I am a Cybersecurity Engineer specializing in DevSecOps, Application Security, Cloud Security, SOC Operations, Threat Intelligence, and Infrastructure as Code Security.
With a background in Telecommunication Engineering, I now focus on securing applications, CI/CD pipelines, and cloud environments (AWS & Azure), while building automated security controls across the SDLC.
I enjoy uncovering vulnerabilities, automating detections, and creating secure-by-design systems.
To design, build, and automate secure systems by integrating security into every stage of the development lifecycle.
I work across:
- DevSecOps & AppSec
- SOC & Incident Response
- Threat Intelligence & Automation
- Cloud Security (AWS & Azure)
- Secure IaC & Terraform
| Skill | Description |
|---|---|
| DevSecOps | Secure CI/CD pipelines, automated security tools |
| AppSec | SAST, DAST, SCA, threat modeling, code security |
| Cloud Security | AWS & Azure IAM, monitoring, infrastructure hardening |
| Security Automation | Python/Node automation, detection engineering |
| Threat Intelligence | IOC analysis, attacker behavior research |
| SOC & IR | Log analysis, threat hunting, detection techniques |
| IaC Security | Terraform secure deployments, cloud security posture |
DevSecOps Pipeline
A comprehensive CI/CD security pipeline integrating automated security scanning tools.
View Project →
Terraform — S3 Static Website
Infrastructure as Code for deploying secure static websites on AWS S3.
View Project →
Terraform — AWS Webserver
Automated AWS webserver deployment with security best practices.
View Project →
Terraform — AWS IAM Multi-User Management
Scalable IAM user and group management using Terraform modules.
View Project →
Intentionally Vulnerable Auth API
Educational project demonstrating common authentication vulnerabilities and secure coding practices.
View Project →
- LinkedIn: Richard Ndung'u
- Medium: @richardndungu
- Email: Contact me
Building secure systems, one commit at a time