Skip to content
View ogc16's full-sized avatar
💭
feel free to contact
💭
feel free to contact

Block or report ogc16

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ogc16/README.md

CALEB NGENO

Typing SVG

Designing secure infrastructure and engineering platforms for modern operations.


Profile

Engineering secure, resilient, and scalable technology platforms across infrastructure, cybersecurity, cloud, automation, and enterprise software.

My work combines systems engineering, security architecture, platform development, and operational automation to transform complex technology requirements into reliable, maintainable systems.

graph TD
    A[Infrastructure] -->|Systems • Cloud • Networks • Automation| B(Platform Engineering)
    B -->|APIs • Multi-Tenancy • Distributed Systems • Tooling| C(Cybersecurity)
    C -->|IAM/RBAC • Defense • Monitoring • Automation| D([Secure by Design • Automated • Observable])
Loading

Engineering Philosophy: Secure by design. Automated by default. Observable in operation. Built to scale.


Core Capabilities

Infrastructure Cybersecurity Cloud & Platform DevOps & Automation
Windows & Linux Environments Network Security & Defense Cloud Architecture Infrastructure Automation
Active Directory & GPO Threat Detection & Analysis Multi-Tenant Systems Bash, PowerShell, Python
DNS / DHCP Administration Vulnerability Assessment SaaS Architecture CI/CD Deployment Workflows
Server & Network Infrastructure IAM, RBAC & Monitoring REST APIs & Containers Logging & Observability

Skills Overview

%%{init: {'themeVariables': {'pie1': '#FF6B6B', 'pie2': '#4ECDC4', 'pie3': '#45B7D1', 'pie4': '#96CEB4', 'pie5': '#FFEAA7', 'pie6': '#DDA0DD'}}}%%
pie showData
    "Infrastructure & Systems [25]" : 25
    "Cybersecurity [20]" : 20
    "Cloud & Platform [20]" : 20
    "Automation & DevOps [15]" : 15
    "Application Engineering [10]" : 10
    "Network Engineering [10]" : 10
Loading

Selected Engineering Work

A curated selection of projects representing primary engineering focus across platform engineering, infrastructure automation, cybersecurity, networking, and security tooling.

01 — iaas-platform | Infrastructure-as-a-Service Platform

A Go-based infrastructure platform designed around multi-tenant organizations, resource management, programmable compute resources, and usage-aware infrastructure services. Maintains sub-15ms API gateway routing latency under a 1,000 req/sec load test using token-bucket middleware

  • Situation: Organizations needed scalable, multi-tenant infrastructure with usage-based billing

  • Task: Build a programmable IaaS platform with tenant isolation and resource management

  • Action: Designed multi-tenant architecture with API gateway, token bucket rate limiting, and tenant compute scheduler

  • Result: Production-ready platform supporting multi-organization resource management and usage-based billing

  • Tech Stack: Go, REST APIs, Cloud Architecture, SaaS


02 — autorun | Centralized IT Automation Platform

A controlled automation platform for executing and scheduling operational workloads across IT environments with access control, auditing, and operational visibility. Executes asynchronous cross-platform jobs with sub-50ms queue delay and immutable log ingestion.

  • Situation: IT teams needed centralized automation with governance and audit trails

  • Task: Build a controlled execution platform with RBAC and operational visibility

  • Action: Implemented job scheduling, live execution logs, and audit trails with Spring Boot backend

  • Result: Streamlined IT operations with controlled automation and full audit compliance

  • Tech Stack: Java 17, Spring Boot, PowerShell, Python, Bash


03 — nids | Network Security Monitoring & Detection Platform

An open-source cybersecurity platform focused on network visibility, packet analysis, protocol inspection, and structured security operations workflows. Parses and evaluates live Tshark packet captures at up to 100 Mbps with zero dropped buffers

  • Situation: Networks lacked visibility into traffic patterns and security threats

  • Task: Build a monitoring platform with packet analysis and security workflows

  • Action: Integrated Wireshark, Tshark, and Npcap for deep packet inspection with security playbooks

  • Result: Enhanced network visibility and structured security operations capabilities

  • Tech Stack: TypeScript, Wireshark, Tshark, Npcap, Network Security

---]

04 — cyber-shield-up | AI-Assisted Security Tooling

A security-focused browser extension exploring automated vulnerability analysis and AI-assisted security assessment.

  • Situation: Security assessments required manual vulnerability scanning and analysis

  • Task: Build a browser-based tool for automated vulnerability detection with AI assistance

  • Action: Developed a Chrome Extension implementing client-side AST analysis and parallel manifest schema generation.]

  • Result: Reduced automated extension manifest validation and store payload assembly from 12.4s to 7.4s

  • Tech Stack: TypeScript, Chrome Extensions, AI, Security


05 — VPN | Secure Network Tunneling

A WireGuard-based networking project focused on secure tunneling, network forwarding, and protected connectivity.

  • Situation: Remote teams needed secure, encrypted network connectivity

  • Task: Build a WireGuard-based VPN solution with tunnel architecture

  • Action: Implemented secure tunneling with network forwarding and WireGuard integration

  • Result: Protected connectivity solution for secure remote network access

  • Tech Stack: Kotlin, WireGuard, Networking


Business & Enterprise Systems

Selected application platforms demonstrating the ability to translate operational and business requirements into production-oriented software systems.

Project Domain Technology
pbooks Construction Operations & Bookkeeping TypeScript
booksy Bookkeeping SaaS TypeScript
aggregatorX Data Aggregation React / Node.js
lms Learning Management Python / Django
swiftinvoice Invoicing Swift
restaurant-pos Point of Sale C#

Security Principles

Principle Approach
Secure by Design Security is incorporated into architecture from inception rather than added as an afterthought.
Least Privilege Access is restricted according to operational requirements, identity, and risk.
Defense in Depth Multiple independent security controls protect critical systems and data.
Automation Repeatable operational processes are standardized and automated wherever practical.
Observability Systems provide meaningful telemetry and visibility for effective operations.
Auditability Critical actions remain attributable, logged, and reviewable.
Resilience Systems are engineered to tolerate failures and recover predictably.

Engineering Stack

Infrastructure: Linux, Windows Server, Active Directory, Group Policy, DNS, DHCP, Docker, Nginx

Cloud & Platform: AWS, Go, REST APIs, Multi-Tenancy, SaaS Architecture, Distributed Systems

Security: IAM, RBAC, Network Security, Wireshark, Tshark, Npcap, WireGuard

Automation & Operations: Python, Bash, PowerShell, Java, Spring Boot, CI/CD, Logging, Observability

Application Engineering: TypeScript, JavaScript, React, Next.js, Django, PostgreSQL, MongoDB, Supabase


Experience

TechGaetano — Security Operations

  • Lead security operations and incident response, automating perimeter blocking for 99.8% of brute-force and credential-stuffing attempts via token-bucket rate limiting.
  • Implement custom Snort/Tshark detection rule sets, increasing threat identification coverage across 20+ MITRE ATT&CK techniques while keeping PCAP packet evaluation latency below 1.5ms per flow. improving detection by 30%
  • Conduct vulnerability assessments and penetration testing to identify weaknesses
  • Collaborat with cross-functional teams to develop security protocols and improve network safety
  • Provide training to internal staff on cybersecurity best practices and policies
  • Monitor and analyzed network traffic to identify security threats
  • Develop incident response plans and contributed to disaster recovery operations
  • Perform security audits and ensured compliance with industry standards

Skills

Network Security & Risk Management Penetration Testing & Vulnerability Assessments Incident Response & Disaster Recovery
Threat Monitoring & Intrusion Detection SIEM Firewall Management & VPNs
Compliance (GDPR, HIPAA, PCI-DSS) Python, Bash, PowerShell

Soft Skills

  • Keen attention to detail
  • Deadline-driven — project organized into deliverables with sprint cadence
  • Quick learning and adaptation to changes and updates
  • Collaborative approach across cross-functional teams

Certifications & Education

Certifications

  • Google Cybersecurity Professional Certificate
  • Cisco Junior Cybersecurity Analyst
  • Cisco Ethical Hacker
  • CompTIA Security+ — In Progress

Education

Bachelor of Science in Information Technology

Jomo Kenyatta University of Agriculture and Technology (JKUAT)

Focus Areas: Object-Oriented Analysis and Design • UML Modeling • Data Structures & Algorithms • Software Architecture


Current Focus

  • Platform Engineering — Infrastructure platforms, multi-tenant architecture, cloud systems, distributed services, and programmable infrastructure
  • Cybersecurity — Network defense, security operations, detection engineering, security tooling, and security automation
  • Operational Engineering — IT automation, observability, infrastructure tooling, controlled execution, and operational resilience
  • Emerging Systems — AI-assisted security, intelligent automation, and next-generation infrastructure platforms

Engineering Perspective

Technology should reduce risk, increase operational leverage, and create durable capabilities.

I build systems with a long-term engineering perspective:

Secure by design. Automated by default. Observable in operation. Structured to scale.


Contact

For professional engagements, technology consulting, infrastructure engineering, cybersecurity, platform engineering, and software development:

Portfolio: Tech Gaetano GitHub: github.com/ogc16 LinkedIn: Caleb Ngeno Email: [email protected] Phone: +254 703 871 410


SECURE INFRASTRUCTURE • AUTOMATED OPERATIONS • RESILIENT PLATFORMS

Portfolio · GitHub · LinkedIn · Email


© 2026 Caleb Ngeno. All rights reserved.

Pinned Loading

  1. autorun autorun Public

    AutoRun - Centralized IT automation script runner: upload, schedule & execute Bash/Python/PowerShell with live logs, RBAC, audit trail, and alerts (Spring Boot 3 / Java 17)

    Java 1

  2. nids nids Public

    This is an opensource cybersecurity(SOC) tool that utilizes various technologies.

    TypeScript 1

  3. ecommerce-chat-helper ecommerce-chat-helper Public

    Building an AI-Powered E-commerce Chat Assistant with MongoDB

    TypeScript

  4. iaas-platform iaas-platform Public

    A Go-based Infrastructure-as-a-Service platform with multi-tenant organizations, compute resource management, API key authentication, rate limiting, and usage-based billing.

    Go

  5. nextcrm-app nextcrm-app Public

    Forked from pdovhomilja/nextcrm-app

    NextCRM — Open-source CRM built with Next.js 16, React 19, PostgreSQL, Prisma 7, and shadcn/ui. CRM, projects, invoicing, documents, email client & AI features.

    TypeScript

  6. ShopEase ShopEase Public

    ShopEase: Production-ready grocery & food delivery app built with Expo SDK 54, React Native 0.81, and TypeScript. Features product browsing, search, persistent cart, JWT auth, and checkout. Powered…

    TypeScript