About

whoami Link to heading

I’m Njeru Mtwaiti — a Cyber Security Engineer with a focus on Application Security, Red Teaming, and Malware Research, working in the Fintech industry from Kenya.

I believe the best defence starts with thinking like an attacker. By understanding how systems break, I build security measures that are practical, resilient, and built for real-world pressure — not just compliance checkboxes.

Currently leading security operations at Durrafx, securing Durrapay’s production infrastructure — a Payment Service Provider platform handling transactions for individual and business clients across borders. I also volunteer my offensive security skills with Protect.ngo, helping non-profits stay safe against adversaries with far more resources.


Experience Link to heading

Cyber Security Engineer — Durrafx (Oct 2025 – Present · Remote)

  • Leading security for Durrapay, a PSP handling cross-border FX transactions
  • Hardened production network access via VPN and automated firewall controls
  • Secured customer-facing APIs against bots, Tor traffic, and web attacks using Cloudflare
  • Identified and remediated a critical account takeover flaw and broken payment integrations

Platform Engineer — Durrafx (Mar 2025 – Oct 2025 · Hybrid)

  • Designed and built DurraPay, a custom Payment Service Provider system
  • Integrated secure payment workflows and APIs for individuals and business clients

Information Security Engineer — Foresight Tech Group (Oct 2025 – Jul 2026 · On-site)

  • SIEM rule tuning to reduce false positives and eliminate false negatives
  • IDS/IPS, Firewall, and VPN implementation and management
  • Log analysis across FW, IDS, Windows DC, Cisco, AV, and antimalware sources
  • Incident escalation to the designated response team

Security Analyst — Pay Hero Kenya (Jan 2025 – Aug 2025 · Remote)

  • Monitored and analyzed security incidents, vulnerabilities, and threat alerts
  • Supported risk assessments, audits, and vulnerability evaluations
  • Contributed to security policy and best practice implementation

Bug Bounty Researcher — HackerOne (Jan 2024 – Present)

  • Web application and API security testing with a focus on fintech and betting platforms
  • East African market attack surfaces
  • Responsible disclosure of authentication, authorization, and payment-flow vulnerabilities

Cyber Security Volunteer — Protect.ngo (Jul 2026 – Present · Remote)

  • Staff security awareness training: phishing, password hygiene, sensitive data handling
  • Penetration testing on internal applications and user-facing systems
  • Practical, low-cost security recommendations for non-profit constraints

Education Link to heading

Kenyatta University — B.Sc. Computer Science (Aug 2021 – Jul 2026)


Certifications Link to heading

  • Cisco Ethical Hacking — Networking Academy (Feb 2025)
  • Qualys Cloud Agent (Jul 2026 · Expires Oct 2028)
  • Android Bug Bounty Hunting
  • Backend & API Development — freeCodeCamp
  • Pursuing: OSCP, eJPT

Skills Link to heading

Offensive Security
Web App Pentesting, Red Teaming, API Security, Mobile Security Research, Malware Development, Kubernetes Security
Defensive / SOC
SIEM Administration (Wazuh, Splunk), IDS/IPS, Firewall Management, Incident Response, Vulnerability Assessment
Tools
Burp Suite, Metasploit, nmap, sqlmap, ffuf, gobuster, Impacket, BloodHound, Cloudflare WAF, Qualys
Languages
Python, Go, Bash, PowerShell, JavaScript, C

What Colleagues Say Link to heading

“Njeru is a highly skilled red teaming engineer with a strong research focus, ensuring that security is maintained throughout the execution of operations. He is particularly dedicated to safeguarding the banking sector.”Warren Gakuo, Information Security Analyst · ISO 27001 Champion

“What truly sets him apart is his curiosity and deep desire to understand why systems behave the way they do — not just that a vulnerability exists. He approaches security testing methodically, digging beneath the surface to uncover root causes and realistic attack paths.”Albert Waweru, Security Researcher


Organizations Link to heading

Member — Kenya Cyber Security and Forensic Association


This Blog Link to heading

Where I document the work: CTF writeups, fintech security breakdowns, SOC notes from the field, tool walkthroughs, and methodology posts. Written to be useful — to future-me or to anyone else going down the same path.

Contact me · Browse posts · See my projects