About
Hi! My name is Nguuma, and I'm a Lead AI and Cybersecurity Engineer with over 14 years of experience building secure AI tools, web platforms and cloud systems. My work sits at the intersection of AI engineering and cybersecurity: private LLMs and SLMs, RAG, AI agents, AI evaluation, DevSecOps, SIEM and vulnerability management. I build for environments where privacy, safety and reliability are non-negotiable, across FinTech, healthcare, public sector, broadcasting, and security research, including regulated industries, vulnerable populations and critical infrastructure.
I hold an MSc in Computer Networks and Security from the University of Essex, and I am ISC2 Certified in Cybersecurity (CC), alongside CompTIA Security+, the Google Cybersecurity Professional Certificate and NVIDIA's Domain-Adaptive Pre-Training for LLMs specialisation. Most recently, as AI Specialist and Senior Developer at Purecontent Media, I built the Financial AI Podcast Generator for eToro end to end, cutting episode production from 5 to 8 hours down to 3 to 4 minutes across 106 episodes, with a Bandit security audit returning zero high-severity findings. Before that, I was Technical Lead, AI and Secure Systems at Media Health and Rights Initiative (MHR), where I built PadiChat, a private AI counselling platform, from the first commit to production for young Nigerians seeking sexual and reproductive health support, holding 99.9% uptime and automating over 1,000+ routine counselling inquiries.
I have published three open-source fine-tuned small language models on Hugging Face, each built to run inside an organisation's own infrastructure with no sensitive data leaving the environment. My Security-SLM models covering the full AI attack surface from SOC triage to agentic lateral movement and RAG vector-store poisoning have surpassed 6,600+ combined downloads. I also publish Med-Lab-finetuned, applying the same methodology to clinical laboratory diagnostic reasoning for resource-constrained environments.
Aside from building, I write and speak about AI security and sovereign AI adoption. I have been cited as an AI researcher by The Guardian Nigeria, Daily Trust, Radio Nigeria, and Leadership Nigeria, and quoted by Informatics Magazine, an international technology outlet, on access control for AI systems. I have spoken at GDG Build with AI 2026 and World Creativity and Innovation Day 2026, and I conduct applied research into emerging LLM attack surfaces and secure AI adoption for regulated environments.
My career ambition is to be the engineer and researcher who proves that security and AI capability are not in tension, that the most powerful systems are also the safest ones. I want to help shape the standards by which the world's most sensitive AI deployments are built, and leave behind models, tools and frameworks that make secure AI accessible to the organisations that need it most.
How I got here
Built the Financial AI Podcast Generator end to end from data ingestion to audio output, cutting eToro episode production from 5 to 8 hours to 3 to 4 minutes across 106 episodes. Led Publish24, a multi-agent content platform built with FastAPI, Django REST, Next.js and LangGraph, reducing content generation time by 70% and improving brand-voice consistency by 40% through LoRA and Unsloth fine-tuning, with a Bandit security audit returning zero high-severity findings.
Set the technical direction and built PadiChat from the first codebase to production, a private AI counselling platform offering RAG-based answers, mood tracking, appointments and referrals for young Nigerians seeking SRHR support. Deployed with OWASP-aligned guardrails, prompt-injection controls and data-leakage prevention, holding 99.9% uptime and automating over 1,000 routine counselling inquiries. Wrote the technical part of the grant proposal that won the 2024 RNW Media Innovation Fund, selected from 58 proposals across 31 countries.
Owned the cybersecurity knowledge base behind BizCyberQuest, translating the NCSC Cyber Assessment Framework, its four objectives and fourteen principles, into the decision logic behind every in-game scenario, grounded in research covering 1,400+ UK businesses. Designed the assessment component of CyberSecurityAId end to end, an AI self-assessment tool that turns the NCSC Cyber Essentials framework into personalised guidance for SME owners, trialled across southwest and eastern England and featured at the National Cyber Security Centre's CYBERUK event.
Led architecture and security for the Federal High Court electronic affidavit platform, a SaaS product owned and operated by Century and licensed to the court across 7 states, replacing paper-based workflows with online registration, identity checks and certified document delivery. Dashboards recorded 79,049 submitted applications, 72,771 approvals and over £217,000 in revenue across deployed states as of March 2026. The Federal High Court adopted the system as core digital infrastructure, with the launch reported by Premium Times, Vanguard and The Cable as part of a broader judicial reform effort.
Built the National TB Conference portal and led the secure migration of organisational services to Microsoft 365 and Azure, improving resilience, registration workflows and security management for Nigeria's national tuberculosis response.
Designed and secured FRCN's online news portal and virtual radio infrastructure including core servers, Juniper firewalls, and Azure environments, helping expand digital broadcasting across 7 state capitals for Africa's largest public radio network.
Credentials & affiliations
Media & speaking
Quoted on Nigeria's sovereign AI strategy, low-infrastructure AI systems for critical sectors, and local model deployment in healthcare, finance, and government.
Delivered a technical session on building secure AI agents in Golang. The session was selected and later published on YouTube.
Invited to speak to founders, SME operators, and public leaders on practical AI use in business workflows.
Presented PadiChat as one of two winning projects at the Digital Media Impact Summit 2024, after the platform won the RNW Media Innovation Fund from 58 proposals across 31 countries, and gave subsequent stakeholder updates.
Quoted on access control for AI systems, covering role-based and attribute-based access control (RBAC and ABAC), drawing on my work building PadiChat and CyberSecurityAId.
Invited by the national public broadcaster to discuss how locally adapted AI surveillance could support work against insecurity in Nigeria.
Published comments on AI surveillance, predictive analytics, and national security policy in Nigeria.