Initializing Portfolio
Leona Kokerai
Cybersecurity Specialist · 2026
Available for work · Open to relocation
Cybersecurity Specialist · Class of 2026

Leona
Kokerai

SOC Analyst T1 Jr. Penetration Tester Cybersecurity Analyst DFIR Analyst Security Engineer I

Top 3% globally on TryHackMe. Real black-box penetration test on a live production system. 9.22 CGPA · First Class. Multiple industry certifications. I don't just study cybersecurity — I practise it.

Top 3%
TryHackMe Global
9.22
CGPA ·
First Class
12+
Vulnerabilities Found
(Live)
Portrait of Leona Kokerai

Leona Kokerai

Find me before they find you.

TryHackMe · Top 3%
LPU · Top 1% in Cohort
9.22 CGPA · First Class
scroll
Leona KokeraiCybersecurity Penetration TestingSOC Analyst DFIRTop 3% TryHackMe Find Me Before They Find You2026 Leona KokeraiCybersecurity Penetration TestingSOC Analyst DFIRTop 3% TryHackMe Find Me Before They Find You2026
"You can't protect what you don't understand — and I make it my business to understand everything."

I'm a BSc (Hons) Computer Science – Cyber Security graduate from Lovely Professional University, graduated in 2026 with an 9.22 CGPA (First Class), concurrently completing the Google Cybersecurity Professional Certificate.

I didn't just learn cybersecurity in a classroom. I ran a real black-box penetration test on a live production system, uncovered 12 critical vulnerabilities, and delivered a professional pentest report with remediation adopted by the client. I built and secured AWS infrastructure handling 5,000+ concurrent users. I ranked Top 3% globally on TryHackMe.

Zimbabwean, raised across southern Africa and India, fluent in six languages. I bring rare technical depth combined with cross-cultural communication and an uncompromising drive to grow.

🇬🇧 English🇿🇦 Afrikaans 🇩🇪 German🇿🇼 Ndebele 🇿🇼 Shona🇿🇦 sePedi
Degree
BSc Hons CS – Cyber Security
University
Lovely Professional University, India
CGPA
9.22 / 10 · First Class
Cohort Rank
Top 1% – Cybersecurity Cohort
TryHackMe
Top 3% Global
Nationality
Zimbabwean · Open to Relocation
Portfolio Live
Technical Expertise

The Stack Behind
the Shield

Penetration Testing

Burp SuiteMetasploitNmapNiktoGobusterSQLMapOWASP Top 10DAST/SAST

SOC & Threat Detection

SplunkSIEMLog AnalysisIncident ResponseMITRE ATT&CKThreat DetectionNIST CSF

Digital Forensics (DFIR)

AutopsyVolatilityMagic NumbersSteghideMemory AnalysisIR Planning

Programming & Scripting

PythonBashC/C++PowerShellPHP (Laravel)JavaScriptAssembly

Cloud & Infrastructure

AWSDockerLinux AdminWindows SystemsCisco Packet TracerWiresharkGitHub CI/CD

GRC & Compliance

ISO 27001PCI DSSHIPAANIST 800-53NIST 800-115GDPRSOC 2
Work History

Where I've Left
My Mark

2024 – Present
Full-Stack Engineer & Cybersecurity Specialist
The African Apostolic Church GBEAAA · Volunteer
  • Developing full-stack React/Node.js provincial management platform
  • Designed NIST CSF-aligned incident response plan
  • Optimised AWS infrastructure for 5,000+ concurrent users
2024 – 2025
ICT Administrator & Penetration Tester
Eduflex Academy
  • Built entire school IT infrastructure (systems, network, software)
  • Conducted authorised black-box pentest — 12 critical vulnerabilities identified
  • Maintained secure digital records dashboard for 50+ users
  • Drove 35% revenue growth in 3 months via digital transformation
2023 – 2026
Cambridge A & O-Level CS Tutor
Sunshine Private Tutors
  • Tutored 20+ international students
  • Improved test pass rates by 15% over two years
  • Curriculum covering algorithms, programming & security fundamentals
2021 – 2023
Junior Web Developer
Oyannah Academy
  • Built and maintained PHP Laravel / MySQL web applications
  • Implemented secure authentication and access control
2021 – 2023
Lead Graphic Designer
Agri-Avenir
  • Designed digital campaigns reaching 10,000+ potential customers
Portfolio

Built. Broken.
Secured.

01 · SECURITY PRODUCT · PHP + AI
Ownuh SAIPS — Secure Authentication & Intrusion Prevention System
Full-stack PHP/MySQL security administration platform built to feel like a compact SOC product, not just a login demo. Combines MFA, password recovery, audit logging, IPS controls, incident tracking, AI executive reporting, HTML and PDF exports, live alert emails, and a recruiter-safe Demo vs Production flow for polished public walkthroughs.
Latest BuildPHPMySQLRedis ControlsMFAIPSAI ReportingHTML/PDF Export
02 · PENTEST · LIVE PRODUCTION SYSTEM
Eduflex Academy — Authorised Black Box Penetration Test
Authorised black-box pentest against a live Laravel/MySQL application serving 50+ active users. Zero prior knowledge. Identified 12 critical vulnerabilities across authentication, session management, and access control - posing direct risk to student and staff PII. Full professional report mapped to OWASP Top 10 and NIST SP 800-115. Remediation adopted by client.
Live Production12 Critical VulnerabilitiesBurp SuiteNmapSQLMapOWASP Top 10NIST 800-115
03 · FULL-STACK + CLOUD
GBEAAA Church — Secure Platform & AWS Infrastructure
Full-stack React/Node.js provincial management platform with NIST CSF-aligned incident response planning. AWS infrastructure optimised to handle 5,000+ concurrent users.
ReactNode.jsAWSNIST CSFIncident Response
04 · SECURITY TOOL · PYTHON
Ownuh SecurePass Analyzer
Password strength analysis tool evaluating credentials via complexity scoring and Shannon Entropy. Full CI/CD pipeline via GitHub Actions - auto-building binaries for Windows, macOS, and Linux.
PythonShannon EntropyTkinterPyInstallerGitHub ActionsCI/CD
05 · DFIR · PYTHON
File Type Identification System
Forensic tool identifying file types using magic number signatures, MIME types, and extensions - demonstrating core DFIR investigation techniques.
PythonMagic NumbersMIME TypesDFIR
06 · SECURITY RESEARCH · C++
Brute Force Attack Simulator
Multithreaded C++ brute-force simulator using pthreads to benchmark password-cracking attempts-per-second and analyse keyspace complexity - illustrating real attack surfaces for security training.
C++MultithreadingpthreadsPassword Security
07 · TRYHACKME · TOP 3% GLOBAL
TryHackMe — 5 Completed Learning Paths
Completed Pre-Security, Cyber Security 101, Jr. Penetration Tester, Web Fundamentals, and Web Application Pentesting. Ranked globally Top 3% from millions of practitioners worldwide.
Web App PentestingJr. Pentest PathSOC FundamentalsEnumeration
Writing

Research. Opinions.
Field Notes.

HTML-native blog

Long-form writing that shows how I think about risk, security, and responsible AI.

This blog section is built to support full standalone HTML essays, so every article can have its own layout and visual voice without needing a CMS or build step.

0 posts live
Standalone HTML workflow
Loading posts...
Credentials

Verified. Earned.
Proven.

Certified in Cybersecurity (CC)
ISC2
Google Cybersecurity Professional Certificate
Google · Coursera
Google IT Support Professional Certificate
Google · Coursera
IBM Cybersecurity Analyst
IBM · Coursera
Certified Digital Forensic Investigator
Quick Heal
Securing Computer Systems
Quick Heal
Cybersecurity Analyst Job Simulation
Tata · Forage
Introduction to Ethical Hacking
CompTIA
BSc Hons CS – Cyber Security
(CompTIA tie-up) A+, Network+, Linux+, Security+, Pentest+
Lovely Professional University · 2026
TryHackMe — 5 Completed Learning Paths
Jr. Pentest · Web App Pentesting · CS 101 · and more
Recognition

Why I Stand Out

🥇
Top 1% of the Cybersecurity cohort at Lovely Professional University
2023 – 2026
🎯
Ranked Top 3% globally on TryHackMe — millions of practitioners worldwide
2025
💡
12 critical vulnerabilities identified on a live production system — real pentest, not a simulation
2024 – 2025
🏆
Best Information Technology Student — Hoërskool Ben Viljoen
2020 – 2022
📈
35% revenue growth in 3 months at Eduflex Academy through digital transformation
2024
🌍
Grade 11 Sekhukhune District Top 100 · Academic Top 10%
2021
Contact

Let's Work Together

Actively seeking junior roles in SOC, penetration testing, DFIR, and security engineering. Visa sponsorship required. Open to relocation worldwide.

leonakokerai@outlook.com