About

Ibrahim El-Radi.

I build things with AI agents, then I try to break them.

I have spent 14 years in security. Detection engineering, incident response, network defense, cloud, and offensive work. Most of it in places where a mistake costs something real, so I got used to asking a plain question about every system I met: does this actually hold, or does it only look like it does.

In 2020 I started Beit Systems, a B2B engineering firm. Since June 2025 I have been at Microsoft as an AI agent developer and principal security engineer, the only agent builder on a 30-person security engineering team. I built and run the internal agent development platform there, security-first by default.

Ibrahim Builds is the public side of that work. I build real things with AI agents, and I test how well they actually hold up.

The main thing I do

Evaluating and stress-testing AI agents.

Most agent demos are shown working once. That is the easy run. The interesting part is the tenth run, the run with bad input, and the run where somebody is actively trying to break it.

So I put agents and AI products through real test builds. Not a prompt and a screenshot, a whole job from start to finish. Then I check the things that decide whether it was worth using: is the output accurate, does the thing it built actually work when you run it, and where does it fail quietly instead of loudly. Quiet failure is the expensive kind, because nobody notices until it is already in production.

The security side is the same question with sharper edges. I test prompt injection defenses, tool use and sandbox escape, and the trust boundaries between the operator, the agent, its tools, and whatever text arrives from the outside world. I look at capability scoping and default-deny permissions, at per-tenant isolation, and at whether there is a kill switch a human can actually reach when the agent is mid-run.

At Microsoft I lead a small team building AI pentesting agents that validate internal applications on their own and surface the gaps they find. I also built an AI Model Security Scanner: automated vulnerability detection, model lineage tracking, and AI-specific attack path analysis across machine learning pipelines.

Zoro is the same question in product form. It exists to prove whether an agent's controls actually held, with independent evidence rather than the agent's own account of what it did.

Teaching

Sunday mornings, for a cohort of career changers.

From December 2023 to March 2024 I taught a live introductory cloud and cybersecurity class, weekly on Sunday mornings, for about three months. Sessions ran two and a half hours or more.

The students were career changers, taught as a cohort. We covered AWS fundamentals with hands-on labs, some Azure including Azure Kubernetes Service, and a real amount of career coaching: resumes, LinkedIn profiles, and how to actually apply for roles.

Teaching beginners is where I learned to explain this work without jargon. If you cannot say it plainly to someone on a Sunday morning who is changing careers and has a full week behind them, you do not understand it well enough yet. That is why the starter kits on this site are free, and why they are written for someone who has never opened a terminal.

See the free kits

The record

The rest of it.

The full career history, the roles, and the education are on LinkedIn.

Certifications: CISM, PMP, Azure Solutions Architect Expert, Azure Administrator Associate, PSM-I, CEH, Security+, Network+, CCSKv4.

Work with Beit Systems