Open to Software Engineering Roles · 2026
Software Developer · Systems Engineer
Security Practitioner
Building security tooling, systems infrastructure, and open-source developer libraries from Kenya. I run a full offensive security lab on real hardware, maintain a cluster of purpose-built security MCP servers, and ship production code across Python, JavaScript, and C++.
I'm a software developer and security practitioner in my fourth year at Chuka University, pursuing a BSc in Applied Computer Science. I've been writing code for over six years across systems programming, backend engineering, infrastructure automation, and offensive security tooling.
Alongside that I keep a home security lab — a Kali Linux container paired with a set of purpose-built MCP servers — that I use to compete in CTF competitions and sharpen practical offensive-security skills.
My open-source work includes ssh-shell-mcp — a 57-tool Python SSH orchestration library — and headscale-mcp, a server for managing self-hosted VPN infrastructure. Both are production-deployed and actively maintained.
I'm looking for a full-time Software Engineering role where I can contribute immediately — in security, systems, backend engineering, or infrastructure.
These are the four areas I spend most of my time in.
Production-grade Bash and Zsh scripting — cron pipelines, daemon scripts, signal handling, process orchestration. If it runs on Linux, I can automate it. Shell is my first language.
Building developer tools and infrastructure that runs in production. SSH orchestration libraries, self-hosted VPN control planes, media processing pipelines, and communications servers.
Run a Kali Linux lab wired to a set of custom MCP security servers, used to compete in CTF challenges and practice offensive techniques across the MITRE ATT&CK framework.
Vector illustrations, UI mockups, system architecture diagrams, and design systems. Design thinking applied to technical communication — making complexity legible.
Projects I've actually shipped and still maintain.
A Python SSH orchestration library exposing 57 structured tools for programmatic infrastructure control — one-off commands, persistent sessions, fleet broadcasting, tunnelling, SFTP, tmux, and playbooks. Async connection pool, built-in audit trail, and a security policy gate. Production-deployed and open source.
A songwriting application built around structured identity reasoning. Three-tier stack: React 18 frontend, Node.js/Express backend with 15 engine modules, Python/Flask ML microservice. 23 REST endpoints, Kiswahili and Sheng language support, lyric analysis toolkit.
MCP server for managing a self-hosted Headscale control plane — user and node management, pre-auth key lifecycle, subnet route control, and DERP map inspection via the Headscale REST API.
Multi-threaded simulation of the spaghetti sort algorithm in C++ — a physical sorting thought experiment implemented with concurrent threads. Demonstrates thread synchronisation and unconventional algorithm design.
A personal lab I run on real hardware, used for CTF competitions and hands-on security practice.
My security practice runs on toolBOX, a private lab built around a Kali Linux container and a handful of purpose-built MCP servers — one per discipline (web, recon, forensics, crypto, binary exploitation, reverse engineering). It's a working environment, not a demo: I use it to compete in CTF challenges and keep offensive-security skills sharp.
The lab also runs an isolated Docker network hosting OWASP Juice Shop, DVWA, and WebGoat — reachable only over a private Tailscale mesh — for safe, repeatable web exploitation practice.
The results are public even where the tooling isn't: writeups from Z0D1AK CTF forensics challenges are published at zod1ak-writeups, and the general-purpose infrastructure tooling that came out of this lab — ssh-shell-mcp — is open source above.
Three projects in active development — designed to prove full-stack, infrastructure, and open-source competency for both Kenyan and global markets.
A real-world fintech application integrating the Safaricom Daraja API for M-Pesa STK Push, C2B, and B2C payment flows. Includes transaction ledger, SMS notifications via Africa's Talking, and an offline-first PWA for low-bandwidth areas.
A benchmarking and observability project for distributed caching. Measures Redis vs in-process caching under load, with a live dashboard showing hit rates, latency distributions, and memory usage.
A typed, modular Node.js/Python SDK for the Safaricom Daraja API — the M-Pesa integration layer every Kenyan developer has had to re-implement from scratch. Full ISP compliance, retry logic, and webhook signature verification.
Every project in this portfolio is architected around these principles — not as theory, but as working code decisions.
Understanding the local tech ecosystem is a competitive advantage. These are the competencies that matter for Kenyan engineering roles — from Safaricom to early-stage startups.
STK Push, C2B, B2C, and account balance integrations. The payment layer behind nearly every Kenyan product — I'm building a typed SDK to make it accessible to every developer.
SMS, USSD, and voice integrations for low-bandwidth, feature-phone-first markets. Building for real Kenyan network conditions, not ideal ones.
Kenya's growing fintech and data sectors need security practitioners who understand local threat models. My lab and CTF practice are directly applicable to this gap.
Building reusable SDKs and tooling that other Kenyan developers can use — reducing duplicated work across the ecosystem and raising the baseline for everyone.