About Me

I'm a security engineer who builds and secures cloud and distributed systems, with a focus on making complex environments more observable, resilient, and easier to operate.

My work spans cloud security, identity and access, detection engineering, incident response, vulnerability management, and security automation. Across AWS, Kubernetes, and open-source projects, I investigate attack paths, improve defensive workflows, and turn security findings into practical fixes.

When I'm not working, you'll find me playing chess, solving math problems, or playing FIFA.

B.Eng. Electrical Engineering, Ambrose Alli University · 2020-2025

Experience

Identrail

Founder
Feb 2026 - Present
  • Founded and built a machine identity security platform that maps AWS IAM, GitHub Actions OIDC, and Kubernetes relationships to expose overprivileged workloads, risky trust paths, and clear remediation ownership.
  • Delivered a CLI, Docker image, API, and hosted web application at identrail.com, turning the security model into a deployable workflow.

CloudSec Network

Security Engineer
Apr 2026 - Present
  • Build AI-assisted detection and triage workflows across application, cloud, IAM, CI/CD, and endpoint signals, improving alert quality and investigation context for analysts.
  • Translate security findings into validated remediation guidance and operator-ready workflows, connecting detection design to response and root-cause analysis.

Prodigy InfoTech

Cyber Security Analyst
Mar 2023 - Feb 2024
  • Performed vulnerability assessments and penetration tests on Linux-based targets using Burp Suite, Nmap, and Metasploit, reproducing findings across web and system attack surfaces.
  • Identified OWASP Top 10 risks, including injection, broken authentication, and access-control weaknesses, then produced severity-ranked remediation reports.
  • Supported incident-response investigations and root-cause analysis while hardening Linux systems through firewall and access-control reviews.

Probuilt Tech

Information Security Analyst
Jan 2021 - Feb 2023
  • Helped establish security operations processes as an early security-team member, replacing ad-hoc response with repeatable workflows.
  • Co-authored incident-response playbooks and runbooks covering triage, escalation, containment, recovery, and post-incident review.
  • Standardized vulnerability-management and security-investigation workflows, partnering with engineering to turn findings into actionable remediation.

Projects

Identrail

Open-source machine identity security platform

Gives security teams one explainable view of how repositories, workloads, and cloud roles connect, so overprivileged machine identities and risky trust paths are found before they become incidents.

Preview
Identrail product preview.

Boundary

Serverless AWS access broker

Replaces standing privilege with approval-based, short-lived access that is automatically revoked and easy to audit.

IAM Logic Fuzzer

AWS IAM analysis tool

Catches dangerous IAM policy combinations before deployment, including confused-deputy paths, privilege escalation, public exposure, and permission-boundary flaws.

Architecture diagram
IAM Logic Fuzzer architecture diagram.

AWS Cloud Incident Response Lab

Cloud incident response simulation

Simulates a full-scale AWS attack and investigation, showing how responders trace identity abuse, contain the blast radius, and turn evidence into repeatable recovery actions.

EDR Simulation

Endpoint detection and response lab

Validated endpoint prevention and investigation in a controlled Windows lab by triggering the EICAR test, reviewing quarantine telemetry, and mapping the event to MITRE ATT&CK.

Network Traffic Analysis

Malware traffic investigation

Analyzed a malware-infected PCAP to trace NetSupportRAT command-and-control traffic, extract indicators, identify the compromised user, and connect the activity to its initial access path.

Incident Response Investigation

Endpoint and network forensics

Reconstructed a suspected Qakbot intrusion by correlating PCAP evidence, VirusTotal intelligence, PowerShell file hashes, and Splunk telemetry to confirm exfiltration and trace the attack path.

AWS Honeypot

Cloud threat detection lab

Deployed an internet-facing AWS honeypot and used Kibana telemetry to observe brute-force activity, attacker origins, and real-world probing against exposed SSH and FTP services.

Open Source Contributions

Keycloak
9 PRs

Hardened enterprise identity flows across authorization, federation, OIDC, token exchange, session cleanup, and audit pagination, reducing privilege-escalation risk and improving policy and audit reliability.

View
Better Auth
4 PRs

Closed authentication edge cases across OTP, multi-session cookies, cookie encoding, and OpenAPI session contracts, improving resistance to bypass and credential-handling errors.

View
Home Assistant
6 PRs

Hardened integrations and secret handling by removing legacy Supervisor tokens, redacting sensitive error data, and making OAuth refresh failures explicit across core integrations.

View
HashiCorp Terraform
1 PR

Fixed web-identity credential precedence in the AWS provider, preventing valid configured tokens from being rejected when environment credentials are also present.

View
Authentik
4 PRs

Hardened self-hosted identity workflows by clearing stale authenticator state, clarifying RBAC permissions, decoding OAuth2 credentials correctly, and handling LDAP data variants.

View
Cloud Custodian
3 PRs

Improved cloud-policy enforcement and SecurityHub reporting by preserving AccessDenied semantics, normalizing IAM condition keys, and sanitizing Lambda network configuration.

View
ZITADEL
1 PR

Corrected unauthenticated v1 gateway responses to return 401, preserving reliable client and security semantics in identity APIs.

View
LeapStack
1 PR

Security-reviewed an AWS launchpad for AI agents, focusing on the IAM, infrastructure, observability, and cost controls needed to move prototypes toward production.

View

Testimonials

Bereket Engida

Bereket Engida

Creator of Better Auth

Thank you @Oluwatobi-Mustapha for the PR fix and update, LGTM.

Alexander Schwartz

Alexander Schwartz

Principal Software Engineer at IBM

As I've raised the original issue, I've tested this change it and it works as expected. Thanks, Oluwatobi!

AJ Kerrigan

AJ Kerrigan

Solutions Architect at Stacklet

Thanks for the catch/fix/test Oluwatobi Mustapha 🍻 !

Martin Hjelmare

Martin Hjelmare

Home Assistant Core Developer

Looks good to me, Tobi! Thanks!

Basil Fateen

Basil Fateen

Head of Startups and VC, MENAT at NVIDIA

Thanks for your security review and updates, Oluwatobi!

Teffen Ellis

Teffen Ellis

Senior Full-stack Developer at Authentik Security and sister-software

Thank you sending such a detailed PR, Oluwatobi Mustapha! The changes here look great and align with an ongoing effort to make the flow stages easier to test and reason about.

Marek Posolda

Marek Posolda

Principal Software Engineer at IBM

Thanks for the updates and PR review.

Gayathri Vijayan

Gayathri Vijayan

Software Engineer at ZITADEL

Thank you very much for the contribution, Oluwatobi. Great job! Please keep contributing to Zitadel :)

Kapil Thangavelu

Kapil Thangavelu

Co-Founder & CTO at Stacklet

This looks good to me. Thank you.

Stefan Agner

Stefan Agner

Senior Security Engineer @ Home Assistant

Great work on this. The Unix socket approach has now proven reliable across multiple releases, making the old Supervisor token obsolete. This was a clean and well-timed removal of unnecessary legacy authentication. LGTM 👍

BeryJu

BeryJu

CTO at goauthentik

LGTM.

Pedro Igor

Pedro Igor

Principal Software Engineer @IBM

Thank you, @Oluwatobi-Mustapha for your PR fix and updates. Merged!

Kit Ewbank

Kit Ewbank

Principal Software Engineer @ HashiCorp

LGTM 🚀. @Oluwatobi-Mustapha Thanks for the contribution🎉 👏.

Technical Toolkit

Cloud & Platform Security

AWSAzureKubernetesTerraformDockerPythonGo

Identity & Access

AWS IAMMicrosoft Entra IDOAuth / OIDCSAML / SCIMRBAC / ABACWorkload IdentityJIT

Security Operations

Detection EngineeringIncident ResponseSecurity AutomationSIEM / SOARVulnerability Management

Community

AWS Community Builder

joined as a security engineer.

Learn about the program
The Identity Underground

accepted as a security professional.

Visit community

Let's Connect

Open to opportunities in Cloud Security, Identity Security, Detection Engineering, and Security Operations Engineering.