Open to Software Engineering Roles · 2026

Paul
Wambugu

Software Developer · Systems Engineer
Security Practitioner

Building security tooling, systems infrastructure, and open-source developer libraries from Kenya. I run a full offensive security lab on real hardware, maintain a cluster of purpose-built security MCP servers, and ship production code across Python, JavaScript, and C++.

57
SSH tools shipped
20+
Open-source repos
6+
Years coding
4th
Year undergrad
~/ssh-shell-mcp — zsh
❯ ssh_health_check_fleet
web01 ok db01 ok jump01 ok

❯ docker ps --format "{{.Names}}"
dizaster-lab # running

❯ whoami
software developer · systems · security

❯
01 / About

Who I Am

I'm a software developer and security practitioner in my fourth year at Chuka University, pursuing a BSc in Applied Computer Science. I've been writing code for over six years across systems programming, backend engineering, infrastructure automation, and offensive security tooling.

Alongside that I keep a home security lab — a Kali Linux container paired with a set of purpose-built MCP servers — that I use to compete in CTF competitions and sharpen practical offensive-security skills.

My open-source work includes ssh-shell-mcp — a 57-tool Python SSH orchestration library — and headscale-mcp, a server for managing self-hosted VPN infrastructure. Both are production-deployed and actively maintained.

I'm looking for a full-time Software Engineering role where I can contribute immediately — in security, systems, backend engineering, or infrastructure.

PythonBashC++ JavaScriptDockerLinux Kali LinuxCTFTailscale OWASPnmapBurp Suite
Paul Wambugu
// identity.json
NamePaul Wambugu
LocationKenya 🇰🇪
UniversityChuka University
ProgrammeBSc Applied Computer Science
Year4th Year · 2022–Present
Daily MachineUbuntu 24.04 LTS
StatusOpen to full-time roles
02 / Expertise Domains

Four Deep Specialties

These are the four areas I spend most of my time in.

🐚
Shell · Systems

Bash / Shell Engineering

Production-grade Bash and Zsh scripting — cron pipelines, daemon scripts, signal handling, process orchestration. If it runs on Linux, I can automate it. Shell is my first language.

Bash 5Zshcron tmuxawk/sedsystemd
⚙️
Infrastructure · Tooling

Systems & Infrastructure

Building developer tools and infrastructure that runs in production. SSH orchestration libraries, self-hosted VPN control planes, media processing pipelines, and communications servers.

PythonNode.jsDocker TailscaleFastMCPAsyncSSH
🔐
Security · CTF

Offensive Security

Run a Kali Linux lab wired to a set of custom MCP security servers, used to compete in CTF challenges and practice offensive techniques across the MITRE ATT&CK framework.

Kali LinuxOWASPBurp Suite nmapsqlmapWireshark
🎨
Graphics · Design

Graphics & Visual Design

Vector illustrations, UI mockups, system architecture diagrams, and design systems. Design thinking applied to technical communication — making complexity legible.

InkscapeGIMPSVG CSS ArtUI/UXDiagrams
03 / Projects

What I've Built

Projects I've actually shipped and still maintain.

Full-Stack · Node + React + Python

Habitat

A songwriting application built around structured identity reasoning. Three-tier stack: React 18 frontend, Node.js/Express backend with 15 engine modules, Python/Flask ML microservice. 23 REST endpoints, Kiswahili and Sheng language support, lyric analysis toolkit.

ReactNode.jsPython/FlaskML
Open sourceGitHub →
Infrastructure · Python

headscale-mcp

MCP server for managing a self-hosted Headscale control plane — user and node management, pre-auth key lifecycle, subnet route control, and DERP map inspection via the Headscale REST API.

PythonFastMCPHeadscaleTailscale
Open sourceGitHub →
Academic · C++ · Algorithms

Spaghetti Sort

Multi-threaded simulation of the spaghetti sort algorithm in C++ — a physical sorting thought experiment implemented with concurrent threads. Demonstrates thread synchronisation and unconventional algorithm design.

C++17ThreadingAlgorithms
Open sourceView →
04 / Security

Offensive Security Lab

A personal lab I run on real hardware, used for CTF competitions and hands-on security practice.

My security practice runs on toolBOX, a private lab built around a Kali Linux container and a handful of purpose-built MCP servers — one per discipline (web, recon, forensics, crypto, binary exploitation, reverse engineering). It's a working environment, not a demo: I use it to compete in CTF challenges and keep offensive-security skills sharp.

The lab also runs an isolated Docker network hosting OWASP Juice Shop, DVWA, and WebGoat — reachable only over a private Tailscale mesh — for safe, repeatable web exploitation practice.

The results are public even where the tooling isn't: writeups from Z0D1AK CTF forensics challenges are published at zod1ak-writeups, and the general-purpose infrastructure tooling that came out of this lab — ssh-shell-mcp — is open source above.

toolBOX is a private repository under active development. It isn't published as separate MCP servers on GitHub — what's public is the CTF writeups it produces and the standalone open-source tools it spun off.
05 / Roadmap

2026 Portfolio Blueprint

Three projects in active development — designed to prove full-stack, infrastructure, and open-source competency for both Kenyan and global markets.

● In Development

PesaFlow

A real-world fintech application integrating the Safaricom Daraja API for M-Pesa STK Push, C2B, and B2C payment flows. Includes transaction ledger, SMS notifications via Africa's Talking, and an offline-first PWA for low-bandwidth areas.

Stack: Next.js · Node.js · PostgreSQL · Daraja API · AT SMS
Target: Safaricom · Equity Bank · Kenyan Fintechs
○ Planned · Q3 2026

EdgeCache

A benchmarking and observability project for distributed caching. Measures Redis vs in-process caching under load, with a live dashboard showing hit rates, latency distributions, and memory usage.

Stack: Go · Redis · Docker · Grafana
Target: Performance-focused engineering roles
⬡ Open Source

daraja-sdk

A typed, modular Node.js/Python SDK for the Safaricom Daraja API — the M-Pesa integration layer every Kenyan developer has had to re-implement from scratch. Full ISP compliance, retry logic, and webhook signature verification.

Stack: TypeScript · Python · npm · PyPI · GitHub Actions
Target: Kenyan dev community · Open Source
06 / Engineering Philosophy

SOLID by Design

Every project in this portfolio is architected around these principles — not as theory, but as working code decisions.

S
Single Responsibility
Each module does one thing. In ssh-shell-mcp, file ops, tunnelling, and fleet tools are split across isolated Python modules. In toolBOX, each security discipline has its own server.
O
Open / Closed
New payment providers in PesaFlow extend a base PaymentGateway interface — no existing code is modified. The Strategy pattern makes this natural.
L
Liskov Substitution
Any CacheBackend implementation (Redis, in-memory, file) is fully substitutable in EdgeCache — same interface, no surprises at the call site.
I
Interface Segregation
ssh-shell-mcp's 57 tools are grouped into focused interfaces: FileOps, SessionManager, TunnelManager — consumers depend only on what they use.
D
Dependency Inversion
High-level modules depend on abstractions. daraja-sdk's HTTP layer is injected — swap the client or mock it in tests without touching business logic.
07 / Tech Stack

Tools of the Trade

Bash / Zsh
Python 3.12
Node.js / ESM
C++17
PHP 8
TypeScript
React 18
Go (learning)
Docker
Docker Compose
Linux · Ubuntu
Tailscale / WG
Caddy
PostgreSQL
FastMCP
AsyncSSH
Git · GitHub
Kali Linux
Burp Suite
nmap · sqlmap
Wireshark
Ghidra · radare2
binwalk · hashcat
Inkscape
GIMP
Redis
08 / Local Edge

Built for Kenya

Understanding the local tech ecosystem is a competitive advantage. These are the competencies that matter for Kenyan engineering roles — from Safaricom to early-stage startups.

M

Daraja API (M-Pesa)

STK Push, C2B, B2C, and account balance integrations. The payment layer behind nearly every Kenyan product — I'm building a typed SDK to make it accessible to every developer.

📡

Africa's Talking

SMS, USSD, and voice integrations for low-bandwidth, feature-phone-first markets. Building for real Kenyan network conditions, not ideal ones.

🔒

Security Culture

Kenya's growing fintech and data sectors need security practitioners who understand local threat models. My lab and CTF practice are directly applicable to this gap.

🌍

Open Source for Africa

Building reusable SDKs and tooling that other Kenyan developers can use — reducing duplicated work across the ecosystem and raising the baseline for everyone.

09 / Contact

Get in Touch

I'm actively looking for full-time Software Engineering opportunities in security, systems engineering, backend development, or infrastructure. If you're building something real in Kenya or globally — let's talk.