Skip to content
View Nyaenya-Devine's full-sized avatar

Block or report Nyaenya-Devine

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Nyaenya-devine/README.md

Devine Nyaenya — Security Engineer • Modern Workplace Operations

Building security systems that prove they are secure — with tests, audit logs, threat models, and verifiable controls.

📍 Nairobi, Kenya · Portfolio · LinkedIn · devinenyaenya@gmail.com


Featured Projects

Live: https://orbitdesk-gamma.vercel.app

Training simulator for Modern Workplace support — Entra ID Conditional Access, Intune compliance, Exchange quarantine, Teams troubleshooting. Features ticket queue with SLA tracking, What-If policy simulation, sign-in log investigation, remote desktop with audit logging, voice communication, and team collaboration.

  • 16 realistic ticket templates across Entra ID, Intune, Exchange, Teams
  • Three client profiles with distinct policies and compliance requirements
  • Student Mode for progressive learning, Expert Mode for full complexity
  • PWA + Electron desktop, Web Speech API voice, offline support

Live: https://chokepoint-demo.vercel.app

Least-privilege access control with tamper-evident audit for sensitive operations. Every high-impact action requires a second distinct authorized approver.

  • HMAC-signed, SHA-256 hash-chained audit log — tamper-evident
  • Dual-control approval with 15-minute expiry and break-glass
  • Role-based access (admin, operator, auditor, viewer)
  • Policy simulation, anomaly detection, SIEM export
  • 26 routes, TypeScript strict, Electron hardened build

Security Labs

Project Focus Live
Android Reset Lab MDM reset controls — RBAC, Merkle transparency, Cedar ABAC, WebAuthn, 68 tests, 6/6 attacks detected Demo
Android Device Management Android Enterprise — simulator + live Management API, QR enrollment, compliance policies Demo
EndoPima Kenya Health-tech — bilingual EN/SW endometriosis early-recognition, privacy-first Demo

What I Build

Security: AppSec, access control, tamper-evident audit, threat modeling, attack simulation, Merkle transparency, Cedar ABAC, WebAuthn, Play Integrity

Modern Workplace: Microsoft 365, Entra ID Conditional Access, Intune compliance, Exchange Online, Teams, SLA/CSAT/QA, ITIL

Stack: Next.js 16 App Router, TypeScript strict, Tailwind CSS, Python, PostgreSQL, Web Crypto, PWA, Electron, Vercel

Method: Build → Test → Break → Learn → Secure. Every repository includes tests, audit logs, security policy, and threat model.


Live Demos


GitHub Stats

Stats Top Languages


Open to: Modern Workplace Team Lead, Security Engineer, AppSec, Detection Engineering roles — Nairobi / Remote

© 2026 Devine Nyaenya — Security-first engineering

Pinned Loading

  1. chokepoint chokepoint Public

    Least-privilege dual-control access plane — HMAC-signed hash-chained audit, 4-eyes approval, break-glass

    TypeScript 2 1

  2. android-reset-lab android-reset-lab Public

    Android MDM reset security lab — RBAC, dual-control, Merkle transparency, Cedar ABAC, WebAuthn detection

    Python 1