- Founded and built a machine identity security platform that maps AWS IAM, GitHub Actions OIDC, and Kubernetes relationships to expose overprivileged workloads, risky trust paths, and clear remediation ownership.
- Delivered a CLI, Docker image, API, and hosted web application at identrail.com, turning the security model into a deployable workflow.
Oluwatobi Mustapha
About Me
I'm a security engineer who builds and secures cloud and distributed systems, with a focus on making complex environments more observable, resilient, and easier to operate.
My work spans cloud security, identity and access, detection engineering, incident response, vulnerability management, and security automation. Across AWS, Kubernetes, and open-source projects, I investigate attack paths, improve defensive workflows, and turn security findings into practical fixes.
When I'm not working, you'll find me playing chess, solving math problems, or playing FIFA.
Experience
- Build AI-assisted detection and triage workflows across application, cloud, IAM, CI/CD, and endpoint signals, improving alert quality and investigation context for analysts.
- Translate security findings into validated remediation guidance and operator-ready workflows, connecting detection design to response and root-cause analysis.
- Performed vulnerability assessments and penetration tests on Linux-based targets using Burp Suite, Nmap, and Metasploit, reproducing findings across web and system attack surfaces.
- Identified OWASP Top 10 risks, including injection, broken authentication, and access-control weaknesses, then produced severity-ranked remediation reports.
- Supported incident-response investigations and root-cause analysis while hardening Linux systems through firewall and access-control reviews.
- Helped establish security operations processes as an early security-team member, replacing ad-hoc response with repeatable workflows.
- Co-authored incident-response playbooks and runbooks covering triage, escalation, containment, recovery, and post-incident review.
- Standardized vulnerability-management and security-investigation workflows, partnering with engineering to turn findings into actionable remediation.
Projects
Identrail
Open-source machine identity security platformGives security teams one explainable view of how repositories, workloads, and cloud roles connect, so overprivileged machine identities and risky trust paths are found before they become incidents.
Preview
Boundary
Serverless AWS access brokerReplaces standing privilege with approval-based, short-lived access that is automatically revoked and easy to audit.
IAM Logic Fuzzer
AWS IAM analysis toolCatches dangerous IAM policy combinations before deployment, including confused-deputy paths, privilege escalation, public exposure, and permission-boundary flaws.
Architecture diagram
AWS Cloud Incident Response Lab
Cloud incident response simulationSimulates a full-scale AWS attack and investigation, showing how responders trace identity abuse, contain the blast radius, and turn evidence into repeatable recovery actions.
EDR Simulation
Endpoint detection and response labValidated endpoint prevention and investigation in a controlled Windows lab by triggering the EICAR test, reviewing quarantine telemetry, and mapping the event to MITRE ATT&CK.
Network Traffic Analysis
Malware traffic investigationAnalyzed a malware-infected PCAP to trace NetSupportRAT command-and-control traffic, extract indicators, identify the compromised user, and connect the activity to its initial access path.
Incident Response Investigation
Endpoint and network forensicsReconstructed a suspected Qakbot intrusion by correlating PCAP evidence, VirusTotal intelligence, PowerShell file hashes, and Splunk telemetry to confirm exfiltration and trace the attack path.
AWS Honeypot
Cloud threat detection labDeployed an internet-facing AWS honeypot and used Kibana telemetry to observe brute-force activity, attacker origins, and real-world probing against exposed SSH and FTP services.
Open Source Contributions
Hardened enterprise identity flows across authorization, federation, OIDC, token exchange, session cleanup, and audit pagination, reducing privilege-escalation risk and improving policy and audit reliability.
ViewClosed authentication edge cases across OTP, multi-session cookies, cookie encoding, and OpenAPI session contracts, improving resistance to bypass and credential-handling errors.
ViewHardened integrations and secret handling by removing legacy Supervisor tokens, redacting sensitive error data, and making OAuth refresh failures explicit across core integrations.
ViewFixed web-identity credential precedence in the AWS provider, preventing valid configured tokens from being rejected when environment credentials are also present.
ViewHardened self-hosted identity workflows by clearing stale authenticator state, clarifying RBAC permissions, decoding OAuth2 credentials correctly, and handling LDAP data variants.
ViewImproved cloud-policy enforcement and SecurityHub reporting by preserving AccessDenied semantics, normalizing IAM condition keys, and sanitizing Lambda network configuration.
ViewCorrected unauthenticated v1 gateway responses to return 401, preserving reliable client and security semantics in identity APIs.
ViewSecurity-reviewed an AWS launchpad for AI agents, focusing on the IAM, infrastructure, observability, and cost controls needed to move prototypes toward production.
ViewTestimonials

Bereket Engida
Creator of Better Auth
Thank you @Oluwatobi-Mustapha for the PR fix and update, LGTM.

Alexander Schwartz
Principal Software Engineer at IBM
As I've raised the original issue, I've tested this change it and it works as expected. Thanks, Oluwatobi!

AJ Kerrigan
Solutions Architect at Stacklet
Thanks for the catch/fix/test Oluwatobi Mustapha 🍻 !

Martin Hjelmare
Home Assistant Core Developer
Looks good to me, Tobi! Thanks!

Basil Fateen
Head of Startups and VC, MENAT at NVIDIA
Thanks for your security review and updates, Oluwatobi!

Teffen Ellis
Senior Full-stack Developer at Authentik Security and sister-software
Thank you sending such a detailed PR, Oluwatobi Mustapha! The changes here look great and align with an ongoing effort to make the flow stages easier to test and reason about.

Marek Posolda
Principal Software Engineer at IBM
Thanks for the updates and PR review.

Gayathri Vijayan
Software Engineer at ZITADEL
Thank you very much for the contribution, Oluwatobi. Great job! Please keep contributing to Zitadel :)

Kapil Thangavelu
Co-Founder & CTO at Stacklet
This looks good to me. Thank you.

Stefan Agner
Senior Security Engineer @ Home Assistant
Great work on this. The Unix socket approach has now proven reliable across multiple releases, making the old Supervisor token obsolete. This was a clean and well-timed removal of unnecessary legacy authentication. LGTM 👍

BeryJu
CTO at goauthentik
LGTM.

Pedro Igor
Principal Software Engineer @IBM
Thank you, @Oluwatobi-Mustapha for your PR fix and updates. Merged!

Kit Ewbank
Principal Software Engineer @ HashiCorp
LGTM 🚀. @Oluwatobi-Mustapha Thanks for the contribution🎉 👏.
Technical Toolkit
Cloud & Platform Security
Identity & Access
Security Operations
Community
Let's Connect
Open to opportunities in Cloud Security, Identity Security, Detection Engineering, and Security Operations Engineering.




