Self-taught,institution-tested

I'm a full-stack developer and security engineer based in Dakar. I taught myself to build software, and for the last four years I've been doing it where the stakes are real — inside Senegalese government ministries and public institutions.
That context shapes everything about how I work. When a platform carries a national programme, it has to hold up on a 3G connection in a rural district as reliably as it does on fibre in Dakar. It has to survive an audit. It has to still be maintainable when the next team inherits it.
My work sits at the intersection of web engineering, security and applied AI. I hold four verified professional certifications — including Google's Cybersecurity Professional Certificate and Cisco's Network Technician path — and I keep the security practice sharp through CTF work on TryHackMe and Hack The Box.
Outside client work I build things to answer questions: can a language model answer questions about a country using only its official statistics? Can a phone camera read sign language well enough to be useful? Some of those became products.
Four things I'm actually good at
Product engineering
End-to-end web applications in Next.js, React and TypeScript, with Python or Node on the server and PostgreSQL underneath.
Security
Threat modelling, OWASP-aligned reviews and penetration testing. Security decided at design time, not bolted on before launch.
AI systems
Retrieval-augmented generation, NLP and computer vision integrated into products people actually use — not demos.
Public-sector delivery
Working inside institutional constraints: procurement, accessibility, low-bandwidth users and long maintenance horizons.
Security is a design decision, not a final checklist.
If it only works on fast connections, it does not work.
Boring, maintainable code beats clever code.
Ship, measure, then decide what was actually needed.
No formal computer science degree. Four years of shipping instead.
- 01
Full-Stack Developer
2023 — PresentIndependentDakar / RemoteActive
Building web platforms and AI systems for government institutions, public organisations and private clients. Next.js and React on the front, Python and Node behind, with security review baked into delivery.
Next.jsReactPythonPostgreSQLAWS - 02
Security Practitioner
2022 — PresentTryHackMe · Hack The BoxOnlineActive
Continuous hands-on security practice through CTF challenges and structured labs — penetration testing, network security and vulnerability assessment. It keeps the offensive perspective current, which is what makes the defensive work credible.
Burp SuiteWiresharkMetasploitNmapKali - 03
Self-Directed Engineering
2021 — PresentSoftware engineering & AIDakar, SenegalActive
Four years of deliberate self-teaching across software engineering, cybersecurity and machine learning. Four verified professional certifications and more than twenty projects shipped, most of them built to answer a question rather than fill a portfolio.
PythonTensorFlowDockerLinuxNetworking
Tools I reach for. The list is shorter than it used to be, on purpose.
- Frontend
- ReactNext.jsTypeScriptTailwind CSSFramer Motion
- Backend
- Node.jsPythonDjangoRESTGraphQLPHP
- Data
- PostgreSQLMySQLMongoDBRedisNeonSupabase
- AI / ML
- TensorFlowPyTorchLangChainRAGYOLOv5
- Infrastructure
- DockerAWSVercelGitHub ActionsNginxLinux
- Security
- OWASPPenetration testingBurp SuiteWiresharkCryptography