Vannessa Tukundane - Security Lead

Hello, I'm Vannessa Tukundane

🛡️ Security Lead & GRC Specialist

I lead PureHosts' security operations — from proactive threat hunting to incident response. My mission: keep every server, every site, and every customer data impregnable.

Fail2ban / CrowdSec SSL/TLS (Let's Encrypt) Firewalld / iptables SSH Hardening DKIM/SPF/DMARC Vulnerability Scanning

🔐 Defense-in-Depth Strategy

PureHosts employs a multi-layered security approach: network firewalls, host-based intrusion detection (Fail2ban, CrowdSec), regular vulnerability scans, and strict access controls. I lead the implementation of CIS benchmarks and continuous compliance monitoring.

We also enforce SSL/TLS encryption everywhere, automated certificate renewals, and email authentication (DKIM/SPF/DMARC) to prevent spoofing. Security isn't a product — it's a mindset.

Cybersecurity concept with firewall and lock

⚔️ Security Arsenal

Tools & frameworks I use to safeguard PureHosts infrastructure

🛡️

System Hardening

Linux kernel tuning, SELinux, SSH key-only auth, and automated patch management.

🔍

Threat Detection

Fail2ban, CrowdSec, OSSEC, real-time log analysis, and SIEM integration.

🔐

Cryptography & PKI

Let's Encrypt automation, mutual TLS, certificate lifecycle management.

📋

Compliance & Audits

GDPR readiness, security policy drafting, and internal penetration testing.

📋 My Core Responsibilities @ PureHosts

🛡️ Security Hardening

Implementing and maintaining server hardening standards, including fail2ban, SSH key authentication, and firewall rules on all VPS instances.

🔒 SSL/TLS Management

Automating Let's Encrypt certificate issuance and renewal for all domains, subdomains, and internal services.

🚨 Incident Response

24/7 monitoring of security logs, immediate response to intrusion attempts, and post-mortem analysis.

📋 Security Policies

Developing and enforcing company-wide security policies, access controls, and regular security awareness training.