Skip to main content
Security-first systems

Build · Scale · Secure · Validate

Jozbert James Bhoyi

$ role: "systems_engineer"; stack: ["saas", "distributed", "off_sec"];

I build and harden systems that survive real traffic and real threats.

I take products from architecture to production: reliable backends, clear APIs, and security that holds up when it matters. I also pentest web apps and APIs so you can fix critical issues on your timeline, not after an incident.

I design systems to scale, then test them the way an attacker would, so shipping fast does not cost you trust.

Systems

Built for load, failure, and change

Architecture and implementation choices driven by throughput, failure modes, and operability, so growth does not force a rewrite every year.

Business

Ship faster without gambling uptime

Clear boundaries and pragmatic delivery mean fewer production surprises, less rework, fewer outages, and a scaling path that finance and operations can plan around.

Security

Find the break paths early

Defense in depth across design and code, plus structured web pentesting that surfaces exploitable issues, misconfigurations, and logic flaws before they reach users.

Shipping is not the finish line. Operating securely at scale is.

I optimize for observability, resilience, and explicit trust boundaries. Where the risk warrants it, I test the attack surface the way an attacker would (within agreed scope and rules of engagement), so remediation happens on your schedule.

What I Do

Engineering and security, end to end

System Architecture & Design

  • Backends and platforms designed for growth and fault isolation
  • Service boundaries, contracts, and multi-tenant-aware design
  • APIs that teams can integrate without guesswork

Full-Stack Development

  • React frontends with production-grade structure and performance
  • Django, REST and GraphQL-style APIs, and disciplined service layers
  • End-to-end ownership from schema to deployment

Performance & Scalability

  • Latency, throughput, and cost trade-offs made explicit
  • Resilience patterns: availability, backoff, and graceful degradation

Security Engineering

  • Authentication stacks (such as JWT and MFA) and session hardening
  • Authorization models: RBAC, least privilege, and enforcement points
  • Threat modeling and architecture reviews that catch design-level risk

Web Penetration Testing

  • Web applications and APIs assessed against real attack patterns (OWASP-aligned)
  • Findings ranked by evidence and impact, with clear fix guidance
  • Retesting after remediation when scope allows

Auditing & Maintenance

  • Code and architecture reviews focused on risk and maintainability
  • Performance and reliability investigations with actionable results
  • Security-oriented reviews that complement pentesting rather than replace it

Featured Work

Live platforms in production

Live product Retail SaaS · POS · Inventory · Cloud sync

Stooqo

POS, inventory, and cloud sync for African SMEs

Hands-on engineering on a live retail platform used in the field. Shops run point of sale, stock control, and sync across devices in one system, built for real connectivity and day-to-day retail constraints.

  • Role: product engineering on a deployed retail stack (POS, inventory, and sync)
  • Technical: multi-context sync, identity-aware access, and APIs shaped around store workflows
  • Impact: SMEs run daily sales and stock on one system, with fewer stockouts and faster checkout
  • Delivery: security- and scale-aware decisions that stay simple for store staff
View live platform
Live platform Cybersecurity · CTF · Training

NeboCTF

Cybersecurity training and CTF platform for Nebotech

A live Capture The Flag platform built for Nebotech to support practical cybersecurity learning, hands-on challenges, and skills development. I was the engineer behind it.

  • Role: engineer for Nebotech, responsible for design, development, and deployment
  • Focus: hands-on challenges that build applied security skills
  • Ongoing: continued technical evolution of the live platform
View live platform

For Sale

Platforms and services available

Live product Tourism & NGO Platform

FahariYetu

A full-stack web platform for tourism and NGO work, supporting community projects, listings, and visitor engagement.

  • Built for tourism and NGO operations
  • Community project listings and visitor engagement
  • Deployed for real-world production use
For sale E-commerce Platform

E-commerce Platform

A production-ready e-commerce platform built for premium lifestyle brands. The design, branding, and features can be restructured to fit each client.

  • Ready-to-deploy e-commerce foundation
  • Customizable design, branding, and structure
  • Adaptable to any product category or client vertical
Consultation Services

Security Audit Package

A security audit of your web applications and APIs, with detailed findings and recommendations.

  • Full assessment report
  • Remediation plan
  • Follow-up support
Custom pricing Get a quote

How I Work

How engagements run

1

Align on outcomes

Goals, constraints, risk appetite, and what “done” means for your users.

2

Shape the architecture

Boundaries, contracts, data ownership, and failure modes, made explicit early.

3

Build in iterations

Small, shippable slices with observability, so behavior is visible in production.

4

Harden and verify

Authorization, hardening, and reviews, plus targeted pentesting when it adds signal.

5

Hand off cleanly

Measure, tune, and document, so operators and the next engineer are not left guessing.

Engineering · Assessment · Advisory

Tell me what you are building, or what needs testing

Whether you need delivery, a scoped web assessment, or both, share the context, timeline, and constraints. I will reply with a concrete next step, not a generic pitch.

Request a reply

Used only to respond to this inquiry.

Email me directly · +255 695 613 653

info@therealjozbert.com