About
Consultant based in Johannesburg with fourteen years of experience across quality engineering and cybersecurity, mostly for South African banks and insurers. I started in QA and test automation before moving into penetration testing and application security. My current focus is DevSecOps: integrating SAST, DAST, SCA and SBOM generation into CI/CD pipelines.
I also build test automation frameworks (Selenium, Cypress, Playwright, Flutter integration_test), run performance testing with k6, and write findings that engineering teams can act on. Clients have included Standard Bank, Absa (9 African markets), Discovery, Liberty, PSG and Glacier.
What I'm looking for
An environment that foster growth and learning
Experience
Founder & Security Consultant
LockedCyber
Apr 2024 – Present
• DevSecOps Rollout (Glacier, via e-Blocks Software): Part of the team leading the DevSecOps rollout. Worked on the Veracode integration, assessed and upgraded the build pipelines, and added SAST, SCA, DAST and SBOM generation across Azure DevOps. Conducted a DSOMM maturity assessment to baseline the programme and prioritise remediation.
• Automation & Pipeline Security (PSG, via e-Blocks Software): Automation testing on the Flutter investment platform app. Migrated the legacy Flutter Driver suite to integration_test, built a BDD/Gherkin framework, and set up iOS provisioning and the Android SDK so the suites ran reliably in CI. Worked on the DevSecOps integration in the same pipelines, adding security scanning to the build alongside the test stages.
• Threat Modelling & Design Review: Threat modelling and secure design review sessions with engineering teams on microservices and API platforms.
• SIEM Engineering (Internal Proof of Concept): Designed and built a multi-node Wazuh SIEM cluster with a manager, worker nodes and HAProxy load balancing, including certificate provisioning and multi-node indexer configuration. Covered log collection, file integrity monitoring, vulnerability detection and alert tuning.
DevSecOpsFlutterWazuh
Certified Ethical Hacker / QA Consultant
Khabane Majestic Consulting
Jun 2016 – Sep 2024
Security Engagements (Oct 2018 – Sep 2024):
• Container Security (Absa Account): Part of the Aqua DevSecOps implementation team, improving the security posture across container and application workloads.
• Application Security (Banks & Insurers): AppSec engagements across Java and JavaScript stacks, covering pipeline tooling and triage of the resulting findings.
• Penetration Testing: Conducted an internal pentest on the web and API digital platforms.
• Vulnerability Management: Triaged findings with engineering teams and supported decisions on remediation, mitigation and risk acceptance.
Quality Engineering (Jun 2016 – Sep 2024):
• Web Automation: Selenium/WebDriver, Cypress, and Playwright across enterprise clients, integrated into Jenkins and Azure DevOps pipelines.
• Performance Testing: Load testing with k6 for clients requiring performance coverage alongside functional automation.
• Test Strategy & Quality Engineering: Test strategy, test data management, and quality engineering across enterprise release cycles.
SeleniumPenetration Testingk6
QA Consultant
Thoughtworks
Jan 2014 – Dec 2015
• Consultant QA (Johannesburg): Automation scripting and test framework work on enterprise delivery teams.
• QA Consultant (China, Apr 2015 – Oct 2015): Automation testing on a distributed Agile team, with Splunk (SIEM) exposure, Agile ceremonies, bug tracking and reporting.
Automation ScriptingTest FrameworkSplunk
Test Analyst
DStv Digital Media
Jun 2013 – Jan 2014
• Multi-Platform Testing: Functional, integration, mobile, web, desktop, and grey-box testing on a multi-tenant media platform, with test case design for manual runs and automation, plus UAT support for client releases.
Functional TestingIntegration TestingMobile Testing
Software Tester (DStv Online)
Software Testing Solutions
Dec 2011 – May 2013
• Release Testing: Test data management, test case execution, and defect management in Pivotal.
Functional, integration, mobile, and black-box testing across release cycles.
Test Data ManagementDefect ManagementBlack-box Testing
Education
Durban University of Technology
Diploma · Information Technology
2009 – 2011
Certifications
Veracode Risk Management
Veracode
2024 – No expiry
Certified Ethical Hacker (CEH v10)
EC-Council
2018 – No expiry
ISTQB Certified Tester
International Software Testing Qualifications Board
Skills
scriptingCI/CDQuality AssuranceKali LinuxAgileKali LinuxBurpSuiteDevSecOpsPenetration Testing
Languages
English (Full professional proficiency)