Final-year Computer Science undergraduate — University of Nairobi. Security engineering: threat detection, SIEM, and network hardening.
- 🛡️ Cybersecurity intern @ Communications Authority of Kenya — Wireshark, Splunk SIEM, T-Pot honeypot, ACLs & network hardening, threat detection and log analysis
- 🖥️ Current ICT attachment @ Ministry of Education
- 🔬 Home labs in SIEM / threat detection (Wazuh) and vulnerability assessment & hardening
- ⚙️ I also build the backends I'd want to defend — Django/DRF and Next.js, with a focus on the failure modes rather than the happy path
Open to security and engineering work → paulandrewochieng@gmail.com
wazuh-siem-home-lab — single-node Wazuh SIEM
Deploying and operating a SIEM end to end: threat detection, log analysis, and alerting.
amd-ai-hackathon-agent — token-efficient AI agent
Built for the AMD Developer Hackathon (ACT II, Track 1). 100% evaluation accuracy, designed around completing the task in the fewest calls rather than the longest chain.
mpesa-stk-django — M-Pesa payment integration (Django + DRF)
▶ Live demo: mpesa-stk-demo.onrender.com — click through a working payment flow in about thirty seconds. (Free instance: the first request after a quiet period takes ~45s to wake.)
Safaricom Daraja STK Push built for what goes wrong: idempotent webhook handling, a recovery path for callbacks that never arrive, timeout sweeping for abandoned payments, and reconciliation reporting. 16 passing tests, including one that fires a duplicate callback carrying a different receipt number and asserts nothing gets double-credited.
Payment webhooks are a good place to think like an attacker — replay, duplicate delivery, and out-of-order events are the same class of problem whether they're accidental or deliberate.
mpesa-stk-demo — the same service in Next.js/TypeScript
Built twice deliberately. The interesting part isn't the framework, it's handling the retries and dropped callbacks that behave identically in both.
Security monitoring · SIEM (Wazuh, Splunk) · Threat detection & log analysis ·
Network configuration & hardening · Vulnerability assessment · Linux
Security — Wireshark · Wazuh · Splunk · T-Pot · Nmap · Linux (Ubuntu, Kali) · Docker Engineering — Python · Django / DRF · PostgreSQL · TypeScript · Next.js
📫 paulandrewochieng@gmail.com · Nairobi, Kenya (GMT+3)
Final-year CS student · resuming September 2026