DDevineSecurity Engineer

Portfolio

Flagship projects

Real implementations over claims. Flagship OrbitDesk — Modern Workplace Operations Lab with 16 tickets, voice, remote desktop, team calls. Plus Chokepoint dual-control security plane, Android Reset Lab, and more. Ordered by depth, starting with OrbitDesk.

5 projects · no blanks52 + 26 tests0 CVEs · strict CSP

How to read these

Status labels are honest: Live demo runs, Simulation / lab models a scenario without touching real systems, and Experimental / WIP didn't fully achieve its vision. Where something is incomplete, I say so — and what it taught.

Modern Workplace Operations Lab — Training environment for IT support

OrbitDesk

Live demo

Professional training environment for Modern Workplace operations — Entra ID, Intune, Exchange, and Teams troubleshooting with realistic tickets, voice communication, remote desktop, and team collaboration. Designed for support engineers and interview preparation.

Security concepts

Modern Workplace OperationsEntra ID and Conditional AccessIntune Device ComplianceExchange and DefenderVoice Communication+3

Built with

Next.js 16 + React 19 + TypeScript + Tailwind CSS + Framer MotionPWA with offline support and installable experienceElectron 32 with security hardening and auto-updateWeb Speech API for voice interaction and Web Audio for telephonyLocal storage with progress persistence — no backend required

Least-Privilege Dual-Control with Tamper-Evident Audit

Chokepoint

Live demo

Security control plane for sensitive operations — least-privilege access control with dual-control approval, hash-chained tamper-evident audit log, anomaly detection, and policy simulation. Designed for human and AI agent operations under OWASP ASI03.

Security concepts

Least PrivilegeDual-ControlTamper-Evident AuditHash ChainingHMAC Integrity+3

Built with

Next.js 16 App Router + TypeScript + VitestCryptography: PBKDF2-SHA256, HMAC-SHA256, SHA-256 hash chainingTamper-evident ledger with integrity verificationDual-control with distinct approver enforcementRole-based access control with default-deny

Security simulation — RBAC, dual-control, and tamper-evident logging

Android Reset Lab

Simulation / lab

Simulation of Android device reset operations with security controls — role-based access, four-eyes dual-control, hash-chained audit logging, and attack detection. Built as isolated lab for security engineering learning.

Security concepts

Security SimulationRBAC and Dual-ControlTamper-Evident LoggingPolicy-as-CodeRisk-Adaptive Auth+1

Built with

Python + pytest + cryptographic controlsMerkle transparency and policy-as-codeRisk-adaptive authenticationWebAuthn and attestationSecurity testing and attack simulation

Android Enterprise management console — simulator and live API integration

Android Device Management Tool

Experimental / WIP

Dual-mode Android Enterprise console with local simulator and live Google Android Management API integration. Manages devices, policies, enrollment, and commands with audit logging.

Security concepts

Android EnterpriseFull-stackAPI IntegrationSecurity-focused

Built with

Next.js + TypeScript + PostgreSQL + Drizzle + Android Management API + OAuth2 JWT

Security engineering portfolio — professional and verifiable

Portfolio

Live demo

Professional portfolio presenting verifiable security work with strict security headers, accessibility, and honest status reporting. Built with Next.js and TypeScript with nonce-based CSP.

Security concepts

Security-minded web developmentAccessibilityHonest engineeringPerformance

Built with

Next.js 16 + TypeScript + Tailwind CSS + Strict CSP + Accessibility

Community health platform — bilingual and privacy-conscious

EndoPima Kenya

Experimental / WIP

Bilingual community platform for endometriosis awareness and care navigation in Kenya. Provides symptom exploration, health timeline, and care guidance with privacy-conscious local-first design.

Security concepts

Health-techBilingual UXCommunity-firstPrivacy-conscious

Built with

HTML, CSS, JavaScript + Bilingual UX + Privacy-conscious design

Want the full story?

How I fixed 15 bugs and cut false positives 14→9, now 52 tests with Argon2id, HMAC, TOTP, SIEM

Read article →