Hi, I'm

Ahmet Furkan Koç

|

Securing cloud infrastructure at scale — Azure, AI/LLM workflows, and automated threat detection.

CompTIA Security+ Azure Defender CSPM SIEM/SOAR
Ahmet Furkan Koç

Building secure systems,
one layer at a time.

I'm a Product Security Engineer focused on cloud security, threat detection, and AI-driven security automation. Currently at Toshiba in Frisco, TX, I work across CSPM, endpoint security, and application security to protect enterprise infrastructure at scale.

I hold a B.S. in Computer Science from UT Dallas (2025) and bring hands-on experience with Azure Defender, CrowdStrike, Splunk, and custom automation using PowerShell, KQL, and Python. I'm passionate about leveraging AI/LLM technologies to accelerate security operations and reduce response times.

Outside of work, I lead the Cybersecurity Community as President, mentoring peers and keeping up with emerging threats and AI/ML security trends.

100+ Misconfigurations Remediated
35% Cloud Security Posture Improvement
11K+ Endpoints Secured
45% MTTR Reduction

Academic Background

University of Texas at Dallas

Bachelor of Science in Computer Science

2025
Richardson, Texas Computer Science Cybersecurity Focus
🏛️ President, Cybersecurity Community Club
🎓 B.S. Computer Science — Class of 2025
🔐 Focus in Cloud Security & AI Systems

Where I've Worked

T
Dec 2025 – Present Frisco, TX

Cloud Security Analyst

Toshiba
  • Improved cloud security posture by 35% within six months by remediating 100+ misconfigurations through Defender for Cloud, ensuring 100% alignment with CIS benchmarks.
  • Monitored and secured endpoint security for 11,000+ assets, reducing successful malware execution attempts through proactive threat protection and hardening.
  • Triaged and investigated security alerts within Sentinel and Defender, identifying potential anomalies and escalating high-priority incidents for remediation.
Azure SentinelDefender for CloudCrowdStrike SIEM/SOARIncident ResponseCSPM
T
May 2025 – Dec 2025 Frisco, TX

Product Security Engineer Intern

Toshiba
  • Automated security operations using PowerShell and KQL to identify critical CVEs, query Azure Resource Graph, and accelerate threat detection workflows leveraging AI/LLM technologies.
  • Conducted application security testing using SAST, DAST, and SCA on enterprise SaaS solutions, performing assessments against OWASP Top 10 and providing remediation guidance for secure CI/CD integration.
  • Monitored cloud security posture across Azure environments using Defender for Cloud, identifying and escalating misconfigurations in alignment with CIS and NIST frameworks.
PowerShellKQLSAST/DAST OWASPAzure DefenderNIST
AI
May 2024 – Aug 2024 Frisco, TX

Cybersecurity Intern

AI Connex
  • Collaborated on AI-focused events promoting knowledge sharing and cybersecurity best practices.
  • Gained proficiency in EDR software and network protocols, enhancing skills in threat detection and mitigation.
  • Utilized OSINT threat tools to identify and analyze potential vulnerabilities across the threat landscape.
EDROSINTThreat DetectionNetwork Protocols

Things I've Built

December 2025 GitHub

Agentic AI Threat Assessment System

Autonomous multi-agent security system that triages Microsoft Defender for Cloud Attack Path alerts using a LangGraph supervisor pipeline. Classifies cloud resources by environment, analyzes NSG exposure and active CVEs, generates structured security verdicts, and creates Jira tickets — with Human-in-the-Loop approval before any action.

  • Multi-agent pipeline: ContextAgent, NetworkAgent, ThreatHunter with LLM-based supervisor routing
  • Automated classification of 200+ daily security logs90% accuracy in risk severity labeling
  • HITL interrupt gate before ticket creation or alert dismissal; PostgreSQL state persistence
August 2025

AI Security Agent for Cloud Monitoring

Security agent built with Azure AI Foundry to detect publicly exposed cloud resources and identify security vulnerabilities across Azure infrastructure. Features automated email notifications to resource owners with detailed exposure reports.

  • 45% reduction in Mean Time to Respond (MTTR)
  • Automated alerting for publicly exposed assets
  • Command-based triggers with detailed guidance reports

Technical Toolkit

☁️ Cloud & Security

Azure Defender for Cloud Azure Sentinel Azure Entra ID Azure AI Foundry CSPM IAM SIEM/SOAR CrowdStrike

🛡️ Security Tools

Microsoft Defender Splunk WIZ OWASP ZAP Burp Suite MITRE ATT&CK BlackDuck Kali Linux

💻 Languages & Compliance

PowerShell Python KQL Bash PCI DSS NIST CIS ISO 27001

⚙️ DevOps & Tools

Terraform Jenkins GitHub / GitLab Linux Logic Apps Power BI JIRA Confluence

Achievements & Certifications

🏆
Award

Intern of the Cohort — Toshiba

Recognized for outstanding performance, dedication, and contribution as a Product Security Engineer Intern (Fall 2025).

Award

WayUp Top Intern — Summer 2025

Elected as a top intern across cohort for outstanding contribution to the company.

CompTIA · Certification

CompTIA Security+

Industry-recognized certification validating foundational cybersecurity knowledge and skills.

CompTIA · Certification

Cloud Security — CompTIA

Validates skills in securing cloud environments, architecture, and infrastructure across major platforms.

Microsoft · Certification

Microsoft Security Essentials Professional

Professional-level Microsoft certification covering core security principles, identity, and compliance solutions.

Microsoft · Certification

Generative AI — Microsoft

Certification covering applied generative AI concepts and their integration into enterprise workflows.

NVIDIA · Certification

Computer Networking — NVIDIA

Certification focused on modern networking concepts, protocols, and infrastructure relevant to AI and cloud workloads.

Certification

GenAI for SOC Analysts

Certification focused on applying generative AI techniques in Security Operations Center workflows.

Certification

SOC 2 Compliance Essential

Certification covering SOC 2 compliance requirements and audit readiness for cloud service organizations.

What People Say

"
SV
Shyam Venkataraman Executive Director, Software Engineering (Cloud/AI/ML Ops) · Toshiba Direct Manager · April 2026

It is a genuine privilege to recommend Ahmet Koc, who joined our Product Security Engineering team at Toshiba as an intern and very quickly distinguished himself as one of the most promising young engineers I have had the pleasure of working with. He ramped up on complex security topics with remarkable speed, took full ownership of his tasks, and began contributing meaningfully to our cloud security posture in ways that materially improved our visibility into risk. What set him apart was the initiative he showed in stepping up well beyond his assigned scope, organizing and energizing his fellow interns, and elevating the entire cohort experience. Ahmet brings a rare combination of intellectual curiosity, humility, reliability, and quiet leadership. Any team fortunate enough to have him will gain not only a strong product security engineer but a future leader.

"
MF
Marco Ferreira AI/ML, Cybersecurity & Automation/Cloud Specialist · Toshiba Senior Colleague · December 2025

Ahmet is not only smart, but he is committed. He does not allow lack of practice in something deter him from completing a task or initializing a new way to handle things. He goes and does his research, finds the right formula and executes. He doesn't wait for someone to do it for him, he gets the job done, by the deadline set forth. You can't teach that. His knowledge and commitment are unparalleled and to say that he builds relationships wherever he is, is an understatement. Ahmet is truly an asset to any team and no matter what the task is, he communicates, visualizes his end plan and works through everything with deadlines in mind and is never afraid to ask questions.

"
AI
Andrei Ilyushchyts Product Security Engineer · Android & Linux Kernel Security Research Senior Colleague · December 2025

They say not all heroes wear capes, but after working with Ahmet for nearly a year, I'm convinced he's one of them in the cybersecurity world. As our Product Security Intern, Ahmet didn't just 'monitor' our cloud — he became its chief guardian. He has a supernatural ability to spot a misconfigured Azure Storage Access from a mile away and fix it before the rest of us have even finished our morning coffee. What really sets him apart is his ability to translate complex technical jargon into something the rest of the team can actually understand. If you need someone who treats cloud security like a high-stakes chess game (and always wins), hire Ahmet. Solid 11/10 — I'd trust him with our Azure tenants any day!

"
DP
Dmytro Pavlenko Head of Security · Toshiba Direct Manager · December 2025

I have had the privilege of managing Ahmet during his internship as a Security Engineer, and I can confidently say he has been an outstanding addition to our team. Ahmet demonstrated strong analytical skills and a proactive approach in handling security incidents, alerts, and providing actionable recommendations. His ability to quickly assess complex situations, prioritize tasks, and communicate findings clearly made a real impact on our security operations. One of the highlights of his internship was being recognized as the Fall 2025 Intern of the Cohort Award winner, a testament to his exceptional performance and dedication. Beyond technical expertise, Ahmet brought professionalism and a collaborative spirit that made working with him a pleasure.

Thoughts & Write-ups

Breaking down what's happening in cybersecurity — from cloud misconfigurations to AI-powered threats — in plain language.

Let's Connect

I'm always open to discussing security challenges, cloud architecture, or new opportunities. Feel free to reach out.