Selected Work

Projects

Featured case studies come first. Client-private repositories are presented with public-safe outcomes and architecture context.

Project deep dives and delivery evidence for security-focused hiring.

I structure this page so you can quickly understand the challenge, my execution approach, the technologies used, and the measurable outcomes.

Security priorities

Identity, cloud, endpoint, and network defense

I align architecture and implementation to measurable risk reduction so your team gets stronger controls and clearer operating evidence.

Delivery priorities

DevSecOps reliability and safe rollouts

I build deployment and monitoring workflows that protect uptime while maintaining security guardrails and rollback confidence.

Client priorities

Production-ready platforms with practical support

I build secure, responsive web platforms and keep the operational layer reliable through DNS, SSL/TLS, hosting, and server management.

Case Studies

01

Project deep dives

Case studies are structured to help hiring teams quickly assess scope, implementation quality, and measurable outcomes.

01

Security deep dive

Zero-Trust Access Hardening Program

Problem or challenge

The organization had inconsistent identity controls across Azure and Microsoft 365, which increased account takeover risk.

My role and specific actions

  • I mapped privileged and non-privileged access paths, then rebuilt role-based access around least privilege.
  • I implemented Conditional Access, MFA enforcement, and legacy-authentication blocking with staged rollout checkpoints.
  • I documented onboarding/offboarding and access-review playbooks so your team could sustain the controls after launch.

Tools used

  • Microsoft Entra ID (Azure AD)
  • Conditional Access
  • Microsoft Sentinel
  • PowerShell

Quantifiable outcome: Reduced high-risk sign-in exposure by 32% and cut excessive permissions by 19% within one quarter.

02

Security deep dive

Firewall and Segmentation Modernization

Problem or challenge

Open and legacy firewall rules made it difficult to prove approved access paths and increased lateral-movement risk.

My role and specific actions

  • I analyzed traffic flows and rebuilt firewall policy around business-approved ports, services, and trust boundaries.
  • I implemented VLAN segmentation for staff, guest, IoT, and server zones, then validated packet flow with rollback plans.
  • I created a repeatable review cadence and change-control documentation for policy lifecycle management.

Tools used

  • Fortinet
  • Palo Alto
  • Wireshark
  • Network ACL and VLAN design

Quantifiable outcome: Reduced external firewall exposure by 25% while preserving production connectivity and support SLAs.

03

Security deep dive

DevSecOps Platform Rollout and Monitoring

Problem or challenge

A multi-service platform needed safer deployments, stronger runtime observability, and clear incident-response workflows.

My role and specific actions

  • I implemented CI/CD quality gates, security checks, and controlled rollout sequencing for reliable releases.
  • I standardized containerized service deployment patterns, reverse-proxy security headers, and health/readiness checks.
  • I built operational runbooks so your team could triage incidents quickly with consistent evidence.

Tools used

  • Jenkins
  • Docker and Docker Compose
  • Nginx
  • SIEM and monitoring workflows
  • Terraform

Quantifiable outcome: Improved release reliability by 40% and lowered mean time to detect critical runtime issues by 35%.

Featured

02

Best evidence for target roles.

Projects selected to show security architecture, network defense, production ownership, automation, and operational follow-through.

01

AI Security Operations / SOC Automation

2026

Project role · Designer and Developer

Intelligent Security Alert Triage Engine

Built an intelligent security alert triage engine with Python 3.11 and Streamlit. The system ingests SIEM-style alerts, classifies true and false positives, assigns risk and severity, maps relevant events to MITRE ATT&CK techniques, and writes enriched audit records for analyst follow-through.

What this demonstrates

  • Implemented LLM-assisted triage with structured JSON validation, retry handling for malformed output, and deterministic fallback classification when AI services are unavailable.
  • Added SOC workflow acceleration features: plain-English incident summaries, response recommendations, and evidence-preserving audit logs for suspicious PowerShell, brute-force, malware, phishing, and privilege-escalation patterns.
  • Delivered production-style engineering quality with modular architecture, pytest coverage, ruff quality gates, and GitHub Actions CI for reliable local and pipeline execution.

Project screenshots

Streamlit dashboard overview for the Intelligent Security Alert Triage Engine showing ingestion controls and recent alerts table.
Dashboard overview: ingest alerts, filter classification, and review triage outcomes.
Classification distribution and criticality timeline charts from the Intelligent Security Alert Triage Engine.
Triage analytics: classification distribution and criticality timeline.
  • Python 3.11
  • Cybersecurity Automation
  • SIEM Alert Triage
  • MITRE ATT&CK
  • Wazuh
  • Elasticsearch
  • Local LLM Inference
  • Prompt Engineering
  • Streamlit
  • REST APIs
  • JSON
  • Pandas
  • Pytest
  • Ruff
  • GitHub Actions
  • Structured Logging
  • Risk Scoring

02

Cloud Security / IAM / Sentinel

2026

Project role · Designer and Implementer

Azure Hybrid Network and IAM Security Architecture

Enterprise-style hybrid security architecture for an education environment. The project combines segmented Azure VNets, simulated on-prem connectivity, Entra ID governance, Conditional Access, RBAC, MFA, and Microsoft Sentinel detections.

What this demonstrates

  • Designed two VNets, eight subnets, VPN Gateway connectivity, and 15+ NSG rules to separate Staff, Students, Servers, and gateway traffic.
  • Implemented 30 governed identities across Staff, Student, and IT Admin groups with MFA, blocked legacy authentication, compliant-device requirements, and least-privilege RBAC.
  • Documented Sentinel and Log Analytics detections for failed logins, risky sign-ins, and authentication review using KQL-backed alert logic.
  • Microsoft Azure
  • Microsoft Entra ID
  • Conditional Access
  • MFA
  • NSG
  • VPN Gateway
  • Microsoft Sentinel
  • KQL
  • Azure CLI

03

Network Security / Segmentation

2024

Project role · Lab Architect

Enterprise Network Segmentation and Security Lab

Network-defense case study focused on segmentation, firewall policy design, and validation. It models how staff, student, guest, IoT, VoIP, and server traffic should be isolated and tested in an enterprise environment.

What this demonstrates

  • Mapped topology, trust boundaries, and approved flows so firewall rules are tied to business purpose instead of open-ended access.
  • Modeled guest and IoT isolation to reduce lateral-movement risk across unmanaged devices and user groups.
  • Created a repeatable validation approach for firewall policy design, packet-flow testing, rollback, and Wireshark evidence.
  • Cisco
  • Fortinet
  • VLAN
  • Site-to-Site VPN
  • Wireshark
  • Firewall Policy Design

04

DevSecOps / Full-Stack / Operations

Ongoing

Project role · Owner, Founder, and Lead Engineer

Private or client repository

Neotha - Owner-Led Platform, Client Support, and Server Operations

Owner-led technology platform and client-service work where I build frontend and backend systems, support customers, manage hosting/server environments, and apply secure deployment habits to live business platforms.

What this demonstrates

  • Deliver production websites and client systems with React/Next.js, TypeScript, backend integration, SEO metadata, responsive UI, and accessibility-aware interfaces.
  • Manage DNS, SSL/TLS, hosting configuration, deployment troubleshooting, uptime support, and customer requests for live services.
  • Apply security-minded operations: environment separation, dependency hygiene, least-privilege access, backups, documentation, and careful change management.
  • Next.js
  • TypeScript
  • React
  • Tailwind CSS
  • Backend Integration
  • DNS
  • SSL/TLS
  • Server Management
  • Hosting
  • DevSecOps

05

Security Operations / Automation

2023

Project role · Operations Engineer

Private or client repository

Network Monitoring and Security Automation Initiative

Monitoring and automation initiative shaped around real support work: availability signals, security follow-up, stale-account review, event-log collection, and repeatable documentation for faster troubleshooting.

What this demonstrates

  • Used SolarWinds/PRTG-style monitoring patterns to centralize availability and operational security signals.
  • Built PowerShell workflows for provisioning review, stale-account checks, event-log collection, and access-audit follow-up.
  • Improved repeatability with documented checks that reduce manual workload and make security follow-through easier to hand off.
  • SolarWinds
  • PRTG
  • PowerShell
  • Event Logs
  • Access Review
  • Security Auditing
  • User Lifecycle Automation

Supporting

03

Client delivery and engineering foundations.

Additional work that demonstrates customer support, production discipline, full-stack ownership, and technical range.

06

Client Platform / Full-Stack Delivery

Ongoing

Project role · Full-Stack Developer and Server Manager

Private or client repository

Nkurunziza - Client Web Platform and Hosting Support

Client-facing web platform delivered with frontend/backend ownership, hosting, and operational support. This project demonstrates client communication, production reliability, deployment discipline, and secure server-management habits.

What this demonstrates

  • Built and maintained a live web experience with clean navigation, responsive UI, and public-facing business reliability.
  • Handled deployment, DNS/SSL alignment, hosting configuration, server updates, and customer support for ongoing operations.
  • Applied practical security controls around access, backups, change discipline, and production troubleshooting.
  • Frontend Development
  • Backend Support
  • Responsive UI
  • Hosting
  • DNS
  • SSL/TLS
  • Server Management
  • Client Support

07

Client Website / Hosting Operations

Ongoing

Project role · Full-Stack Developer and Server Manager

Private or client repository

Sylva Renovations - Client Website and Hosting Operations

Client website built and maintained for Sylva Renovations, with professional frontend delivery, backend/hosting support, SSL/TLS configuration, DNS alignment, and ongoing production troubleshooting.

What this demonstrates

  • Delivered a clean public-facing website that presents the client professionally and works across desktop and mobile screens.
  • Handled hosting setup, DNS, SSL/TLS, deployment updates, and operational support for the live business site.
  • Applied the same security-minded habits I use in IT work: controlled access, careful changes, backups, documentation, and reliable client communication.
  • Frontend Development
  • Responsive UI
  • Backend Support
  • Hosting
  • DNS
  • SSL/TLS
  • Server Management
  • Client Support

08

Product Engineering / Data Workflow

2026

Project role · Full-Stack Developer

Private or client repository

Expense Tracker - Roommate Receipt and Cost-Sharing App

Private full-stack application for shared household expenses. The app is designed around receipt upload, monthly review, total tracking, and cleaner cost-splitting between roommates.

What this demonstrates

  • Organized a real workflow around uploads, totals, monthly review, and shared accountability instead of manual tracking.
  • Shows practical product thinking: user input, data capture, privacy-sensitive records, and clear monthly summaries.
  • Adds backend/data-handling experience that supports secure web and DevSecOps positioning.
  • TypeScript
  • Frontend Development
  • Backend Integration
  • File Upload
  • Data Modeling
  • Privacy-Aware Handling
  • GitHub

09

DevSecOps / CI/CD / Portfolio

2026

Project role · Developer and Maintainer

Portfolio - Next.js Static Export and GitHub Pages Pipeline

This portfolio is maintained as a professional public GitHub project using Next.js, TypeScript, static export, GitHub Actions, and GitHub Pages deployment under the /portfolio path.

What this demonstrates

  • Configured one clean public repository for hiring review with a GitHub Pages deployment workflow and static export output.
  • Built recruiter-focused case-study pages with direct links, resume download, responsive navigation, dark mode, and no fake contact backend.
  • Verified linting, production builds, route base paths, metadata, and generated static assets for Pages hosting.
  • Next.js
  • TypeScript
  • React
  • Tailwind CSS
  • GitHub Actions
  • GitHub Pages
  • Static Export
  • SEO Metadata

10

Programming Fundamentals / GitHub Practice

2023

Project role · Developer

Python Engineering Foundations

Public Python projects that show core programming fundamentals: formatting, date/time logic, probability simulation, object-oriented geometry, and budget/category tracking.

What this demonstrates

  • Built small, readable Python utilities with testable logic and clear problem boundaries.
  • Practiced object-oriented design, data formatting, arithmetic rules, probability simulation, and command-line style problem solving.
  • Maintains a public GitHub trail of programming foundations that supports broader engineering credibility.
  • Python
  • Object-Oriented Programming
  • Data Structures
  • Simulation
  • Testing
  • Git
  • GitHub

If these outcomes align with your security goals, let's discuss your role or project scope.