(256) 555-0117 ◇ Huntsville, AL
njeri.wanjiku@example.com ◇ linkedin.com/in/njeri-wanjiku ◇ njeriwanjiku.com
Cybersecurity practitioner with 10 years defending regulated environments, owning security operations across 4,200 endpoints and 340 servers at 3 facilities. Cut mean time to contain a confirmed incident from 9 hours to 40 minutes, closes 1,400 vulnerability findings a year, and took critical patch compliance from 71% to 98%. A generalist who came up through systems administration.
Coursework in Networks, Operating Systems, Cryptography, and Systems Security.
Also holds CompTIA Security Plus and the GIAC Certified Incident Handler credential.
- Own security operations for an environment of 4,200 endpoints and 340 servers across 3 facilities.
- Cut mean time to contain a confirmed incident from 9 hours to 40 minutes across 3 years.
- Close about 1,400 vulnerability findings a year and raised critical patch compliance from 71% to 98%.
- Ran vulnerability management across 2,600 assets and 40 application teams.
- Led the response to about 60 security incidents a year, of which 9 required formal reporting.
- Built the awareness programme that cut phishing click rates from 22% to 4%.
- Administered 180 Windows and Linux servers supporting about 900 users.
- Hardened 120 servers to a published benchmark, closing 40 configuration findings.
- Automated patch deployment across 180 servers, cutting a 3-day cycle to 6 hours.
Containment Time Reduction. Took mean time to contain from 9 hours to 40 minutes by pre-authorising isolation actions and rehearsing them quarterly. The delay had never been technical, it was waiting for permission to unplug something.
Risk-Based Patching. Rebuilt patching around exposure and exploitability rather than raw severity score, which took critical compliance from 71% to 98% while the team actually patched fewer things per cycle.
Awareness Programme. Cut phishing click rates from 22% to 4% by replacing annual training with short monthly simulations and same-day feedback, and by removing the blame from reporting a mistake.
- Mentor 4 analysts a year through a regional cybersecurity association programme.
- Volunteer security advisor to 2 nonprofits, reviewing their systems annually.
- Attend a Huntsville security meetup monthly and presented twice on incident response drills.
- Serve as incident commander for a security team of 6 across 3 facilities.
- Trained 40 application owners on vulnerability triage and remediation ownership.
- Introduced the quarterly incident response exercise now run across the whole organisation.

.webp)



.webp)


%20Which%20Should%20You%20Use.webp)