Mugeha Jackline

Mugeha Jackline

Cybersecurity Engineer
0 (0 Reviews)

About me

I break applications to understand how to secure them, and build security in before attackers get a chance. I focus on application security, with a strong interest in web and API security, as well as secure system design. My work sits at the intersection of how applications are built and how they can be broken. I’ve done hands-on testing of web and API-based systems, focusing on authentication flaws, broken access control (including IDOR), misconfigurations, and common vulnerabilities mapped to the OWASP Top 10(both Mobile and Web) and API Security Top 10. I’m comfortable using tools like Burp Suite, Postman, MobSF, Nmap, Metasploit, and curl to identify, validate, and document security issues. Beyond offensive testing, I care about secure design and risk awareness. I’ve worked with secure API authentication mechanisms and understand the importance of governance and reporting in regulated environments. I can translate technical findings into clear, structured security reports that decision-makers can act on.

I’m continuously building my skills through hands-on labs, real-world scenarios, and deep dives into modern attack surfaces. I document what I learn and stay focused on practical, real-world security, not just theory.
I’m actively exploring opportunities in Application Security, Product Security, and Security Engineering, where I can grow under strong mentorship while contributing a security-first mindset.

Work Experience

Cybersecurity Trainee
AfricaHackon 2025-07-14 - Application and API Security Testing - Identified IDOR, broken authentication, and input validation flaws in RESTAPIs, producing risk-rated reports with remediation guidance that could directly inform a development team's security backlog. -Executed structured API testing using BurpSuite, Postman, and curl following the OWASP API Security Top 10 framework, the same methodology used in enterprise bug bounty and red team engagements. -Delivered penetration testing reports formatted for both technical and non-technical audiences, demonstrating the ability to communicate risk to engineering leads and business stakeholders. Secure Backend and Authentication Engineering - Built JWT-based authentication with role-based access control(RBAC), mirroring the access management patterns used to protect enterprise APIs and internal tooling. - Hardened API endpoints through middleware-level authorization, input validation, and structured error handling, reducing attack surface inline with OWASP Secure Coding Practices. Threat Profiling and Incident Readiness - Mapped attack vectors and threat actor profiles for simulated environments, producing outputs aligned with MITRE ATT&CK, a skill directly applicable to enterprise threat intelligence and red team planning. - Developed incident readiness strategies for simulated breach scenarios, building foundational capability for SOC-level triage and response workflows
API Security Analyst Intern
Cybersafe Foundation 2025-11-15 - 2026-02-28 API Security Training and Hands-On Testing - Completed a structured program covering API security from fundamentals to advanced exploitation, building the depth expected of an application security engineer in an enterprise security team. - Performed targeted testing for IDOR, broken object-level authorization, and improper input validation, vulnerability classes that appear in the majority of enterprise API security audits. - Applied OWASP API Security Top 10 methodology consistently across engagements, ensuring findings map to a recognized framework that integrates with enterprise GRC and risk management processes. Tool Proficiency and Practical Exposure - Used BurpSuite, Postman, and curl to probe live API endpoints for authentication weaknesses, manipulate request flows, and enumerate hidden attack surfaces, core skills for application security roles and bug bounty programs. - Validated real-world API vulnerabilities end-to-end: from discovery through proof-of-concept exploitation to documented remediation advice
Software engineering Intern
Kocela Limited 2025-01-15 - 2025-03-15 Developed mobile application features using Kotlin and Jetpack Compose, gaining developer-side perspective that strengthens the ability to identify security flaws in mobile code during assessments. - Worked with MySQL and SQLite databases, building practical understanding of data storage patterns that underpin SQL injection and privilege escalation vulnerabilities. -Delivered unit and integration tests in an Agile(Scrum) environment using Git, demonstrating the collaborative delivery practices common in enterprise engineering teams. -Interpreted and implemented UI/UX designs from Figma, contributing to full-stack delivery and cross-functional communication skills valued in security consulting engagements

Education

Bachelor of Science in Computer Science
Bachelor's Degree 2021-09-09 - 2025-12-19

Review

0 Base on 0 reviews
Working attitude
Progressive working attitude
0
Team work
Good teamwork spirit
0
Skill & Experience
Skills and experience meet well
0
Offered Salary
Suitable salary
0

Reply

Cancel reply
Send message
Cancel
Invite to apply job

Select job to invite this user

No item found