Selected projects, case studies, and research.
Full-scope red team engagement against a 500-user financial institution. Achieved domain admin via spear-phishing + lateral movement within 48h. Delivered hardening roadmap.
Security assessment of a multi-account AWS environment for a West African telecom operator. Identified 47 misconfigurations across IAM, S3, and VPC. Implemented CSPM tooling.
Led end-to-end ISO 27001 certification project for a telecom company (850 employees). Designed ISMS scope, drafted 42 security policies, and coordinated the certification audit.
Led post-breach investigation following a ransomware attack on a manufacturing company. Identified patient zero, traced lateral movement, recovered 98% of data from backups.
Redesigned security architecture of a hybrid VSAT/IP network for a regional ISP in Central Africa. Deployed pfsense cluster, IDS/IPS, and ALLOT traffic management.
OWASP Top 10 assessment of a SaaS platform including REST API, OAuth2 flows, and infrastructure. Found SSRF and privilege escalation vulnerabilities pre-launch.
Built a COBIT®-aligned security governance framework for a financial institution, including KPI/KRI dashboards, monthly security board reports, and security committee charter.
Investigated SIM-swap fraud and insider threat case at a mobile operator. Correlated CDRs, network logs, and access logs. Delivered evidence package for legal proceedings.
Collaborate
Whether you need a pentest, a risk assessment, or a full security programme — let's talk.
▶ Contact Me