-- Sharjeel Khan has received a 2026 Global Recognition Award for Innovation, recognizing cybersecurity work that improves how organizations evaluate and act on software-security findings. The recognition reflects his work in secure development leadership, open-source tooling and incident-response guidance, all of which are designed to connect technical evidence with accountable risk decisions. His efforts focus on a central operational challenge: security teams must assess large volumes of alerts while identifying the exposures that warrant immediate attention.

Photo Courtesy of Sharjeel Khan
Khan leads a secure software development life cycle programme for a major public-infrastructure client, where software weaknesses can affect essential services, organizational resilience and public confidence. His approach brings vulnerability analysis into established engineering and security workflows, while retaining the professional judgment required when teams make risk-based decisions. The wider cybersecurity environment is becoming more complex as artificial intelligence changes both defensive processes and attacker capabilities.
Building A Clearer Triage Process
Khan architected an AI-powered security-finding triage system that integrates GitHub Advanced Security, DefectDojo and Dependency-Track within a unified operational process. The system uses tree-sitter abstract syntax tree reachability analysis, CSAF and Microsoft Security Response Center vulnerability intelligence, alongside Exploit Prediction Scoring System data. This combination gives analysts information beyond a single severity rating, because it connects code-level evidence with current intelligence and projected exploit likelihood.
A high-severity finding does not always represent the most immediate operational concern, whereas a reachable weakness with credible exploitation indicators may require urgent remediation. Khan’s system helps teams determine whether vulnerable code is reachable in a relevant environment and whether the available intelligence points to a meaningful likelihood of exploitation. The process is structured to reduce time spent on findings that do not need immediate intervention, while maintaining traceable evidence for each prioritization decision.
“A severity rating is valuable, but it cannot independently establish the practical urgency of a security finding,” said Sharjeel Khan. “Analysts need context about reachability, exploit likelihood and the affected environment, so they can direct their attention to the weaknesses that could have the greatest operational effect.” EPSS is designed to estimate the probability that a reported vulnerability will be exploited within the next 30 days, which can complement conventional severity assessments.
Making Security Methods Reusable
Khan expanded this work through ghas-assess, an open-source GitHub Advanced Security posture-assessment tool that evaluates the adoption and configuration of security capabilities across enterprise repositories. The tool enables organizations to identify inconsistent security practices across broad software portfolios, while supporting a more structured view of programme maturity. Its open-source model allows practitioners to review the method, adapt it to their own operating environments and apply a shared framework for improvement.
“Security programmes require approaches that can be used consistently across many repositories and delivery teams,” Khan said. “A clear assessment process helps leaders identify where capabilities are uneven, and it gives teams a more practical basis for strengthening their security practices.” The tool supports the wider objective of making security data useful to people responsible for technical delivery and organizational oversight.
Khan also wrote Cybersecurity Incident Response Playbooks: Detection, Containment, Recovery, and Forensics in the AI Era, which examines incident-response practices in an environment shaped by artificial intelligence. The book addresses detection, containment, recovery and forensic discipline, while considering how AI can influence both attack methods and defensive operations. His professional preparation includes CISM, ISACA Advanced in AI Security Management and Microsoft Certified Cybersecurity Architect Expert certifications, which support his work across governance and security architecture.
Final Words
“Sharjeel Khan has earned this recognition because he applies technical depth to practical cybersecurity problems and develops methods that organizations can use to make more rigorous decisions,” said Alex Sterling, spokesperson for Global Recognition Awards. “His work helps security teams identify relevant threats, prioritize their response and preserve a clearer record of why action was taken.” The recognition considers a record that combines secure development leadership, an open-source contribution and published guidance.
Global Recognition Awards assessed Khan’s work through an expert screening process and a Rasch model that provides a linear measurement scale for comparing achievements across award categories. His contributions address the gap between security information and timely action because they are intended for people responsible for protecting complex software environments. The award recognizes innovation that can be applied within operational security and engineering programmes.
About Global Recognition Awards
Global Recognition Awards is an international organization that recognizes exceptional companies and individuals who have significantly contributed to their industry.
Contact Info:
Name: Alexander Sterling
Email: Send Email
Organization: Global Recognition Awards
Website: https://globalrecognitionawards.org
Release ID: 89202683

Google
RSS