About
whoami Link to heading
I’m Njeru Mtwaiti — a Cyber Security Engineer with a focus on Application Security, Red Teaming, and Malware Research, working in the Fintech industry from Kenya.
I believe the best defence starts with thinking like an attacker. By understanding how systems break, I build security measures that are practical, resilient, and built for real-world pressure — not just compliance checkboxes.
Currently leading security operations at Durrafx, securing Durrapay’s production infrastructure — a Payment Service Provider platform handling transactions for individual and business clients across borders. I also volunteer my offensive security skills with Protect.ngo, helping non-profits stay safe against adversaries with far more resources.
Experience Link to heading
Cyber Security Engineer — Durrafx (Oct 2025 – Present · Remote)
- Leading security for Durrapay, a PSP handling cross-border FX transactions
- Hardened production network access via VPN and automated firewall controls
- Secured customer-facing APIs against bots, Tor traffic, and web attacks using Cloudflare
- Identified and remediated a critical account takeover flaw and broken payment integrations
Platform Engineer — Durrafx (Mar 2025 – Oct 2025 · Hybrid)
- Designed and built DurraPay, a custom Payment Service Provider system
- Integrated secure payment workflows and APIs for individuals and business clients
Information Security Engineer — Foresight Tech Group (Oct 2025 – Jul 2026 · On-site)
- SIEM rule tuning to reduce false positives and eliminate false negatives
- IDS/IPS, Firewall, and VPN implementation and management
- Log analysis across FW, IDS, Windows DC, Cisco, AV, and antimalware sources
- Incident escalation to the designated response team
Security Analyst — Pay Hero Kenya (Jan 2025 – Aug 2025 · Remote)
- Monitored and analyzed security incidents, vulnerabilities, and threat alerts
- Supported risk assessments, audits, and vulnerability evaluations
- Contributed to security policy and best practice implementation
Bug Bounty Researcher — HackerOne (Jan 2024 – Present)
- Web application and API security testing with a focus on fintech and betting platforms
- East African market attack surfaces
- Responsible disclosure of authentication, authorization, and payment-flow vulnerabilities
Cyber Security Volunteer — Protect.ngo (Jul 2026 – Present · Remote)
- Staff security awareness training: phishing, password hygiene, sensitive data handling
- Penetration testing on internal applications and user-facing systems
- Practical, low-cost security recommendations for non-profit constraints
Education Link to heading
Kenyatta University — B.Sc. Computer Science (Aug 2021 – Jul 2026)
Certifications Link to heading
- Cisco Ethical Hacking — Networking Academy (Feb 2025)
- Qualys Cloud Agent (Jul 2026 · Expires Oct 2028)
- Android Bug Bounty Hunting
- Backend & API Development — freeCodeCamp
- Pursuing: OSCP, eJPT
Skills Link to heading
- Offensive Security
- Web App Pentesting, Red Teaming, API Security, Mobile Security Research, Malware Development, Kubernetes Security
- Defensive / SOC
- SIEM Administration (Wazuh, Splunk), IDS/IPS, Firewall Management, Incident Response, Vulnerability Assessment
- Tools
- Burp Suite, Metasploit, nmap, sqlmap, ffuf, gobuster, Impacket, BloodHound, Cloudflare WAF, Qualys
- Languages
- Python, Go, Bash, PowerShell, JavaScript, C
What Colleagues Say Link to heading
“Njeru is a highly skilled red teaming engineer with a strong research focus, ensuring that security is maintained throughout the execution of operations. He is particularly dedicated to safeguarding the banking sector.” — Warren Gakuo, Information Security Analyst · ISO 27001 Champion
“What truly sets him apart is his curiosity and deep desire to understand why systems behave the way they do — not just that a vulnerability exists. He approaches security testing methodically, digging beneath the surface to uncover root causes and realistic attack paths.” — Albert Waweru, Security Researcher
Organizations Link to heading
Member — Kenya Cyber Security and Forensic Association
This Blog Link to heading
Where I document the work: CTF writeups, fintech security breakdowns, SOC notes from the field, tool walkthroughs, and methodology posts. Written to be useful — to future-me or to anyone else going down the same path.