$ cat profile.txtOffensive Security Engineer and Penetration Tester based in Nairobi, Kenya.
Expertise in bug bounty research, vulnerability & malware research, and red team operations.
I find the gaps before attackers do — then help organizations close them for good.
- 🔴 Red teaming payment & authentication platforms at Durrafx
- 🐛 Hunting bugs across web, API, and mobile targets on HackerOne
- 🔐 SOC operations & log analysis at Foresight Tech Group
- 📖 Deepening expertise in mobile app security and malware analysis
OffensivePenetration TestingRed TeamingBug BountyVulnerability ResearchMalware AnalysisSocial Engineering
DomainsWeb SecurityAPI SecurityMobile SecurityNetwork SecurityFinancial Systems
Frameworks & StandardsOWASPPTESPCI-DSSMITRE ATT&CK
Languages & ToolsPythonGoBashBurp SuiteDockerMetasploitWiresharkNmapSIEM
DefensiveLog AnalysisIncident ResponseThreat ModelingIDS/IPSSecure Code Review
| Project | Description | Stack |
|---|---|---|
| ARP | ARP spoofing tool — intercepts DNS traffic and exfiltrates to a remote server | Python, Scapy |
| PhoneBook-Vault | All possible Kenyan phone number combinations for OSINT/recon use | Data |
| Note-Weave | Minimal, elegant note-taking app | JavaScript |
🖊️ Writeups & disclosures coming soon — follow to stay updated.
$ cat availability.txt
✓ Open to penetration testing engagements
✓ Available for red team operations ✓ Bug bounty collaborations welcome
✓ Security consulting & advisory📬 Reach me at njerumtwaiti@proton.me or connect on LinkedIn.


