About Me

Tobi builds and secures cloud and distributed systems, with a focus on identity security, least-privilege architecture, threat detection, and incident response.

He works across AWS, Kubernetes, and cloud-native environments, using technologies such as IRSA, Kubernetes ServiceAccounts, workload identity federation, managed identities, and policy-as-code to reduce excessive access and enforce least privilege at scale.

He also builds security detections and automation to identify misconfigurations, shadow administrators, privilege-escalation paths, suspicious activity, and cloud security risks before they become major incidents.

His work combines security operations, detection engineering, vulnerability management, and automated response to improve visibility, reduce risk, and strengthen cloud security posture.

B.Eng. Electrical Engineering, Ambrose Alli University · 2020-2025

Experience

Identrail

Founder & CEO
Feb 2026 - Present
Remote
Machine IdentityAWSGitHub/OIDCKubernetes

Key contributions

  • Identrail is an open-source machine identity security platform. It maps trust paths across AWS, GitHub/OIDC, and Kubernetes, and turns repository exposure and authorization gaps into findings with owners, evidence, and remediation steps.
  • Ships as a CLI, Docker image, API, and hosted web app at identrail.com

CloudSec Network

AI Security Freelance
Apr 2026 - Present
Remote
AI SecurityDetection WorkflowsDefensive OperationsApplied Analysis

Key contributions

  • Building AI-assisted detection and triage workflows that give analysts better alerts and clearer remediation context.

Prodigy InfoTech

Cyber Security Analyst
Jan 2024 - Feb 2025
Remote
Burp SuiteNmapMetasploitLinux

Key contributions

  • Performed vulnerability assessments and penetration tests on Linux-based targets, and wrote findings with reproduction steps and clear remediation guidance.

Probuilt Tech

Data Analyst
Feb 2022 - Apr 2024
Remote
SQLValidationData QualityTroubleshooting

Key contributions

  • Built SQL validation pipelines and repeatable data-quality checks for backend workflows.

Projects

Boundary

Serverless AWS access broker

Boundary turns access requests into short-lived IAM Identity Center assignments with approval routing, automatic revocation, and reviewable audit evidence.

ImpactReduced privileged access turnaround from days to seconds using approval-based short-lived grants.

Highlights

Routes request, approval, grant, and revoke stages through one workflow
Temporary access by default instead of standing privilege
Keeps request, assignment, and expiry events reviewable

IAM Logic Fuzzer

AWS IAM analysis tool

IAM Logic Fuzzer pressure-tests AWS IAM policies before deployment and reports confused deputy risk, escalation paths, public exposure, and permission-boundary flaws.

ImpactDetects 4 IAM flaw classes pre-deployment so escalation paths are caught before merge.

Hide Architecture DiagramView Architecture Diagram
Flow: Terraform-provisioned IAM test roles are collected and analyzed by the engine, then rendered into HTML findings.

Highlights

Normalizes trust and permission documents into an explainable analysis model
Deterministic rule engine with JSON findings and HTML reporting
Built to catch risky trust-plus-permission paths before merge

Testimonials

Alexander Schwartz

Alexander Schwartz

Principal Software Engineer at IBM

As I've raised the original issue, I've tested this change it and it works as expected. Thanks, Oluwatobi!

Marek Posolda

Marek Posolda

Principal Software Engineer at IBM

Thanks for the updates and PR review.

Pedro Igor

Pedro Igor

Principal Software Engineer @IBM

Thank you, @Oluwatobi-Mustapha for your PR fix and updates. Merged!

Bereket Engida

Bereket Engida

Creator of Better Auth

Thank you @Oluwatobi-Mustapha for the PR fix and update, LGTM.

AJ Kerrigan

AJ Kerrigan

Solutions Architect at Stacklet

Thanks for the catch/fix/test Oluwatobi Mustapha 🍻 !

Kapil Thangavelu

Kapil Thangavelu

Co-Founder & CTO at Stacklet

This looks good to me. Thank you.

Martin Hjelmare

Martin Hjelmare

Home Assistant Core Developer

Looks good to me, Tobi! Thanks!

Basil Fateen

Basil Fateen

Head of Startups and VC, MENAT at NVIDIA

Thanks for your security review and updates, Oluwatobi!

Teffen Ellis

Teffen Ellis

Senior Full-stack Developer at Authentik Security and sister-software

Thank you sending such a detailed PR, Oluwatobi Mustapha! The changes here look great and align with an ongoing effort to make the flow stages easier to test and reason about.

Gayathri Vijayan

Gayathri Vijayan

Software Engineer at ZITADEL

Thank you very much for the contribution, Oluwatobi. Great job! Please keep contributing to Zitadel :)

BeryJu

BeryJu

CTO at goauthentik

LGTM.

Technical Toolkit

Cloud Security

AWSAzureKubernetesTerraformHelmPolicy-as-CodeLeast PrivilegeCloud Misconfiguration Review

Identity & Access

AWS IAMIAM Identity CenterMicrosoft Entra IDOAuthOIDCRBACABACWorkload IdentityIRSAManaged Identities

Detection & Response

Detection EngineeringIncident ResponseSecurity AutomationVulnerability ManagementPrivilege Escalation AnalysisThreat DetectionPythonGo

Let's Connect

Open to opportunities in Cloud Security, Identity Security, Detection Engineering, and Security Operations Engineering.