Michael Ted Ndeda

Cybersecurity Analyst | GRC | Security Assurance

Michael Ted Ndeda

ISO/IEC 27001:2022 Lead Auditor Cybersecurity Analyst SOC & Risk

Cybersecurity professional focused on compliance, security assurance, SOC operations, and risk-based control design for real business environments.

BSc Information Security & Forensics — KCA University

🎖 Current role: Lead Security and Compliance Officer — Stratnovo Agency

About Me

Cybersecurity Analyst and GRC professional working across compliance, risk, security assurance, and SOC operations. My work focuses on helping organisations translate regulatory obligations and operational risk into practical, implementable security controls.

I currently support client-facing security and compliance work, including ISO/IEC 27001 delivery, hardening review, and governance documentation, while continuing to build depth in incident response, threat analysis, and control validation.

  • Network Security & Ethical Hacking
  • SIEM Tools & Security Operations
  • Firewall, VPN & Endpoint Security
  • Incident Triage & First-line Support
  • Digital Forensics (Autopsy)
  • Technical Documentation & Reporting

Practical Projects

Active

SOC Operations Lab

Production-grade home SOC on VMware Workstation: multi-phase detection engineering lab with real attack telemetry. ARTEMIS architecture spans pfSense firewall, AD DC, Windows workstation, and integrated security stack.

Outcome: builds a repeatable detection environment for validating alerts, triage flow, and analyst response across simulated attack behavior.

Limitation: lab-scale log volume and tooling; not yet tested against production traffic or large enterprise telemetry.

  • Splunk
  • TheHive
  • Cortex
  • OpenCanary
  • Sysmon
  • Ubuntu Server
View on GitHub
Active

ISMS Suite

ISO/IEC 27001:2022 ISMS template suite — 10-document MSSP client onboarding package. Covers all 93 Annex A controls, Kenya DPA 2019, risk assessment, SoA, policies, procedures. Production-ready for SME deployment.

Outcome: packages governance artifacts for clients in a form that can be used for risk treatment, documentation review, and control mapping.

Limitation: designed for SME-ready implementation contexts rather than deeply regulated enterprise programs with large-scale control libraries.

  • ISO 27001
  • GRC
  • Risk Assessment
  • ISMS
  • Compliance
View on GitHub
Active

Sentry

Autonomous multi-agent offensive security tool. Generates real attack telemetry against the SOC Lab for detection engineering and ISMS documentation. Built on LangGraph for orchestrated attack simulation.

Outcome: creates adversary simulation flows that help bridge offensive testing and defensive tuning in a single feedback loop.

Limitation: focused on controlled lab scenarios rather than full-spectrum production adversary emulation or live red-team operations.

  • LangGraph
  • Red Team
  • Autonomous Agents
  • Python
  • Offensive Security
View on GitHub

Technical Skills

Networking & Security

  • TCP/IP
  • DNS & DHCP
  • Firewall Configuration
  • VPN Setup
  • Cisco Umbrella
  • WHOIS Lookups
  • Domain Reconnaissance

Systems & Tools

  • Splunk
  • TheHive & Cortex
  • Wireshark
  • Nmap
  • Metasploit
  • OpenCanary
  • Sysmon
  • Autopsy

Cloud & Scripting

  • Azure Fundamentals
  • Python
  • LangGraph
  • Bash
  • Technical Documentation
  • Incident Reporting

GRC & Compliance

  • Risk Assessment
  • Security Awareness Training
  • Data Protection Act 2019
  • Computer Misuse Act 2018
  • ISO 27001 Awareness

Education & Professional Training

Education

  • KCA University
  • BSc Information Security and Forensics
  • Second Class Upper Division Honours

Professional Training & Certifications

  • ISO/IEC 27001:2022 Lead Auditor (Mastermind, Apr 2026)
  • Microsoft Cybersecurity Analyst (Microsoft, May 2026)
  • SOC Analyst Learning Path (LetsDefend, May 2026)
  • Penetration Testing Professional Certificate (Cybrary, May 2026)
  • VirusTotal Fundamentals (Virustotal, Jul 2026)
  • Certified Cyber Core Associate (Ubuntu Bridge Initiative, Jul 2026)
  • KC7 Cybersecurity Investigation: Clout Defender (KC7 Foundation, Jul 2026)
  • Windows Event Logs & Finding Evil (HTB, Apr 2026)
  • Security Monitoring & SIEM (HTB, Apr 2026)
  • AI Skills Fest 2026 – Information Security Track (Microsoft, Jun 2026)
  • Ethical Hacking (Cisco, Sep 2025)
  • Network Security (Cisco, Nov 2023)
  • CCNA: Introduction to Networks (Apr 2023)
  • CCNA: SRWE (Sep 2022)

Professional Experience

Aug 2026 – Present Contract

Lead Security and Compliance Officer

Stratnovo Agency

  • Deliver ISO/IEC 27001:2022 and Kenya Data Protection Act 2019 compliance packages for client projects and technical bids.
  • Review client systems prior to handover, identify control gaps, and recommend practical hardening actions to reduce risk.
  • Provide security and risk-management input into proposals, technical reviews, and governance documentation for digital transformation work.
May 2026 – Present Seasonal

Cyber Security Risk and Certified Protection Officer

Ubuntu Bridge Initiative

  • Completed a five-stage SOC analyst internship with a 90/100 score, covering kill-chain reconstruction, insider threat analysis, breach notification drafting, and remediation planning.
  • Led investigation work across a live-fire breached fintech scenario, including log and authentication trail analysis, C2 detection, and incident lifecycle documentation.
  • Produced board-level risk memos, risk registers, and 30/60/90-day remediation roadmaps to support executive understanding and operational response.
May 2026 – Jul 2026 Internship

Security Operations Center Analyst

The Root Access Network (T.R.A.N)

  • Worked through a structured SOC analyst track focused on insider threat investigation, SIEM correlation, and web application vulnerability assessment.
  • Correlated SIEM tickets to identify post-offboarding access abuse and data exfiltration patterns, then produced a formal analyst brief.
  • Reviewed a web application assessment covering 11 vulnerabilities including SQLi, XSS, SSRF, XXE, and broken authentication, mapping findings to OWASP 2021 and CWE with CVSS 3.1 scoring.
Apr 2025 – Aug 2025 Internship

Intern — IT Infrastructure Management

The National Treasury, Kenya

  • Supported implementation of cybersecurity controls aligned to the PFM ICT Information Security Policy 2024, including VPN configuration and firewall rule validation.
  • Helped maintain secure access for IFMIS users and resolved connectivity issues affecting critical financial systems.
  • Contributed to infrastructure support, endpoint hardening, and compliance implementation tied to data protection and cybercrime legislation.

Industry Simulations

Apr 2026 Forage Simulation

AIG — Shields Up

Forage

  • Threat analysis and vulnerability remediation recommendations
  • Built Python brute-force decryption script for credential security assessment
Apr 2026 Forage Simulation

Tata — Cybersecurity Analyst

Forage

  • Comprehensive threat analysis and vulnerability remediation aligned with risk frameworks
Apr 2026 Forage Simulation

PwC US — Cyber Security Consulting

Forage

  • Risk assessment, Test of Design & Operating Effectiveness, controls gap analysis
Apr 2026 Forage Simulation

Datacom — Cyber Security Operations

Forage

Mar 2026 Forage Simulation

Deloitte Australia — Cyber

Forage

  • Enterprise log analysis, networking fundamentals, and IAM security architecture
Mar 2026 Forage Simulation

Mastercard — Cybersecurity

Forage

  • Phishing threat analysis and targeted security awareness training programme design

Certifications & Badges

  • ISO/IEC 27001:2022 Lead Auditor Mastermind Assurance · Issued April 2026 · Valid through April 2029
    Certified
  • Microsoft Cybersecurity Analyst Microsoft · Issued May 2026
    Completed
  • SOC Analyst Learning Path LetsDefend · Issued May 2026
    Completed
  • Penetration Testing Professional Certificate Cybrary · Issued May 2026
    Completed
  • VirusTotal Fundamentals VirusTotal · Issued Jul 2026
    Completed
  • Certified Cyber Core Associate Ubuntu Bridge Initiative · Issued Jul 2026
    Completed
  • KC7 Cybersecurity Investigation: Clout Defender KC7 Foundation · Issued Jul 2026
    Completed
  • Windows Event Logs & Finding Evil HackTheBox Academy · Issued Apr 2026
    Completed
  • Security Monitoring & SIEM HackTheBox Academy · Issued Apr 2026
    Completed
  • Ethical Hacker Cisco NetAcad · Sep 2025
    Cisco Badge
  • CCNA: Introduction to Networks Cisco NetAcad · Apr 2023
    Cisco Badge
  • SC-500: Microsoft Cybersecurity Architect Microsoft · Active queue item · Voucher deadline Oct 18, 2026
    In Progress

Portfolio Artifacts

Comprehensive documentation of investigations, risk assessments, detection engineering, and job simulation results. All materials stored in Google Drive with full credential trails.

🔍

SOC and Detection

SIEM detection rules, threat hunting queries, incident reports, and log analysis documentation.

View Folder
🛡️

Governance and Risk

Risk assessments, ISMS frameworks, Statement of Applicability, and compliance documentation.

View Folder
📋

Work Simulations

Datacom risk register, PwC consulting analysis, Mastercard phishing report, and all Forage deliverables.

View Folder
📚

Reflection and Methodology

Project reflections, detection engineering methodology, MITRE ATT&CK mappings, and learning outcomes.

View Folder

Contact

Open to security consulting, governance, SOC, detection engineering, and DevSecOps collaboration opportunities. Based in Nairobi, Kenya. Let's connect.