Profile // Ahura
About
An independent security practice built on one conviction: a business should be able to bloom without getting compromised.
I'm Ahura. I run AhuraIntel — an independent security practice built on one conviction: a business should be able to bloom without getting compromised. Security that strangles productivity is bad security. Productivity that ignores risk is borrowed time. My work lives exactly on that line, and I refuse to trade one side away silently.
The short version
I'm a cybersecurity engineer by training (BSc, Tallinn University of Technology, Estonia), a former SOC analyst at a major Nordic telecom, a former startup founder, and — before any of that — a systems administrator and a B2B sales manager in Kuala Lumpur. I'm currently completing an MA in International Relations in Istanbul, because I've learned that the hardest security problems aren't technical. They're problems of governance, incentives, and trust.
That mix isn't an accident, and it isn't padding. It's the whole product.
Four crafts, one operator
Security operations and governance. I've sat in the SOC chair — monitoring, triaging, and responding to live incidents across enterprise infrastructure, and building the detection and incident-response playbooks a team actually uses under pressure. On the governance side, I work with risk frameworks (NIST CSF, ISO-family thinking, OWASP for the engineering lifecycle) the way they're meant to be used: calibrated to the organization's real stakes, not maximal for their own sake.
Engineering. I write code and I've shipped products. As co-founder and CEO of Apogee Code OÜ in Tallinn, I recruited and led an international development team, wrote the company's information security policy from scratch, built our vulnerability-management process, and directed a penetration test against our own mobile app before we shipped it. I don't advise on systems I couldn't build.
Sales. Before security, I spent years closing high-ticket B2B deals and building sales teams in Malaysia. That taught me something most security consultants never learn: nobody buys risk reduction. They buy speed, confidence, and revenue — and security has to be sold, internally and externally, in that language.
Marketing and communication. Much of my current work is translation: making technical risk legible to people who will never read a packet capture — executives, policymakers, ordinary users. If a security program can't be explained plainly, it won't be followed, and a control nobody follows is a control that doesn't exist.
How I work: the 80/20 rule
Every engagement starts with the same question: what is the 20% of work that removes 80% of the risk — or unlocks 80% of the value? I do that first, name what I'm deliberately deferring and why, and I put the trade-off in writing. You'll never get a 200-page report designed to impress rather than decide. You'll get the shortest path to a materially safer, faster organization, with the residual risk stated honestly.
Where the work points
I've watched, up close, what happens when digital infrastructure fails people — including a national-scale internet shutdown that cut an entire population off from work and family for months at a stretch. It convinced me that firewalls can't fix broken policy. So alongside client work, I research and write about how states and organizations under sanctions, isolation, or resource constraints build cyber-resilience anyway — and I teach security to people who will never write a line of code. You'll find both threads in the writing and research sections of this site.
The record, briefly
- BSc Cybersecurity Engineering, Tallinn University of Technology (TalTech), Estonia — thesis on VPN solutions for peer-to-peer content delivery under network restrictions
- MA International Relations, Beykent University, Istanbul (completing September 2026)
- SOC Analyst, Telia Company, Tallinn — enterprise incident monitoring, triage, and response
- Co-founder & CEO, Apogee Code OÜ — Tehnopol startup incubator, Starteridea national competition finalist
- ICT Systems Administrator, five years, Kuala Lumpur — servers, networks, SIEM, EDR, backup and disaster recovery
- Independent security consultant since 2023, formalized as AhuraIntel
Full detail, including certifications, is on the credentials page.
If your organization needs to move faster and sleep better — those are the same project. Get in touch.