Summary
Overview
Work History
Education
Skills
Certification
Accomplishments
9. Languages
Timeline
Generic

Elvir Joss Sam Junior Ninteretse

Bujumbura

Summary

Cybersecurity Specialist with a sharp eye for risk and a passion for resilience. Skilled in penetration testing, incident response, and vulnerability management, I help organizations stay ahead of evolving cyber threats. I bring a strong understanding of security frameworks (ISO 27001, PCI DSS, NIST) and apply them with both precision and practicality. Known for being risk-averse but solution-driven, I balance governance with agility — ensuring systems stay secure without slowing the business down.

Overview

5
5
years of professional experience
1
1
Certification

Work History

ICT Risk and Cyber Security Specialist

CRDB Bank Burundi
05.2025 - Current

Cybersecurity Operations

  • Monitor and assess the bank’s cybersecurity posture across infrastructure and digital assets.
  • Conduct vulnerability assessments and internal security scans (network, system, and application).
  • Lead vulnerability management efforts: ensure timely remediation of vulnerabilities within defined SLAs, track remediation status, and share monthly reports with management.
  • Oversee patch and configuration reviews to ensure compatibility and secure deployment.
  • Support the deployment and tuning of tools like Imperva WAF, Radware, and Airgap Solution
  • Collaborate with IT operations to improve system hardening, firewall rules, and endpoint protection.
Governance, Risk, and Compliance (GRC)
  • Develop and maintain the ICT risk register and perform periodic risk assessments.
  • Design and implement templates and frameworks to assess:
    Cybersecurity maturity
    ICT risk maturity
    Risk appetite and tolerance thresholds
  • Map technical controls to compliance standards (ISO 27001:2022, NIST CSF, PCI DSS).
  • Lead compliance documentation and audit readiness for both internal and external review.
  • Advise on secure process improvements to align with governance best practices.
Security Strategy & Reporting
  • Draft baseline reports (e.g., Zero-Day Baseline, Risk Heat Maps) to reflect ICT risk posture.
  • Contribute to the security roadmap, BIA sessions, and change management risk reviews.
  • Analyze insider threats, DDoS exposure, and segmentation strategies for all Bank's systems
Security Awareness & Advisory
  • Engage in awareness efforts to educate teams on phishing, secure access, and secure-by-design principles.
  • Coordinate with TZ headquarters on change control, domain-integrated systems, and failover scenarios.


Technical Environment:

Imperva WAF | Radware | Nessus | CyberArk | ISO 27001:2022 | NIST CSF | PCI DSS | Risk Register Management | Risk Heat Maps

Data analyst Intern

Kahawatu Foundation Burundi
01.2025 - 04.2025
  • 1. Data Collection
  • Collected field data from coffee farmers, partners, and other relevant stakeholders.
  • Verified the quality of the collected data, ensuring its reliability and completeness.
  • 2. Data Analysis
  • Contributed to the quantitative and qualitative analysis of data to assess project progress.
  • Assisted in interpreting results to provide actionable insights for project improvement.
  • Prepared reports and dashboards based on collected data.
  • 3. Reporting and Documentation
  • Contributed to drafting periodic activity and evaluation reports.
  • Documented best practices, lessons learned, and key findings.
  • Assisted in preparing presentations for internal meetings and partner discussions.
  • Supported the preparation of bank reconciliations.
  • Assisted in developing reports and visualizations using Excel and Tableau.
  • Analyzed data sets to identify trends and insights for program evaluation.
  • Conducted surveys and interviews to gather qualitative data for project assessments.
  • Collaborated with team members to ensure accurate data entry and management.
  • Supported data cleaning processes to enhance database integrity and reliability.
  • Participated in meetings to present findings and recommend actionable strategies.

Cyber Security Analyst Intern

Tracom Services Limited
04.2024 - 08.2024
  • Conducted penetration testing and vulnerability assessments in compliance with ISO 27001 and PCI DSS standards.
  • Led penetration testing documentation efforts, refining security architecture in collaboration with the senior network administrator and contributing to the Fortinet firewall configuration for enhanced network defense.
  • Gained hands-on experience in compliance frameworks by working closely with external PCI DSS assessors, deepening knowledge of security auditing tools such as Qualys.
  • Deployed and maintained SIEM solutions to monitor security incidents and ensure real-time response to cybersecurity threats.
  • Enhanced e-tax compliance security by working on a project destined to implementing encryption techniques such as SHA-256 and reverse engineering to secure taxpayer data, similar to KRA’s e-system in Kenya.
  • Educated staff on security awareness, including phishing detection and password hygiene.
  • Analyzed security incidents and vulnerabilities to enhance overall system protection.
  • Monitored network traffic for suspicious activity, identifying potential threats proactively.

Web Developer

Ihelá Credit Union
06.2020 - 08.2020
  • Developed secure web applications using HTML, CSS, Python, and Django.
  • Built employee login platforms with integrated security features.

Education

Bachelor of Science - Information Technology

United States International University of Africa
10.2024

High School Diploma - undefined

Riviera High School
11.2019

Ordinary Level (O’Level) - undefined

College Amis Des Enfants
11.2016

High School - undefined

Ecole Saint Michel Archange
05.2015

Skills

  • Penetration Testing & Vulnerability Assessments (eg, Zenmap, Wireshark, Nikto, Nessus, Nuclei)
  • ISO 27001, PCI DSS Compliance
  • SIEM Solutions (eg, Splunk, IBM QRadar, Qualys)
  • Encryption Protocols (SSL/TLS, PGP)
  • Firewalls & Intrusion Detection/Prevention Systems (IDPS) (eg, Suricata)
  • Cloud & Platforms: Microsoft Azure, Microsoft Power Automate, GitHub, MySQL
  • Governance, Risk and Compliance
  • Vulnerability and Patch Management
  • Security Architecture & Controls Implementation
  • Security Operations & Monitoring

Certification

  • Network Defense - Cisco – June 2024
  • Cyber Threat Management - Cisco – May 2024
  • Ethical Hacking Essentials – EC Council – April 2024

Accomplishments

  • Improved network architecture; increased efficiency, reduced latency, and enhanced system reliability.
  • Created and executed penetration tests aligned with PCI DSS v4.0 and ISO 27001:2022.
  • Built a structured reporting mechanism to track and communicate penetration testing results.
  • Implemented encryption in application systems; strengthened data security and compliance.

9. Languages

English
French

Timeline

ICT Risk and Cyber Security Specialist

CRDB Bank Burundi
05.2025 - Current

Data analyst Intern

Kahawatu Foundation Burundi
01.2025 - 04.2025

Cyber Security Analyst Intern

Tracom Services Limited
04.2024 - 08.2024

Web Developer

Ihelá Credit Union
06.2020 - 08.2020

High School Diploma - undefined

Riviera High School

Ordinary Level (O’Level) - undefined

College Amis Des Enfants

High School - undefined

Ecole Saint Michel Archange

Bachelor of Science - Information Technology

United States International University of Africa