About Me

I'm a security engineer who builds and secures cloud and distributed systems, with a focus on making complex environments more observable, resilient, and easier to operate.

My work spans cloud security, identity and access, detection engineering, incident response, vulnerability management, and security automation. Across AWS, Kubernetes, and open-source projects, I investigate attack paths, improve defensive workflows, and turn security findings into practical fixes.

When I'm not working, you'll find me playing chess, solving math problems, or playing FIFA.

B.Eng. Electrical Engineering, Ambrose Alli University

Experience

Identrail

Founder
Feb 2026 - Present
  • Founded and built a machine identity security platform that maps AWS IAM, GitHub Actions OIDC, and Kubernetes relationships to expose overprivileged workloads, risky trust paths, and clear remediation ownership.
  • Delivered a CLI, Docker image, API, and hosted web application at identrail.com, turning the security model into a deployable workflow.

CloudSec Network

Security Engineer
Apr 2026 - Present
  • Build AI-assisted detection and triage workflows across application, cloud, IAM, CI/CD, and endpoint signals, improving alert quality and investigation context for analysts.
  • Translate security findings into validated remediation guidance and operator-ready workflows, connecting detection design to response and root-cause analysis.

Independent

Cloud & Identity Security Engineer
Feb 2024 - Feb 2026
  • Delivered cloud and identity security engineering across AWS, Keycloak, Terraform, Authentik, Better Auth, and Cloud Custodian.
  • Contributed upstream security fixes for authentication, OTP-bypass, and IAM-monitoring issues, and built JIT-access and privilege-analysis tooling.

Prodigy InfoTech

Cyber Security Analyst
Mar 2023 - Feb 2024
  • Performed vulnerability assessments and penetration tests on Linux-based targets using Burp Suite, Nmap, and Metasploit, reproducing findings across web and system attack surfaces.
  • Identified OWASP Top 10 risks, including injection, broken authentication, and access-control weaknesses, then produced severity-ranked remediation reports.
  • Supported incident-response investigations and root-cause analysis while hardening Linux systems through firewall and access-control reviews.

Probuilt Tech

Information Security Analyst
Jan 2021 - Feb 2023
  • Helped establish security operations processes as an early security-team member, replacing ad-hoc response with repeatable workflows.
  • Co-authored incident-response playbooks and runbooks covering triage, escalation, containment, recovery, and post-incident review.
  • Standardized vulnerability-management and security-investigation workflows, partnering with engineering to turn findings into actionable remediation.

Projects

Identrail

Open-source machine identity security platform

Gives security teams one explainable view of how repositories, workloads, and cloud roles connect, so overprivileged machine identities and risky trust paths are found before they become incidents.

Preview
Identrail product preview.

Fintech SOC Assessment

45-page fintech SOC assessment

Conducted an independent 45-page fintech security operations assessment spanning SIEM alert triage, detection engineering, AWS incident response, vulnerability validation and remediation, compliance and posture reporting, and executive security metrics. Used Datadog Cloud SIEM to investigate a 47-signal queue, make evidence-led containment judgments, evaluate KRI/KPI integrity, MTTR and log coverage against SLA, and define responsible AI guardrails without overstating what the data could prove.

Boundary

Serverless AWS access broker

Replaces standing privilege with approval-based, short-lived access that is automatically revoked and easy to audit.

IAM Logic Fuzzer

AWS IAM analysis tool

Catches dangerous IAM policy combinations before deployment, including confused-deputy paths, privilege escalation, public exposure, and permission-boundary flaws.

Architecture diagram
IAM Logic Fuzzer architecture diagram.

Modernizing EKS Workload Identity

IRSA-to-Pod Identity migration

Conducted a hands-on migration from OIDC-based IRSA to Amazon EKS Pod Identity, preserving least-privilege IAM access while validating STS credential delivery and private S3 access.

Architecture diagram
EKS Pod Identity architecture and workload-to-S3 access path.

EDR Simulation

Endpoint detection and response lab

Validated endpoint prevention and investigation in a controlled Windows lab by triggering the EICAR test, reviewing quarantine telemetry, and mapping the event to MITRE ATT&CK.

Network Traffic Analysis

Malware traffic investigation

Analyzed a malware-infected PCAP to trace NetSupportRAT command-and-control traffic, extract indicators, identify the compromised user, and connect the activity to its initial access path.

Incident Response Investigation

Endpoint and network forensics

Reconstructed a suspected Qakbot intrusion by correlating PCAP evidence, VirusTotal intelligence, PowerShell file hashes, and Splunk telemetry to confirm exfiltration and trace the attack path.

AWS Honeypot

Cloud threat detection lab

Deployed an internet-facing AWS honeypot and used Kibana telemetry to observe brute-force activity, attacker origins, and real-world probing against exposed SSH and FTP services.

Open Source Contributions

Keycloak
10 PRs

Hardened enterprise identity flows across authorization, federation, OIDC, token exchange, session cleanup, and audit pagination, reducing privilege-escalation risk and improving policy and audit reliability. Most recently, restricted Twitter request-token deserialization to expected classes, reducing unsafe-input risk without disrupting valid callbacks.

View
Better Auth
4 PRs

Closed four authentication edge cases: blocked race-condition reuse of one-time codes, enabled session activation using signed multi-session cookies, preserved cookie values during refresh, and aligned session responses with OpenAPI 3.1, improving account security and client interoperability.

View
Home Assistant
6 PRs

Across six fixes, improved OAuth recovery and integration reliability: distinguished reauthentication from transient Google token failures, normalized Hive usernames, surfaced failed Abode actions, removed legacy Supervisor refresh tokens, and redacted sensitive Z-Wave add-on errors.

View
HashiCorp Terraform
1 PR

Fixed AWS provider credential precedence so an explicitly configured web-identity token is not rejected when an environment token file is present, while preserving validation for conflicting sources and existing environment-only configurations.

View
Authentik
4 PRs

Improved identity and administration flows across four fixes: reset stale MFA challenge selections, disambiguated duplicate RBAC permissions, decoded form-encoded OAuth client credentials correctly, and handled list-valued FreeIPA password-change timestamps during LDAP sync.

View
Cloud Custodian
3 PRs

Strengthened three cloud-governance paths: matched IAM condition keys using AWS case-insensitive semantics, preserved genuine AccessDenied errors during user lookup, and sanitized Lambda VPC data so Security Hub findings pass schema validation.

View
ZITADEL
1 PR

Fixed v1 gateway error translation to preserve native gRPC authentication statuses, so unauthenticated API requests return HTTP 401 instead of 500; aligned activity reporting and added regression coverage across the converter, middleware, and gateway.

View
LeapStack
1 PR

Security-reviewed LEAP Stacks, an AWS launchpad for AI agents, with attention to IAM boundaries, infrastructure deployment, observability, and cost controls, providing practical safeguards when evaluating prototypes under real cloud conditions.

View

Testimonials

Bereket Engida

Bereket Engida

CEO of Better Auth

Thank you @Oluwatobi-Mustapha for the PR fix and update, LGTM.

Alexander Schwartz

Alexander Schwartz

Principal Software Engineer at IBM

As I've raised the original issue, I've tested this change it and it works as expected. Thanks, Oluwatobi!

AJ Kerrigan

AJ Kerrigan

Solutions Architect at Stacklet

Thanks for the catch/fix/test Oluwatobi Mustapha ๐Ÿป !

Martin Hjelmare

Martin Hjelmare

Home Assistant Core Developer

Looks good to me, Tobi! Thanks!

Basil Fateen

Basil Fateen

Head of Startups and VC, MENAT at NVIDIA

Thanks for your security review and updates, Oluwatobi!

Victor Wilkis-Ehizojie

Victor Wilkis-Ehizojie

AI Fraud Detection Consultant @ Probuilt Tech

I worked with Oluwatobi at Probuilt Tech and always found him easy to work with. He helped us improve how we handled security issues, from incident response to vulnerability management, and worked well with the engineering team whenever fixes were needed. He was proactive, practical, and someone I could rely on.

Teffen Ellis

Teffen Ellis

Senior Full-stack Developer at Authentik Security and sister-software

Thank you sending such a detailed PR, Oluwatobi Mustapha! The changes here look great and align with an ongoing effort to make the flow stages easier to test and reason about.

Marek Posolda

Marek Posolda

Principal Software Engineer at IBM

Thanks for the updates and PR review.

Gayathri Vijayan

Gayathri Vijayan

Software Engineer at ZITADEL

Thank you very much for the contribution, Oluwatobi. Great job! Please keep contributing to Zitadel :)

Kapil Thangavelu

Kapil Thangavelu

Co-Founder & CTO at Stacklet

This looks good to me. Thank you.

Stefan Agner

Stefan Agner

Senior Security Engineer @ Home Assistant

Great work on this. The Unix socket approach has now proven reliable across multiple releases, making the old Supervisor token obsolete. This was a clean and well-timed removal of unnecessary legacy authentication. LGTM ๐Ÿ‘

Pedro Igor

Pedro Igor

Principal Software Engineer @IBM

Thank you, @Oluwatobi-Mustapha for your PR fix and updates. Merged!

Kit Ewbank

Kit Ewbank

Principal Software Engineer @ HashiCorp

LGTM ๐Ÿš€. @Oluwatobi-Mustapha Thanks for the contribution๐ŸŽ‰ ๐Ÿ‘.

Stan Silvert

Stan Silvert

Principal Core Developer at Red Hat

LGTM. Copilot and Claude also agree it's ready to merge.

Technical Toolkit

Cloud & Platform Security

AWSAzureKubernetesTerraformDockerPythonGoJavaGitHubDatadog

Identity & Access

AWS IAMMicrosoft Entra IDOAuth / OIDCSAML / SCIMRBAC / ABACWorkload IdentityJIT

Security Operations

Detection EngineeringIncident ResponseSecurity AutomationSIEM / SOARVulnerability Management

Community

AWS Community Builder

joined as a security engineer.

Learn about the program
The Identity Underground

accepted as a security professional.

Visit community

Let's Connect

Open to opportunities in Cloud Security, Identity Security, Detection Engineering, and Security Operations Engineering.