Arcel Mukadi — Cybersecurity & AWS Cloud Security Consultant

Practical security for growing businesses.

>_

I assess and strengthen AWS environments, applications and APIs, then translate security findings into prioritized remediation your team can act on.

Assessments · Remediation · Fractional support · Corporate training

public.activity/githubLive

Live public GitHub activity + replay of portfolio lab sessions — never client data.

AWS CertifiedLinux & Cloud InfrastructureEnglish / Français13+ Years in IT & Infrastructure

About

Practical security work, clearly reported.

Arcel Mukadi — cybersecurity and AWS cloud security consultant

I'm Arcel Mukadi, a cybersecurity and AWS cloud security consultant backed by 13+ years across IT support, systems and infrastructure. I help growing teams identify and reduce risk across AWS, applications and APIs.

My work combines focused assessments, practical hardening and remediation support. Documented security engineering projects and controlled labs provide transparent technical proof-of-work.

Bilingual (English / Français), based in the DRC, working remotely with teams worldwide.

arcel@consultant:~ profile

Profile facts — kept current as engagements and credentials change.

What I Do

Security services with clear outcomes.

Defined scope, practical deliverables and clear next steps for technical teams and decision-makers.

AWS & Cloud Security

Assess and harden AWS environments across IAM, networking, storage, logging, encryption and detection controls.

AWSIAMTerraformProwlerScoutSuiteGuardDuty

Application & API Security

Identify exploitable weaknesses across web applications and APIs, with practical remediation guidance for developers.

OWASPAPI SecurityAuthenticationAccess ControlBurp Suite

Security Posture & Hardening

Review vulnerabilities, exposed services, access controls, logging and configuration, then prioritize what should be fixed first.

Vulnerability ManagementHardeningWAFSecurity Controls

Fractional Cybersecurity & Cloud Security

Ongoing part-time security expertise for growing companies that need support without hiring a full-time security engineer.

Cloud SecurityRemediationAdvisorySecurity Reviews

Corporate Security Training

Focused security training for teams, covering phishing, credential safety, cloud access, incident reporting and secure working practices.

Security AwarenessPhishingCloud AccessIncident Reporting

Incident Response Readiness

Prepare practical response playbooks, escalation paths, evidence requirements and recovery priorities before an incident occurs.

Response PlanningTabletop ExercisesDetectionRecovery

Featured Security Projects

Hands-on security engineering.

Threat intelligence, detection engineering, incident response and AWS posture management — built and validated in controlled environments I own. These are security engineering portfolio projects, not client engagements.

AWS Cloud Security · Detection Engineering · Incident Response

AWS Cloud Incident Detection & Automated Response

Completed · Security Engineering Project

Built an AWS-native detection and incident-response pipeline that identifies suspicious cloud activity, creates structured incidents, preserves forensic evidence and automatically alerts responders.

CloudTrailEventBridgeLambdaDynamoDBS3SNS

Key outcomes

  • Detect suspicious AWS API activity
  • Preserve forensic evidence in S3
  • Create auditable incident records
  • Automate responder notifications

Technology

AWSCloudTrailEventBridgeLambdaDynamoDBS3SNSIAMPythonTerraformGuardDuty

AWS Cloud Security · CSPM · Security Remediation

AWS Cloud Security Posture Assessment & Remediation

Completed · Security Engineering Project

Built an intentionally vulnerable AWS environment, assessed its posture with Prowler, ScoutSuite and manual validation, prioritized findings by risk, remediated with Terraform and independently verified the hardened result.

AssessValidatePrioritizeRemediateRetestDocument

Key outcomes

  • CSPM assessment with Prowler & ScoutSuite
  • Manual validation of scanner findings
  • Terraform-based remediation
  • Before / after verification and residual risk

Technology

AWSTerraformProwlerScoutSuiteIAMS3EC2CloudTrailAccess AnalyzerSystems ManagerCSPM

Before → after remediation

IAM

AdministratorAccess and weak controls

Privileged access reduced, least privilege applied

Administrative access

Public SSH exposure

Public SSH removed, Systems Manager used

EC2 metadata

IMDSv1 permitted

IMDSv2 enforced

S3

Potential public exposure

Block Public Access enabled

EBS

Unencrypted storage

Encryption enabled

Logging

Insufficient audit visibility

Multi-Region CloudTrail enabled

IAM analysis

Limited permission visibility

IAM Access Analyzer enabled

Validation

Changes assumed effective

Controls retested and evidence documented

Threat Intelligence · Ransomware Preparedness · Incident Response

Cyber Preparedness & Ransomware Threat Assessment

Completed · Security Engineering Project

Board-level preparedness assessment of a multinational logistics scenario facing a ransomware-as-a-service threat, connecting adversary behaviour and business exposure to operational consequences and defining layered controls across identity, edge security, segmentation, EDR/Sysmon monitoring, backups and trusted recovery.

Threat ModellingATT&CK MappingDetection EngineeringResponse StrategyRecovery

Key outcomes

  • Ransomware TTPs mapped to MITRE ATT&CK
  • Layered defence across identity, edge, segmentation and EDR
  • Detection engineering on Sysmon Event IDs 1 and 11
  • Prioritized first-24-hour response strategy

Technology

MITRE ATT&CKSysmonEDRWindows Event LogsIncident ResponseBackup & Recovery

AWS Cloud Security · IAM · Offensive Security

IAM Privilege Escalation & Hardening Lab

Completed · Portfolio Lab

Demonstrated common AWS IAM privilege-escalation paths in a controlled environment, then reduced exposure with least-privilege policies, permission boundaries, SCP guardrails and CloudTrail visibility.

EnumerateEscalateValidateHardenRetest

Key outcomes

  • Validated iam:PassRole and policy-attachment risks
  • Reduced excessive permissions with least privilege
  • Applied permission boundaries and SCP guardrails
  • Verified activity through CloudTrail

Technology

AWSIAMSTSCloudTrailPermission BoundariesSCPs

AWS Cloud Security · Application Security · SSRF

SSRF to EC2 Metadata — Exploitation & Defence

Completed · Portfolio Lab

Demonstrated credential exposure through application-layer SSRF in a controlled EC2 environment, then hardened the path with IMDSv2, least-privilege roles, network controls and detection coverage.

SSRFMetadataCredentialsDetectionHardening

Key outcomes

  • Demonstrated the SSRF-to-metadata attack path
  • Enforced IMDSv2 on EC2 workloads
  • Reduced role permissions and credential exposure
  • Added logging and detection guidance

Technology

AWSEC2IMDSv2IAMWAFCloudTrail

Offensive Security · Active Directory · Reporting

Network & Active Directory Attack Path Lab

Completed · Portfolio Lab

Built a controlled Windows domain to practise enumeration, lateral movement and privilege escalation, then documented validated findings with risk ratings and practical remediation guidance.

EnumerateMap PathsValidateEscalateReportRemediate

Key outcomes

  • Mapped identity and privilege relationships
  • Validated lateral-movement paths safely
  • Prioritized findings using risk and evidence
  • Documented hardening and retest guidance

Technology

NmapBloodHoundImpacketCrackMapExecActive Directory

AWS readiness check

How prepared is your AWS environment?

Mark the controls you can confidently verify. This quick check is directional, not a security assessment.

Readiness snapshot · 0/4

4 areas may need review: IAM and privileged access, logging and detection coverage, public resource exposure, incident response readiness.

Discuss My AWS Readiness
AWS security readiness controls

Selected Security Projects

Other security engineering projects.

Security engineering projects, AWS builds and portfolio labs I designed and documented. Client work is covered by NDA and shared on request.

Application Security

Security Engineering Project

OWASP-Aligned Web & API Testing Methodology

Repeatable workflow for authentication, access control, injection, SSRF and business-logic testing with developer-facing fixes.

Burp SuiteOWASP WSTGGraphQLJWT

Mobile Security

Portfolio Lab

Android & iOS Application Security Review

Static and dynamic analysis of test applications: traffic interception, insecure storage and pinning bypass mapped to OWASP MASVS.

MobSFFridaObjectionMASVS

Detection & Response

Security Engineering Project

Threat Hunting Queries & IR Playbooks

Hunting content aligned to MITRE ATT&CK plus response playbooks for ransomware, business email compromise and credential exposure.

MITRE ATT&CKSigmaSplunkKQL

AWS Cloud Security

AWS Project

Secure Multi-Account AWS Landing Zone

Terraform landing zone with Organizations, SCP guardrails, centralized CloudTrail archive, delegated GuardDuty and KMS keys.

OrganizationsTerraformIAM Identity CenterKMS

How I Work

Security findings your developers can actually fix.

Every assessment can include a detailed technical report plus a concise remediation brief for developers and decision-makers.

01

Scope

Confirm the assets, objectives, authorization boundaries and evidence required before testing begins.

02

Find

Identify and validate security weaknesses across applications, APIs and AWS environments.

03

Fix

Provide prioritized, practical remediation guidance your developers can act on.

04

Verify

Retest remediated issues and confirm the improvements hold.

Reports may include

Executive summary

Scope and methodology

Risk ratings

Technical findings with evidence

Business impact

Reproduction steps

Remediation recommendations

Retest results

Remediation priority

Fix First

Fix Next

Improve Later

Fractional Security

Security expertise without the cost of a full-time hire.

Growing businesses often need cybersecurity expertise before they are ready to build an internal security team. Fractional engagements provide ongoing access to practical security support on a part-time basis.

Discuss Fractional Security Support

AWS cloud security reviews

Vulnerability management

IAM and access-control reviews

Web and API security reviews

Security hardening

WAF and network security review

Logging and monitoring

Incident-readiness improvements

Developer security guidance

Periodic posture assessments

Experience & Credentials

13+ years in IT and infrastructure.

arcel@consultant:~ career

Complete role history — 2012 to present.

Completed credentials

AWS Solutions Architect — Associate

Amazon Web Services

Completed

AWS Cloud Practitioner

Amazon Web Services

Completed

Google IT Support Certificate

Google / Coursera

Completed

Cloud Engineering Certificate

Cloud Career Mentor

Completed

Diploma — Computer Systems Engineering

Vaal University of Technology

Completed

In progress

AWS Certified Security — Specialty

Amazon Web Services

In progress

ACRTP — Amazon Cloud Red Team Professional

Pwned Labs

In progress
Authorized TestingClear ScopeActionable ReportingRemediation Support

Get started

Let's secure what matters most.

Tell me what you need to secure. We can start with a focused call, define the scope and identify the most useful next step.

+243 810 092 962 · Phone & WhatsApp

No obligation · NDA available · English / Français