-assisted triage, IOC enrichment, phishing analysis) in a BDDK-regulated banking environment. MITRE ATT&CK is how I think about threats. Off the clock I build open-source security tooling for AI systems: Tamga, a self-hosted LLM security proxy, and MCPRadar, a scanner that checks MCP servers for nasty surprises.
Istanbul Technical University (İTÜ)
B.Sc. in Computer Engineering · 2023 / 2027 (expected)
Kocaeli ENKA Technical Schools
Industrial Automation (Technical High School Diploma) · 2019 / 2023
Tools & disciplines
Cybersecurity
SOC Operations · Alert Triage · Incident Response (IR) · Threat Detection · Log Analysis · Phishing Analysis · IOC Enrichment · CTI · SIEM · SOAR · EDR/NDR · MITRE ATT&CK
AI / LLM Security
Prompt Injection Defense · PII Redaction · MCP Security · LLM-Assisted Triage
Infrastructure
Active Directory · Windows/Linux Administration · Network Security · Network Segmentation
Compliance
BDDK Regulatory Awareness · KVKK · ISO/IEC 27001 Awareness · Incident Reporting
Tools & Programming
Python · Go · SQL · C/C++ · FastAPI · Cortex XSOAR · n8n · Wireshark · Docker · Git
Certifications
Nokia NRS1
Nokia Network Routing Specialist I
Nokia