profile image
About Me

With a sharp focus on offensive security, penetration testing and cloud security, I bring over 5 years of expertise as a Cyber Security and Application Security Specialist. My passion lies in uncovering vulnerabilities, fortifying cloud infrastructures, and executing strategic penetration tests to ensure robust defense mechanisms. I thrive on the thrill of securing networks against potential threats and leveraging cloud technologies to enhance resilience.

5+Years Experience
10+Certifications
50+Assessments Done
✓ Available
Connect on LinkedIn
TOP SKILLS
~ ls skills/
Offensive Security
Red/Purple Team Ops VAPT Cloud Penetration Testing
AppSec & DevSecOps
Application Security DevSecOps Secure Code Review
GRC & Defensive
Incident Response Threat Intelligence Security Audit Security Policies & Measures Implementing Security Solutions
CERTIFICATIONS & AWARDS
Offensive & DevSecOps
Certified DevSecOps Professional (CDP)
Practical DevSecOps
Offensive & DevSecOps
API Penetration Testing
APIsec University
Offensive & DevSecOps
Mobile Application Security Foundation
NowSecure
Cloud & Network
Cloud and Network Security Analyst
CyberShujaa
Cloud & Network
Cato Certified Associate
Cato Networks
Industry Standard
Certified in Cybersecurity (CC)
ISC2
Vendor
Trellix Certified Architect – ENS
Trellix
Vendor
Ivanti Endpoint Manager Administration
Ivanti
Vendor
Salt Technical Associate
Salt Security
Vendor
JAMF Certified Associate
JAMF
Portfolio

A selection of personal projects and client builds. More on GitHub ↗

Enterprise DevSecOps Pipelines Internal

Enterprise DevSecOps Pipelines

Security built into CI/CD end to end: SCA and SAST gating the build, DAST against running environments, then infrastructure hardening and Compliance-as-Code checks before production — with every scanner's findings pushed into central vulnerability management for triage.

GitLab CI Docker DefectDojo
Private · internal deployment
SSL Expiry Monitor Internal

SSL Expiry Monitor

Tracks TLS certificate expiry across an internal enterprise estate and alerts each application owner once their certificate falls inside a 30-day window, repeating every 2 days until it is renewed. Both thresholds are configurable.

Python TLS/x509 Automation
Private · internal deployment
Kiruh Client

Kiruh

Website design and build for an East African cybersecurity consultancy, covering services, case studies and a blog.

WordPress PHP Responsive
RISQ Pro Client

RISQ Pro

Website development and deployment for a risk management and compliance consultancy.

HTML/CSS JavaScript Deployment
Research Essays Capital Client

Research Essays Capital

Full website design and build for an academic writing services company.

HTML/CSS JavaScript Responsive
Weather App Personal

Weather App

Real-time weather forecasts and a clean dashboard UI, pulling live data from the OpenWeatherMap API.

Python REST API UI Design
Work Experience
Timeline
  • Cyber Security Analyst — Red Team

    Britam Holdings Financial Services

    • Lead red team engagements simulating APT tactics to test enterprise defences across corporate and insurance systems.
    • Conduct internal and external penetration tests on web applications, APIs, and cloud infrastructure.
    • Produce executive and technical risk reports with remediation roadmaps for stakeholder review.
  • Cyber Security Engineer — Assurance Services ⇧ Promoted

    CYBER1 Solutions – East & West Africa Consulting

    • Delivered VAPT engagements for clients across banking, telecoms, and government sectors.
    • Performed security audits aligned to ISO 27001 and CIS benchmarks, producing gap analyses and remediation plans.
    • Supported pre-sales technical scoping and authored detailed security assessment proposals.
  • Cyber Security Engineer — Technical Division

    CYBER1 Solutions – East & West Africa Consulting

    • Deployed and configured security solutions including EDR, SIEM, and network access control for enterprise clients.
    • Performed threat-hunting exercises and tuned detection rules to reduce false-positive alert rates.
    • Provided Tier-2/3 incident response support, leading root-cause analysis and post-incident reviews.
  • Cybersecurity Specialist (OJT)

    eKRAAL Innovation Hub Startup / Research

    • Conducted vulnerability assessments on internal systems and drafted remediation reports for the engineering team.
    • Researched emerging mobile and web application attack vectors as part of the hub's security R&D programme.
  • IT Officer / Systems Administrator

    Kitui County Referral Hospital Government / Healthcare

    • Administered Windows Server and Linux environments, managing user accounts, backups, and patch cycles.
    • Designed and maintained the hospital's LAN/WAN network, reducing downtime by proactive monitoring.
    • Implemented endpoint security policies and trained staff on cybersecurity awareness best practices.
Get In Touch
Send a Message
Let's Work Together
Have a project, an engagement, or just want to connect? Drop me a message.
Contact Info
Location
Nairobi, Kenya
GitHub
Unbound3d
Available for engagements