
Tetrasec
FDEWorking as a forward deployed engineer — embedding directly with SME clients to build AI-powered products with Claude and DeepSeek, ship observable infrastructure, and leave every team with a security posture grounded in what they actually built.
Situation
SMEs across Kenya are under pressure to modernise with AI and automation, but most don't have the internal engineering depth to evaluate, integrate, or deploy these technologies safely. The systems being built — often handling sensitive business and customer data — regularly go live without security review, no observability, and teams with no understanding of the threat surface they've just inherited. The gap between 'we want AI' and 'we have a secure, working system' is where most engagements fall apart.
Task
Embed directly with SME clients as a forward deployed engineer: map their workflows, build AI-powered features using LLM models (Claude, DeepSeek) and modern tooling (Next.js, NestJS, Python, PostgreSQL), instrument everything with observability (Grafana, Prometheus), automate deployment via GitHub Actions, and — during or after each deployment — run security training anchored to what was actually built, covering OWASP, MITRE ATT&CK, and Kenya Data Protection Act obligations.
Action
- 01
Conducted discovery sessions on-site with each client to map their existing workflows, identify the highest-value automation and AI integration points, and scope a build plan that matched their capacity to maintain it.
- 02
Designed and built AI-powered features integrating Claude and DeepSeek APIs into Next.js frontends and NestJS backends — covering prompt engineering, response streaming, context management, and cost-aware usage patterns.
- 03
Architected backend services in NestJS with PostgreSQL, designing schemas and API layers that kept data structured and queryable without creating sprawl as AI features added new data types.
- 04
Wrote Python scripts and automation pipelines to handle data processing, transformation, and integration tasks that didn't belong in the application layer.
- 05
Set up Grafana and Prometheus for each deployment, building dashboards that gave clients real-time visibility into application performance, LLM latency, error rates, and infrastructure health — so anomalies surfaced before users noticed them.
- 06
Built and maintained GitHub Actions CI/CD pipelines that automated testing, linting, and deployment, reducing manual release risk and giving clients a repeatable, auditable process from day one.
- 07
Ran security-in-mind training sessions timed to each deployment, covering the OWASP Top 10 vulnerabilities relevant to the stack in use, MITRE ATT&CK tactics applicable to the client's threat model, and data handling obligations under the Kenya Data Protection Act — always anchored to the code the team had just shipped.
Result
- →
Clients moved from zero AI capability to production systems with working LLM integrations embedded in their core workflows — not demos, but tools their teams used daily.
- →
Every deployment shipped with live observability: clients could see exactly what their applications were doing in real time through Grafana dashboards rather than finding out something was wrong from a user complaint.
- →
Security training landed differently because it was grounded in the client's own codebase and threat model — teams walked away understanding the risk surface of what they specifically built, not a generic slide deck.
- →
Established a consistent delivery pattern across engagements — discover, build, instrument, automate, secure, train — that reduced ramp-up time on each new client and made the handover reliable.