Cyber-Security · Blockchain · AI

Epaphras M. Makoko

Offensive security practitioner and builder — I break systems to secure them, then ship the tools that defend them.

Dar es Salaam, Tanzania

$6,000

Vodacom bounty

8

certifications

Vodacom

red team

SCROLL
01 / about

About

I'm a cybersecurity professional specializing in penetration testing, vulnerability assessment, secure code review, and DevSecOps — currently running red team engagements for Vodacom Tanzania.

Beyond breaking systems, I build them. From an AI-powered WAF (e-WAF) to centralized threat monitoring (SEMOTO) and BongoShield, I turn offensive-security insight into products that defend real organizations.

I hold a BSc in CyberSecurity and Digital Forensics Engineering and work across the full security spectrum — web, mobile, API, and Active Directory — with a builder's toolkit spanning blockchain and AI.

WHAT I DO

Offensive Security

Web · Mobile · API · AD · Red Team

DevSecOps

SAST/DAST · CI/CD · Threat Modeling

Building

Blockchain · AI/LLM · Security tooling

02 / experience

Experience

  1. Aug 2025 — Present

    Penetration Tester / Red Team

    Vodacom Tanzaniavia Softnet Company

    • Conduct advanced red teaming and penetration testing across networks, applications, and cloud environments.
    • Identify and exploit vulnerabilities, then collaborate with internal teams to strengthen security controls, threat detection, and cyber resilience.
    Red TeamCloudAppSec
  2. Dec 2023 — Jul 2025

    Cyber Security Intern

    e-Government Authority (Ega-RIDC)

    • Assessed security metrics and led tailored security projects across teams.
    • Ran penetration tests and vulnerability assessments; performed code review, threat modeling, and SAST/DAST in CI/CD; hardened container security.
    PentestDevSecOpsThreat ModelingContainer Security
  3. Jul 2023 — Oct 2023

    Practical Training Student

    e-Government Authority (Ega-RIDC)

    • Developed security and automation tools, including a USB Rubber Ducky–style keystroke-injection assessment device.
    • Contributed to the Tanzanite localized operating system's security enhancements and helped build a single sign-on (SSO) solution for enterprise authentication.
    ToolingAutomationSSO

Education

  • BSc, CyberSecurity & Digital Forensics EngineeringUniversity of Dodoma2021 — 2025
03 / skills

Skills

Offensive Security

Web Application PentestingMobile Application PentestingAPI Penetration TestingActive Directory PentestingEthical Hacking & Vulnerability AssessmentMalware Analysis (Static & Dynamic)

DevSecOps

Secure Code Review (SAST & DAST)CI/CD Security AutomationContainer SecurityThreat Modeling

Building

Blockchain / Smart ContractsAI Development (LLM & Machine Learning)Security Tooling & Automation
04 / work

Projects

FEATURED

BongoShield

Founder & Builder

A security product built to shield organizations with intelligence-driven defense.

SecurityIntelligenceAPI
Visit BongoShield
FEATURED

e-WAF

Creator

AI-powered Web Application Firewall for real-time detection and mitigation of web attacks.

AI/MLWeb SecurityWAF
FEATURED

SEMOTO

Co-developer

Centralized monitoring tool for real-time threat detection across systems.

Threat DetectionMonitoring

USB Rubber Ducky

Creator

Custom pen-drive keystroke-injection tool for red teaming and security automation.

Red TeamHardwareAutomation

Smart Cashier System

Developer

Blockchain-based system for transparent, tamper-evident financial operations.

BlockchainSmart Contracts

DevSecOps & Threat-Intel Automation

Contributor

Secure CI/CD pipelines with automated checks, OpenCTI threat-intel integration, and a secure remote screen-sharing tool.

CI/CDOpenCTIAutomation
05 / credentials

Certifications

CAPT
Certified Associate Penetration TesterHackviser
CWSE
Certified Web Security ExpertHackviser
AD-RTS
Active Directory Red Team SpecialistCWL
SAL1
Security Analyst Level 1TryHackMe
Mobile Application Penetration TestingTCM Security
Practical API HackingTCM Security
Practical Web HackingTCM Security
Android Bug Bounty HuntingEC-Council
06 / highlights

Achievements

$6,000
1ST PLACE

Vodacom Live Ethical Hacking Event — 1st Place

Won first place at Vodacom's Live Ethical Hacking Event by discovering and responsibly disclosing critical vulnerabilities.

07 / contact

Get in touch

Open to security engagements, collaboration, and building. Based in Dar es Salaam, Tanzania — working with teams anywhere.

[email protected]