🟢 Available for enterprise collaborations & Microsoft partnership projects Let's talk →
DevSecOps Engineer

Best S. E.
Aihebholoria

Solutions Architect · Microsoft Ecosystem · ERP Builder

If your systems are insecure, your pipelines are slow, or your teams are still running operations on spreadsheets — I fix that. From DevSecOps pipelines to full enterprise platforms, I turn security and operational risk into competitive advantage.

6+
Live Projects
5+
Years Experience
MS·Azure
Ecosystem

Building secure systems
that enterprises rely on

I'm Best S. E. Aihebholoria, a DevSecOps Engineer and Solutions Architect with a passion for building enterprise-grade systems that are secure by design and scalable by nature.

My work spans the full lifecycle — from security assessments and infrastructure hardening to building custom service desks, helpdesk platforms, and ERP solutions for organisations. I operate deep within the Microsoft ecosystem — Azure, M365, Entra ID, Sentinel — and collaborate with companies to digitally transform their operations.

Whether it's securing a cloud environment, building a legal service desk from scratch, or architecting an ERP system with Microsoft, I bring engineering rigour and business clarity to every project.

🛡️
DevSecOps
Security embedded into every stage of the development and deployment pipeline.
☁️
Cloud Architecture
Azure-first infrastructure design, IaC, and cloud-native security posture management.
⚙️
Enterprise Apps
Custom service desks, helpdesk platforms, and ERP systems built for real organisations.
🤝
Microsoft Partner
Collaborating with Microsoft to build and deploy ERP and M365-integrated solutions.

Tools I work with

Security
SIEM / SOAR
Microsoft Sentinel
Vulnerability Assessment
Penetration Testing
Zero Trust Architecture
ISO 27001 / NIST
SLA Compliance
Cloud & DevOps
Microsoft Azure
Azure DevOps
Docker / Kubernetes
Terraform / IaC
GitHub Actions CI/CD
AWS / GCP
Linux Administration
Microsoft Ecosystem
Microsoft 365
Entra ID (Azure AD)
Dynamics 365
Power Platform
SharePoint / Teams
Intune / Endpoint
Defender for Cloud
ITSM & Dev
Custom ITSM Platforms
ServiceNow
Jira / Confluence
Python / Bash / PS
REST APIs / GraphQL
SQL / PostgreSQL
Node.js / TypeScript

Live enterprise systems

Real platforms built and deployed for real organisations — handling legal workflows, IT operations, and compliance tracking.

HTTP Trigger API Gateway Event Trigger Queue / Timer Snyk Webhook Vuln Alert Azure Functions Python Runtime ⚡ Serverless Threat Scan SAST + Snyk SCA Dependency CVE Analysis Auto Remediate PR + Fix Apply Security Dashboard Alerts CVEs Critical Azure Python Snyk
Serverless Azure Python Snyk SCA
Serverless Security Platform
A cloud-native security platform built on Azure Functions (Python) that automates vulnerability detection across the SDLC. Integrates Snyk for continuous Software Composition Analysis, automated CVE triage, and dependency auto-remediation via PR generation — all triggered serverlessly through HTTP, queue, and webhook events.
⚙ DevSecOps
This platform is the DevSecOps pipeline. Snyk SCA runs continuously on every dependency — CVEs are triaged automatically and auto-remediation PRs are raised without human intervention. Azure Functions enforce least-privilege serverless execution with zero persistent compute surface. Secrets managed via Azure Key Vault — never hardcoded. Webhook signatures validated on ingress to prevent supply-chain injection attacks.
Role: Architect & Developer
Stack: Azure Functions · Python · Snyk · SCA
View on GitHub →
☁ AWS Cloud Oracle EBS / ERP AI Models Predictive Data Store S3 / RDS ⚙ On-Premise Oil Field Sensors Field Equipment Operations Team Data Poisoning → Sensors Model Extract → AI Models Adversarial → AI Models Cloud Vulns → Oracle EBS Insider Threat → Ops Team RISKS FOUND 4 High 3 Medium Methodology STRIDE MITRE ATT&CK DREAD Kill Chain
Threat Modelling STRIDE MITRE ATT&CK Oracle EBS AWS AI Security
AI Threat Modelling — Desicon Engineering & Oracle EBS
Led an AI Threat Modelling Workshop for Desicon Engineering (oil servicing), targeting their AWS-hosted Oracle EBS and AI prediction systems. Ran all scenarios against the cyber attack kill chain using STRIDE, MITRE ATT&CK, and DREAD for control gap assessment. Identified 4 high risks and 3 medium risks — including data poisoning, model extraction, adversarial attacks, and insider threats.
⚙ DevSecOps
Pure threat-intelligence engagement. Applied STRIDE to enumerate spoofing, tampering, and repudiation vectors across the Oracle EBS API layer. Mapped every finding to MITRE ATT&CK TTPs and scored residual risk with DREAD. Modelled the full Cyber Kill Chain — from initial AI data-poisoning reconnaissance through insider-threat lateral movement to impact. Output: a prioritised, sprint-ready remediation backlog Desicon's engineering team could act on immediately.
Role: Lead DevSecOps Architect
Client: Desicon Engineering Ltd
View on GitHub →
Desicon Engineering Legal Service Desk Architecture
React 18 Node.js 20 Azure PostgreSQL 16 Entra ID SSO Microsoft Graph pdf-lib Legal Tech Compliance
Desicon Engineering — Legal Service Desk
A production legal operations platform that took Desicon Engineering's in-house legal department off email and into a structured, auditable system — ten modules across sixteen tables, live at legal.desiconapp.com. Any department raises a request (contract draft, legal opinion, document review, advice or compliance check) against an auto-generated REQ reference; it is prioritised, checked hourly for SLA breach, routed to the Drafting Desk or Review & Advice, and the requester is emailed on every status change through Microsoft Graph. ITT qualification auto-classifies tenders into Category A, B or C by contract value and assigns the approving authority accordingly — Board, Executive Director or Department Head — running a checklist to clearance with CSV export of the full register. The digital signature engine stamps PDFs server-side with pdf-lib: officers place a stamp on any page of a multi-page document, drag to fine-tune and resize between 10 and 55 percent of page width, while the signature image bytes never reach the browser. Agreement lifecycle covers NDA, SLA, joint venture, employment and supplier contracts with 90-day expiry alerts; case management tracks intake to resolution with an event timeline and litigation cost per case; the compliance tracker scores regulatory, labour and HSE-permit obligations automatically; and board governance handles meetings, minutes and resolution follow-up. Six scheduled jobs run behind it all, so expiry dates, tender deadlines, court hearings, compliance obligations and board meetings escalate on their own rather than depending on someone remembering.
Client: Desicon Engineering Ltd — in-house legal department
Role: Architect & Builder — designed, built & deployed end-to-end
Stack: React 18 · PDF.js · Azure MSAL · Node.js 20 · Express · pdf-lib · node-cron · PostgreSQL 16 Flexible Server · Entra ID · Microsoft Graph · Azure App Service · Static Web Apps · GitHub Actions
Live: legal.desiconapp.com — v1.0, production
DevSecOps — Evidence That Holds Up
Audit and signature logs are append-only at the database level — rules block UPDATE and DELETE, so the application itself cannot rewrite history
Entra ID SSO with JWKS-RSA bearer validation on every route · 5-tier RBAC (Department User · Legal Officer · Head of Legal · Company Secretary · IT Admin)
Signature application and ITT clearance are role-gated — every stamp records officer, document, applied-by user, timestamp and IP address
PDF stamping runs server-side — signature image bytes are never exposed to the client
Helmet security headers · CORS restricted to the configured origin · rate limiting at 500 req/15 min per IP · uploads validated before reaching SharePoint
GitHub Actions push-to-deploy — path-filtered pipelines deploy backend and frontend independently
8 new 8 6 1 0 OPEN: 6 CLOSED: 1 IN PROG: 1 OPEN IN PROGRESS OPEN OPEN
ITSM Helpdesk Desicon Engineering Live Production
ICT Helpdesk — Desicon Engineering
Enterprise IT helpdesk system for Desicon Engineering with real-time ticket tracking, priority management (Critical/High/Low), multi-engineer assignment, status workflows (Open/In Progress/Closed), SLA monitoring, admin controls, and live notifications — deployed in production.
⚙ DevSecOps
Every ticket mutation is audit-logged with timestamp and actor — creating a tamper-evident trail suitable for ISO 27001 evidence gathering. Priority triage (Critical → High → Low) mirrors security incident-response playbook SLAs. RBAC separates admin controls from engineer views; PostgreSQL row-level security prevents cross-engineer data leakage. Live notifications run over secure WebSocket channels with session-bound authentication tokens.
Role: Architect & Builder
Stack: TypeScript · Node.js · PostgreSQL
Desicon Engineering Logistics & Fleet Management Platform Architecture
.NET 8 React 18 Azure TypeScript EF Core 8 SQL Server Entra ID Bicep GitHub Actions
Desicon Engineering — Logistics & Fleet Management Platform
An enterprise logistics platform coordinating fleet and movement operations across Desicon Engineering's Nigerian sites — Lagos head office, Port Harcourt, Abuja, Site Bonny and field locations. It replaced phone-call driver coordination, WhatsApp vehicle assignments, paper maintenance notebooks, per-site Excel fuel sheets and gate logbooks with one real-time system. At its centre is an automated assignment engine: a staff transport request notifies coordinators, the engine selects a driver and vehicle on availability and workload balance, and completion cascades statuses back across driver, vehicle and request — with an audit row written at every step and manual overrides logged rather than blocked. Delivered in three phases across 19 API modules. Fleet operations cover the vehicle registry, live driver status board, a weekly schedule spanning nine duty types (day and night shift, standby, expatriate, management and project assignment), and driver performance with severity-coded incidents and an accident-free streak. Maintenance tracks service intervals and fault repairs with overdue email reminders, while fuel logs run per location with odometer readings, automatic mileage calculation and cost-centre tagging, consolidated into cross-site reporting. Phase 3 added a digital movement register replacing gate logbooks (time and mileage out and in, gate pass, one-click closure), material transport on a three-level approval chain (Requestor → HOD → GM Logistics → Driver), a project materials register tracking PO numbers, freight forwarders, ETD/ETA, customs and BL/AWB, plus travel and accommodation requests. Every mutation is written to an audit trail carrying user email, IP address and timestamp.
Client: Desicon Engineering Ltd — multi-site operations, Nigeria
Role: Solution Architect & DevSecOps Engineer
Stack: React 18 · TypeScript · Vite · Tailwind · React Query · .NET 8 / ASP.NET Core · EF Core 8 · SQL Server 2022 · Entra ID · Azure App Service · Static Web Apps · Blob & Queue Storage · Docker · Bicep · GitHub Actions
DevSecOps Built-in
Microsoft Entra ID SSO via MSAL v3 with PKCE flow — no local credentials, MFA enforced at tenant level
5-tier RBAC (Driver · Coordinator · Mechanic · Manager · Admin) — JWT bearer validated on every API endpoint from Entra role claims
Full audit trail on every assignment, status change, approval and override — user email, IP address, timestamp, action
Rate limiting at 60 req/min per user · HTTPS enforced · SQL encryption at rest · Blob Storage private access
Bicep IaC · separate API and web GitHub Actions pipelines · CodeQL SAST + Trivy SCA gating deployment
NOW Operations Dashboard 0 0 ₦0 0 ₦0 ! 0 No bookings yet No payments recorded
Travel Tech CRM Azure Microsoft 365 SharePoint
FlyNow Business Management System
Bespoke digital operations platform built for Now Travel & Tours (IATA & NANTA certified, Port Harcourt). Replaces spreadsheets & WhatsApp threads with a unified system: Customer CRM, Bookings, Visa Application Pipeline, Invoices & Paystack payments, SharePoint Document Vault, and Staff RBAC — giving the MD real-time visibility from any device. Deployed on Microsoft Azure Static Apps.
⚙ DevSecOps
Microsoft 365 SSO — staff authenticate with existing corporate credentials; no separate passwords; MFA enforced at tenant level. SharePoint Document Vault stores passports and visa scans with Azure AD-gated access and encryption at rest — sensitive customer identity data never sits in a local database. RBAC scopes junior staff to their assigned work only; financial data is MD-restricted. Paystack webhooks are HMAC signature-validated on every callback — no card data ever touches the application server. All booking and payment mutations carry a full audit trail.
Client: Now Travel & Tours Ltd
Stack: React · Azure · SharePoint · M365 · Paystack
GitHub Source Repo CI/CD GH Actions SAST CodeQL SCA Trivy IaC Scan Terraform+Trivy Static Code Analysis Dependency Check Infrastructure Check Remediation & Auto-fix Reporting & Alerts AWS Terraform
DevSecOps SAST SCA IaC Scanning GitHub Actions AWS Terraform
DevSecOps Pipeline — SAST, SCA & IaC Security
A comprehensive DevSecOps implementation integrating SAST (CodeQL), Software Composition Analysis (Trivy), and IaC scanning (Terraform Compliance + Trivy) — automated through GitHub Actions. Enforces PR blocking on Critical/High vulnerabilities, implements a full Secure SDLC, and deploys to AWS with encrypted Terraform remote state on S3.
Role: DevSecOps Architect
Stack: GitHub Actions · CodeQL · Trivy · Terraform · AWS S3
View on GitHub →
LD-CMS Architecture Diagram
Python FastAPI Azure PostgreSQL Entra ID SSO GitHub Actions Trivy pip-audit 4-tier RBAC
LD-CMS — Learning & Development Competency Management System
A production-grade talent management platform built entirely in-house for a leading engineering company — covering the full performance & talent lifecycle across 213 employees and 37 competency domains. Core workflow: Competency Assessment → Gap Register → Learning Intervention → Post-Training Validation → KPI Appraisal → Deployment Readiness. The system is now extended with a full 9-Box Talent Matrix: Performance axis is fed automatically from KPI Appraisal scores; managers assess Potential (Leadership Rating + Learning Agility); HR selects a period and recalculates. Nine talent categories from Future Leaders to Underperformers, each with recommended development actions. HR calibration override with reason recorded. Any employee in a low-performance box auto-generates a PIP — pre-filled with recommended actions and a 90-day review date. An Executive Dashboard shows live talent distribution with movement arrows vs. the prior period and overdue PIP alerts. One-click Excel + PDF exports for talent-review and succession-planning meetings. A scheduled GitHub Actions workflow emails managers a weekly digest of overdue and upcoming PIP reviews every Monday. All existing staff records, managers, and HODs were migrated intact. Live at ldcms.desiconapp.com.
Role: ICT Lead — Designed, built & deployed entirely in-house
Stack: Python 3.11 · FastAPI · SQLAlchemy 2.0 · PostgreSQL Flexible Server · Azure App Service · Entra ID · Bootstrap 5 · GitHub Actions
DevSecOps Built-in
Entra ID SSO · JWT cookie auth · 4-tier RBAC (Admin / HR / Manager / Employee)
GitHub Actions CI/CD — push to main → auto-deploy to Azure App Service
Trivy (vuln · secret · misconfig) + pip-audit on every push/PR — SARIF artifacts saved
Scheduled workflow: weekly PIP digest emailed to managers every Monday 07:00 UTC
General Service & Logistics Management Platform Architecture
Azure React ASP.NET Core Azure SQL Entra ID Power BI DevSecOps
General Service & Logistics Management Platform
An enterprise-grade platform built for a leading engineering & oil services company — automating service requests, vehicle & fleet coordination, staff activity tracking, maintenance scheduling, fuel consumption analytics, and operational reporting. Features a token-based ISO-22000 compliant workflow engine, multi-level approval routing, and real-time SLA monitoring. Secured end-to-end with Entra ID SSO, Azure Front Door + WAF, Private VNet, Key Vault, and a full DevSecOps pipeline (SAST · DAST · GitHub Actions CI/CD · Azure Bicep IaC). Power BI embedded dashboards deliver live operational intelligence across all modules.
Role: DevSecOps Engineer & Solutions Architect
Stack: Azure · React · ASP.NET Core 8 · Azure SQL · Entra ID · Service Bus · Azure Functions · Power BI
DevSecOps Built-in
Entra ID SSO · Azure Front Door + WAF
SAST (SonarCloud) · DAST (OWASP ZAP)
GitHub Actions CI/CD · Azure Bicep IaC · App Insights
Desicon Digital Workplace Architecture Diagram
.NET / C# Terraform Azure Blazor Checkov Trivy GitHub Actions GHCR
Desicon Enterprise Digital Workplace & Notification Platform
An enterprise notification and workplace communications platform built for a leading engineering company — delivering real-time announcements to 200+ staff across offices and remote project sites via a Blazor web portal and a Windows desktop agent (MSI/GPO deployed). The full stack is provisioned by a single Terraform module — App Service, PostgreSQL, Key Vault, Entra ID App Registration, and Application Insights — with zero manual Azure portal clicks. The GitHub Actions CI/CD pipeline enforces three mandatory security gates on every commit: Checkov (IaC/Terraform misconfiguration), Trivy (Docker image CVE scan), and dependency scanning on every PR. Images are SHA-pinned, pushed to GHCR, and deployed with az webapp config container set — no drift, no manual deploys. Microsoft 365 SSO via Entra ID gives staff single sign-on; the Windows agent (v1.1.0) polls the API and surfaces a scrollable popup with Acknowledge / Dismiss, deployable via GPO or Intune. Admins can Withdraw live announcements centrally in real time.
Role: DevSecOps Engineer & Solutions Architect — Designed, built & deployed entirely in-house
Stack: .NET / C# · Blazor SSR · Azure App Service · PostgreSQL · Key Vault · Entra ID · Terraform · Docker · GHCR
DevSecOps — Security-First IaC
Checkov scans Terraform before every apply — blocks on misconfiguration
Trivy scans Docker image for CVEs — blocks on HIGH/CRITICAL findings
Dependency scan on every PR — SCA across all .NET packages
Full Terraform module: DB · App Service · Key Vault · Entra app reg · App Insights
Desicon Finance Workflow Platform Architecture
.NET / C# Terraform OPA/Rego ASP.NET Core React + TypeScript cosign SLSA L3 Checkov Trivy SBOM
Desicon Engineering — Finance Workflow Platform
A Sprint 0 scaffold that digitises Desicon Engineering's paper financial approval forms (DEL-AC-FRM-002 & DEL-AC-FRM-003) — covering Expense Reimbursement, Cash Advance, and Procurement Requisition — built on a generic workflow engine where new modules are added as JSON definitions, not code. The engine enforces maker–checker separation at the guard, domain, and database levels, and every state transition is written to a hash-chained, insert-only audit table the application cannot alter. The project's primary purpose is to demonstrate enterprise DevSecOps maturity across six dimensions: supply-chain integrity (SHA-pinned Actions, keyless cosign signing, SLSA Build L3 provenance, CycloneDX SBOM, deploy by digest only); policy-as-code via OPA/Rego evaluated over the Terraform plan JSON (not just source files); security exceptions that carry an owner, justification, and expiry date — CRITICAL/HIGH capped at 30 days, build fails when they lapse; and continuous scanning (weekly re-scan of the running image, Terraform drift detection with auto-raised issues, OpenSSF Scorecard). The 11-job PR pipeline covers Gitleaks on full history, Checkov, OPA/Rego policy, Trivy, SCA, SBOM generation, and keyless image signing before any deployment proceeds.
Role: DevSecOps Engineer & Solutions Architect — Designed & built entirely in-house
Stack: .NET / C# · ASP.NET Core · React + TypeScript · PostgreSQL · Azure App Service · Key Vault · Entra ID · Terraform · Docker · GHCR · OPA/Rego · cosign · Syft · CycloneDX
DevSecOps — Enterprise Maturity
Supply chain: SHA-pinned Actions · cosign keyless sign (OIDC) · Rekor transparency log · SLSA Build L3 provenance · CycloneDX SBOM · deploy by digest · cosign verify gate
Policy-as-code: OPA/Rego evaluates terraform show -json plan — catches computed values missed by .tf-only scanners
Exceptions with expiry: owner + justification + expiry required · CRITICAL/HIGH capped at 30 days · build fails automatically when lapsed
Continuous scanning: weekly re-scan of running image · Terraform drift detection → auto issue · OpenSSF Scorecard · Gitleaks on full history
DESICON Secure — Employee Safety & Duress Alerting Platform Architecture
Android Azure Terraform Entra ID Key Vault App Insights Checkov Trivy GitHub Actions
DESICON Secure — Employee Safety & Duress Alerting Platform
An Android safety application for Desicon Group staff working across Nigerian offices and project sites, where personal security is a genuine operational risk. Employees register with their company email via Entra ID — staff only, and access is removed automatically when someone leaves. The app provides three things: a panic button that raises an immediate duress signal with location in a single tap (no menus, no confirmation dialog to fight when it matters); a security issue report for non-urgent concerns with photo, location and category; and broadcast security alerts pushed to staff about routes, areas and site advisories. A duress alert is persisted before any dispatch is attempted, then fanned out over redundant channels — push, SMS and email fallback — to Corporate Security, the HSE Manager and Head of IT, with acknowledgement tracked so it is always clear who responded and when. Location is treated as duress evidence rather than continuous tracking: it is shared on alert only, encrypted in transit and at rest, and readable only by responders on duty. The whole stack — database, App Service, Key Vault, Entra app registration and Application Insights — is provisioned by a single Terraform module, so every environment is identical and rebuildable from source, with no secrets in code. Every pull request must clear Checkov (Terraform misconfiguration), Trivy (container image CVEs) and dependency scanning before merge is allowed.
Role: In-house DevSecOps Engineer & Solutions Architect — architecture, build & security testing
Stack: Android · Azure App Service · Key Vault · Entra ID · Application Insights · Terraform · Docker · GitHub Actions
Status: In build — architecture and secure baseline complete
DevSecOps — Safety-Critical by Design
Entra ID company-email registration — staff only, leaver process revokes access automatically
Alert persisted before dispatch · redundant push / SMS / email channels · delivery-gap alerting via App Insights
Location shared on duress only — never continuous tracking · encrypted in transit and at rest · responder-scoped access
Full Terraform module: DB · App Service · Key Vault · Entra app reg · App Insights — zero secrets in code
Checkov · Trivy · dependency scanning gate every PR — merge blocked until findings clear

Professional Credentials

Vendor-certified across security, cloud, and infrastructure — validated by industry-leading bodies.

CA
DevSecOps
Cyber Agoge
✓ Valid to Dec 2028
AWS
AWS Certified Cloud Practitioner
Amazon Web Services
✓ Valid to Jun 2027
PEN
CompTIA PenTest+ ce
CompTIA
✓ Valid to Apr 2027
GH
GitHub Foundations
GitHub
✓ Valid to Aug 2027
TF
HashiCorp Terraform Associate (003)
HashiCorp
✓ Valid to Jun 2026
CEH
Certified Ethical Hacker (CEH)
EC-Council
✓ Valid to Sep 2026
CSA
CompTIA CySA+ ce
CompTIA
✓ Valid to Oct 2026
CCNP
Cisco Certified Network Professional
Cisco
✓ Active
View all credentials on LinkedIn →

What I build for companies

From security hardening to full enterprise platforms — I help organisations secure, modernise, and scale their digital operations.

🛡️
DevSecOps Implementation
Ship faster and safer — security embedded in every pipeline stage, so vulnerabilities are caught before they reach production.
Pipeline security & SAST/DAST
Secrets management
Container & Kubernetes hardening
Security gates & policy-as-code
🔍
Security Assessment
Know exactly where your exposure is — before an attacker does. Walk away with a prioritised action plan, not just a report.
Cloud security posture review
Penetration testing
Zero Trust implementation
ISO 27001 / NIST alignment
⚙️
Enterprise App Development
Replace the spreadsheets and WhatsApp threads with a system that actually runs your operations — built around your exact workflows, not a generic template.
Service desk & helpdesk systems
Legal operations platforms
Procurement & ITT systems
Compliance & case management
🟦
Microsoft ERP & M365 Solutions
Get the full value of your Microsoft investment — unified ERP, automation, and governance that actually makes your teams more productive.
Dynamics 365 ERP customisation
Power Platform automation
Azure-integrated workflows
M365 governance & compliance
☁️
Cloud Infrastructure
Stop paying for cloud you're not using, and stop losing sleep over infrastructure that isn't properly secured or monitored.
Azure architecture design
AWS (EC2, S3, Lambda, IAM)
Infrastructure as Code (Terraform)
Monitoring & alerting (Sentinel)
Disaster recovery planning
🤝
Digital Transformation
Move from "we're planning to modernise" to "we've modernised" — with a roadmap, a partner, and the delivery to back it up.
ITSM process design
Legacy system migration
Team training & enablement
Roadmap & architecture consulting

How I work

A repeatable method that moves you from "we have a problem" to "the problem is solved" — without surprises, hidden costs, or handoff gaps.

01
Discovery Call
30 minutes. I listen to your problem, your current state, and your constraints. No pitching — just honest scoping.
02
Technical Assessment
I audit your pipelines, infrastructure, access controls, and codebase. You get a clear picture of risk — not just a findings list.
03
Solution Architecture
A custom roadmap built around your stack and team — not a generic template. Includes timeline, tooling choices, and cost estimate.
04
Build & Implement
Delivery in phases with visible progress at every stage. Tight feedback loop — you see it working before it's marked complete.
05
Handover & Support
Full documentation, team training, and retainer options. You own everything — I'm available when you need to scale further.

Who I work with

I work best with organisations operating in high-stakes environments where security, compliance, and operational reliability are non-negotiable.

🛢️
Oil, Gas & Energy
OT/IT convergence, SCADA security, and pipeline operations. Built for companies managing critical national infrastructure in Nigeria and beyond.
🏗️
Engineering & EPC
E&I, procurement, and project delivery firms scaling into full EPC. I understand the workforce, compliance, and mobilisation pressures that come with that transition.
🏦
Financial Services
Banks, fintechs, and insurance companies needing Zero Trust architecture, PCI-DSS alignment, and application security they can show regulators.
🏛️
Government & Public Sector
Agencies modernising legacy systems, digitising public services, and implementing compliance frameworks under public scrutiny.
🚚
Logistics & Supply Chain
Fleet operations, last-mile delivery, and multi-vendor supply chains that need real-time visibility, automation, and systems that don't go down.
⚖️
Legal & Professional Services
Law firms and consulting practices handling sensitive data, client confidentiality, and audit trails. Secure collaboration and data governance platforms.
Building enterprise solutions
on the Microsoft stack
I work within the Microsoft ecosystem to build and deploy ERP systems, Azure-integrated applications, and M365-powered workflows for companies looking to modernise at scale. Open to Microsoft partnership collaborations.
Azure
M365
Sentinel
DevOps
Dynamics 365

Not sure if you need DevSecOps,
a security audit, or a full platform?

Book a free 20-minute call. We'll look at your setup together and I'll tell you exactly what I'd do — no sales pitch, no obligation.

Book a 20-min Discovery Call →

Free · No commitment · 20 minutes

Let's build something
enterprise-grade together

Whether you need a DevSecOps engineer, a solutions architect, or a partner to build your next ERP or enterprise platform — I'm ready to collaborate.

aihebest@gmail.com
📍
Office Address 60 King Perekule Street GRA Phase 2, Port Harcourt Rivers State, Nigeria
🎥
TikTok @aihebest DM for quick enquiries