Kevin
Gitau.
IT operations and application support engineer with a cybersecurity track. Six years keeping distributed systems healthy across enterprise networks, regulated fintech, and IoT at scale, with every incident owned from first alert through post-mortem.

Two disciplines, built in parallel. The core is production systems and cloud infrastructure: Azure-hosted platforms, distributed IoT, and application support under real commercial pressure. Security is the second, built deliberately alongside: SIEM engineering, penetration testing, and Active Directory defense. Alongside both, I build and ship independent products.
Read moreProduction support for a cloud-hosted SaaS platform blending software services with connected IoT hardware endpoints.
- Cut operational overhead 40% through targeted automation
- Administered Azure + Entra ID across the platform estate
- Ran container security assessments with Trivy and Docker Scout
- Maintained observability via Grafana + Prometheus
Part-time consultancy running production support for regulated US fintech trading platforms across staging and production. Held alongside full-time roles, with dedicated evening and weekend coverage windows.
- Reduced incident recurrence 25% through structured post-mortems
- Cut engineering escalation response time 20%
- Owned SQL root-cause analysis and end-to-end QA
Monitoring and reliability for a distributed IoT platform across 3,000+ field endpoints.
- MTTR: 11 min → 3 min via Python automation
- 98% uptime across 3,000+ IoT endpoints
- 50% faster troubleshooting through improved tooling
24/7 NOC monitoring of enterprise ISP infrastructure across OLTs, core nodes, and backhaul.
- 99% SLA adherence across enterprise accounts
- 24/7 continuous coverage across the OLT estate
End-to-end IT support and Windows Server administration as the organisation's primary technical contact.
- Administered Active Directory, Group Policy, and Hyper-V

Wazuh SIEM deployed across Linux and Windows hosts. Custom detection rules, multi-source log ingestion, Grafana dashboards, and a structured analyst investigation workflow.
Monitoring, incident response, and customer-facing support across production platforms.
Administering cloud estates and identity across Azure and AWS.
Detection engineering, API and network testing, and Active Directory defense.
Automation and independent product builds, end to end.
Detailed documentation covering detection engineering, penetration testing, network security, and Active Directory.