Imran Al Munyeem
PhD Researcher
PhD Researcher in Computer Science at Nottingham Trent University, specialising in cybersecurity, hybrid cyber range architectures, cyber-physical systems, and AI-assisted security testing. My research focuses on developing secure, scalable, and realistic cyber experimentation and training environments.
-
How would you describe your professional background in a few sentences?
PhD Researcher in Computer Science at Nottingham Trent University, specialising in cybersecurity, hybrid cyber range architectures, cyber-physical systems, and AI-assisted security testing. My research focuses on developing secure, scalable, and realistic cyber experimentation and training environments.
-
What lesson from your first job still guides you today?
My first job as a Software Test Engineer taught me that quality is rarely about finding the obvious defect - it's about questioning the assumptions everyone else takes for granted. Early on, I learned that the most damaging bugs hide in the gap between what a system was specified to do and how people actually use it. That mindset of looking past the happy path and probing where things quietly break has shaped everything since. It's the same instinct that now drives my PhD research into cyber range realism and AI-assisted test regeneration: the value isn't in the tool that works in ideal conditions, but in the one that holds up when reality doesn't cooperate.
-
What does a typical day look like in your role?
My days blend deep technical work with the slower, more deliberate rhythm of research. Mornings usually go to focused work - designing and testing components of my hybrid cyber range architecture, running experiments, or building out the tooling that supports them. Afternoons are more varied: reading and reviewing recent literature, analysing results, writing up findings, and meeting with my supervisors to pressure-test ideas. Alongside the core research, I maintain open-source projects, write technical articles, and prepare work for conferences and publication.
-
What's one piece of advice you'd give to someone building expertise?
Build in public, and build things people can actually use. Early in my career I assumed expertise was something you accumulated privately - courses, certifications, credentials - and then displayed once it was complete. I've come to believe the opposite. Real expertise compounds fastest when you put work into the open: writing about what you're learning, releasing tools others can pick apart and use, and inviting the kind of scrutiny that private study never gives you. It's uncomfortable, because it means being visible before you feel ready. But every article, open-source project, and talk forces a clarity that passive learning can't, and it's the feedback from real users and peers - not the credential itself - that turns competence into genuine depth.
-
What trends are shaping your industry right now?
The defining trend is that AI has become both the tool and the target. On the defensive side, AI-assisted testing is moving from novelty to standard practice - Gartner projects that by 2027, over 40% of penetration testing at large enterprises will incorporate AI-assisted automation. But the same capabilities are arming attackers: generative models now craft near-flawless phishing lures and AI-driven reconnaissance maps entire networks, with attackers using LLMs to generate commands that mimic legitimate activity and evade detection.
-
What values guide your decision-making at work?
Three things guide most of my decisions. The first is rigour over convenience - in both testing and research, the easy answer and the correct one are often different, and I've learned to trust the evidence rather than the assumption. The second is openness: I share my work publicly, release tools others can scrutinise and use, and treat feedback from peers and real users as more valuable than working in isolation. The third is integrity about impact - I care less about whether something looks impressive and more about whether it holds up and genuinely helps the people relying on it. Taken together, these keep me honest: build carefully, work in the open, and measure success by real-world usefulness rather than appearances.
-
What accomplishment are you most proud of?
The accomplishment I'm most proud of is my open-access book, API Testing Using Postman. What makes it meaningful isn't the writing itself but what it represents: taking years of hands-on testing experience and turning it into something freely available for anyone learning the craft. It brings together the practical foundations of modern API testing - scripting, CI/CD automation, mock servers, AI-assisted testing - in a form that removes the paywall so many learners hit. Releasing it openly, with a DOI and a permanent archive, was a deliberate choice: I wanted it to be citable, durable, and genuinely useful rather than just another tutorial. It captures who I try to be professionally - someone who builds carefully and shares generously.
-
What advice would you give to someone just starting out?
Don't rush to specialise before you understand what you're specialising in. When you're starting out, it's tempting to chase whatever's in demand and collect credentials as fast as you can. But the thing that actually compounds is judgment - the ability to tell a real problem from a superficial one, and to know why something works rather than just that it does. Early on, I invested in fundamentals and hands-on practice before titles, and I've never regretted the depth. The other thing I'd say is: be willing to change direction. My own path moved from software testing into research, and the pivot only worked because I treated my earlier experience as a foundation to build on, not a lane to stay in. Stay curious, go deep, and don't be afraid to reinvent what you're aiming for as you learn.
