I am a security-focused software engineer with experience in building secure SaaS applications, leading DevSecOps initiatives, and embedding security practices across the software development lifecycle. I have a strong foundation in secure authentication, CI/CD security, cloud infrastructure, and incident response. Currently, I am pursuing a Master of Information and Cybersecurity at UC Berkeley. I have worked across multiple sectors including healthcare and fintech in Uganda, the US, and globally, taking leadership roles in security architecture, incident response, and automation. My passion lies in developing secure, scalable applications and leveraging AI-driven systems for cybersecurity innovation.

Gerald Michael Musumba

I am a security-focused software engineer with experience in building secure SaaS applications, leading DevSecOps initiatives, and embedding security practices across the software development lifecycle. I have a strong foundation in secure authentication, CI/CD security, cloud infrastructure, and incident response. Currently, I am pursuing a Master of Information and Cybersecurity at UC Berkeley. I have worked across multiple sectors including healthcare and fintech in Uganda, the US, and globally, taking leadership roles in security architecture, incident response, and automation. My passion lies in developing secure, scalable applications and leveraging AI-driven systems for cybersecurity innovation.

Available to hire

I am a security-focused software engineer with experience in building secure SaaS applications, leading DevSecOps initiatives, and embedding security practices across the software development lifecycle. I have a strong foundation in secure authentication, CI/CD security, cloud infrastructure, and incident response. Currently, I am pursuing a Master of Information and Cybersecurity at UC Berkeley.

I have worked across multiple sectors including healthcare and fintech in Uganda, the US, and globally, taking leadership roles in security architecture, incident response, and automation. My passion lies in developing secure, scalable applications and leveraging AI-driven systems for cybersecurity innovation.

See more

Experience Level

Expert
Expert
Expert
Expert
Expert
Expert
Expert
Expert
Expert
Expert
Expert
Expert
Expert
Intermediate
Intermediate
Intermediate
Intermediate
See more

Work Experience

Software Security Engineer at CentroAccess, SaaS Platform
October 1, 2024 - Present
Developed and enforced a granular roles and permissions system for multi-tenant management using React frontend and Django REST backend APIs. Integrated multiple 2FA methods and led SSO implementation for enterprise customers. Automated CI/CD pipelines with GitHub Actions including tests, container and infrastructure scanning. Built secure infrastructure-as-code deployments with Terraform and standardized environments using Docker, Kubernetes, Helm, Argo Rollouts, EKS, Grafana, and Prometheus. Deployed observability stacks and led incident response efforts, reducing mean-time-to-resolution through proactive log analysis and automated alerts.
Graduate Student Researcher at University of California, Berkeley
July 1, 2024 - August 8, 2025
Collaborated in an 8-person team leveraging AI technologies like LangChain, litellm, ChatGPT, and cloud platforms including GCP and Azure to develop AI-driven cybersecurity defenses. Created a cyber reasoning system capable of automatically remediating vulnerabilities in open-source code.
Software Engineer - Contractor at Turing, Palo Alto, California
January 31, 2024 - August 8, 2025
Maintained and developed web applications for the 'All of Us' research program, collaborating in a global 13-member team. Architected systems to ensure HIPAA compliance and healthcare security standards. Scaled the program from 10,000 to 1.25 million participants. Developed backend REST APIs, optimized Python scripts for large-scale data management, and oversaw data integration projects. Improved code quality with rigorous reviews and active security testing using Semgrep, mypy, Sentry, Honeycomb, and Datadog. Conducted regular penetration testing and remediated vulnerabilities. Collaborated with cross-disciplinary teams to deliver innovative product features.
Software Engineer at Dmark Mobile, Kampala, Uganda
June 30, 2022 - August 8, 2025
Developed secure applications for bulk payments, mobile banking, and value-added services. Managed SMS gateways integrating directly with Airtel and MTN networks. Designed secure APIs for mobile money transactions. Configured, hardened, and maintained AWS Linux servers tailored to banking institutions. Created customer engagement applications using WhatsApp API.
Software Engineer at Asterisint, Kampala, Uganda
December 31, 2021 - August 8, 2025
Led a 5-person engineering team to develop fintech applications simplifying money transfers from diaspora to African families. Integrated CyberSource for Credit and Visa card transactions ensuring PCI compliance. Implemented multi-factor authentication, secure session management, and role-based access with a zero-trust model. Designed and tested RESTful APIs using Laravel. Integrated various African mobile money APIs. Managed and hardened Linux Linode servers for security and reliability.
Software Engineer Intern at Wimea-ICT, Kampala, Uganda
September 30, 2021 - August 8, 2025
Collaborated on agriculture-related research projects partnering with global universities. Enhanced a data aggregation web application for IoT weather stations, adding features for improved data analysis. Contributed to the development of AdEMNEA, a tool for insect pollinator monitoring.
Software Security Engineer at CentroAccess, SaaS Platform
October 1, 2024 - Present
Developed and enforced a custom roles and permissions system for multi-tenant management, implementing granular access control across React front-end pages and Django REST backend APIs. Implemented multiple 2FA methods including email, SMS, authenticator apps, and passkeys; currently leading SSO implementation (SAML/OIDC) for enterprise customers. Automated CI/CD pipelines with GitHub Actions, including SAST, DAST, secret scanning, and container and infrastructure scans. Built secure infrastructure-as-code deployments with Terraform and standardized development environments with Docker, Kubernetes, Helm, and EKS. Deployed observability and logging stacks with Grafana and Prometheus to monitor server logs and detect security anomalies. Led incident response efforts, significantly reducing mean-time-to-resolution through proactive log analysis and automated alerts.
Graduate Student Researcher at University of California, Berkeley
July 1, 2024 - August 8, 2025
Collaborated as a member of an 8-person team at UC Berkeley to innovate AI-driven cybersecurity defenses. Developed cyber reasoning systems using LangChain, litellm, ChatGPT, anthropic, GCP, Azure, Gemini, Lama, RabbitMQ, and other technologies, aimed at automatically remediating vulnerabilities in open-source code.
Software Engineer - Contractor at Turing, Palo Alto, California
January 1, 2024 - August 8, 2025
Maintained and developed five web applications for the 'All of Us' research program and genetic product for healthcare client Color Health. Collaborated in a 13-member global team to deliver scalable web applications using Python, Django, React.js, TypeScript, and Material-UI. Architected systems for HIPAA compliance and healthcare security standards. Scaled research program participant base to 1.25 million. Developed backend REST APIs and oversaw data integration projects. Conducted code reviews and proactive debugging, streamlined development processes, and reduced security vulnerabilities using SAST, DAST, and SCA testing tools including Semgrep and Mypy, supported by active monitoring with Sentry, Honeycomb, and Datadog. Conducted frequent penetration tests and remediated vulnerabilities. Coordinated cross-functional collaboration with product managers, genetic counselors, doctors, and engineers to launch innovative features and critical fixes.
Software Engineer at Dmark Mobile, Kampala, Uganda
June 30, 2022 - August 8, 2025
Developed new software capabilities including bulk payments, mobile banking, value-added services, and custom solutions. Managed SMS gateways with direct API connections to Airtel and MTN networks. Designed and maintained secure APIs for mobile money transactions facilitating seamless financial interactions. Led configuration, hardening, and maintenance of AWS Linux servers customized for banking needs. Developed innovative WhatsApp API applications to improve customer engagement.
Software Engineer at Asterisint, Kampala, Uganda
December 31, 2021 - August 8, 2025
Led a team of five engineers to develop fintech solutions simplifying money transfers from the diaspora to African families. Integrated CyberSource payment platform ensuring PCI compliance. Implemented multi-factor authentication, secure session management, and role-based access control based on least privilege and zero trust principles. Designed and tested RESTful API endpoints with Laravel and Postman. Integrated various African mobile money APIs enabling seamless transfers. Managed and secured Linux Linode servers for performance and reliability.
Software Engineer Intern at Wimea-ICT, Kampala, Uganda
September 30, 2021 - August 8, 2025
Collaborated on agriculture-related research projects with global university partnerships. Enhanced a data aggregation web application for IoT weather stations by adding features for improved data collection and analysis. Contributed to the development of AdEMNEA, a tool for insect pollinator monitoring, working closely with fellow engineers.

Education

Master of Information and Cybersecurity at University of California, Berkeley, School of Information
January 1, 2024 - January 1, 2025
Bachelor of Science in Software Engineering at Makerere University
January 1, 2020 - January 1, 2023
Bachelor of Science in Cyber Security at Isbat University
January 1, 2019 - January 1, 2021
Master of Information and Cybersecurity at University of California, Berkeley, School of Information
January 1, 2024 - January 1, 2025
Bachelor of Science in Software Engineering at Makerere University
January 1, 2020 - January 1, 2023
Bachelor of Science in Cyber Security at Isbat University
January 1, 2018 - January 1, 2021

Qualifications

Graduate Certificate in Applied Data Science
January 1, 2024 - August 8, 2025
Graduate Certificate in Applied Data Science
January 1, 2024 - August 8, 2025

Industry Experience

Software & Internet, Healthcare, Financial Services, Education, Government, Professional Services