Skip to content
View Oluwatobi-Mustapha's full-sized avatar

Block or report Oluwatobi-Mustapha

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Oluwatobi-Mustapha/README.md

Hi, I'm Tobi.

Security Engineer | Non-Human Identity | OSS Contributor

I build and secure cloud and distributed systems, with a focus on identity security, least-privilege architecture, threat detection, and incident response.

Member of the AWS Community Builders and The Identity Underground.


Projects

  • Identrail - Machine Identity Security A machine identity security platform for AWS, GitHub/OIDC, and Kubernetes, built to find risky trust paths, repository exposure, and authorization gaps before they become incidents.

  • Fintech SOC Assessment An independent 45-page fintech security operations assessment spanning SIEM alert triage, detection engineering, AWS incident response, vulnerability validation and remediation, compliance and posture reporting, and executive security metrics. Used Datadog Cloud SIEM to investigate a 47-signal queue, make evidence-led containment judgments, evaluate KRI/KPI integrity, MTTR and log coverage against SLA, and define responsible AI guardrails without overstating what the data could prove.

  • Boundary - AWS JIT Access Broker A just-in-time access vending engine that reduces provisioning time from days to seconds while generating artifacts needed for SOC 2 audit evidence.

  • AWS Cloud Incident Response Lab Simulates a full-scale AWS attack and investigation, showing how responders trace identity abuse, contain the blast radius, and turn evidence into repeatable recovery actions.

  • IAM Logic Fuzzer A security testing tool that surfaces hidden privilege escalation paths in IAM policies and helps validate controls against CIS AWS benchmarks.

  • EDR Simulation Validated endpoint prevention and investigation in a controlled Windows lab by triggering the EICAR test, reviewing quarantine telemetry, and mapping the event to MITRE ATT&CK

  • Network Traffic Analysis Analyzed a malware-infected PCAP to trace NetSupportRAT command-and-control traffic, extract indicators, identify the compromised user, and connect the activity to its initial access path

  • Incident Response Investigation Reconstructed a suspected Qakbot intrusion by correlating PCAP evidence, VirusTotal intelligence, PowerShell file hashes, and Splunk telemetry to confirm exfiltration and trace the attack path.


Open Source Contributions

I contribute security fixes to enterprise infrastructure, identity, & cloud governance projects. My full open-source contribution log.

  • HashiCorp Terraform: Fixed web-identity credential precedence in the AWS provider, preventing valid configured tokens from being rejected when environment credentials are also present.

  • Keycloak: Hardened enterprise identity flows across authorization, federation, OIDC, token exchange, session cleanup, and audit pagination, reducing privilege-escalation risk and improving policy and audit reliability.

  • Better Auth: Closed authentication edge cases across OTP, multi-session cookies, cookie encoding, and OpenAPI session contracts, improving resistance to bypass and credential-handling errors.

  • Home Assistant: Hardened integrations and secret handling by removing legacy Supervisor tokens, redacting sensitive error data, and making OAuth refresh failures explicit across core integrations.

  • Authentik: Hardened self-hosted identity workflows by clearing stale authenticator state, clarifying RBAC permissions, decoding OAuth2 credentials correctly, and handling LDAP data variants.

  • Cloud Custodian: Improved cloud-policy enforcement and SecurityHub reporting by preserving AccessDenied semantics, normalizing IAM condition keys, and sanitizing Lambda network configuration.

  • ZITADEL: Corrected unauthenticated v1 gateway responses to return 401, preserving reliable client and security semantics in identity APIs.


Certifications

AWS Certified Security - Specialty badge
AWS Certified Security - Specialty
HashiCorp Terraform Associate badge
HashiCorp Terraform Associate
AWS Solutions Architect - Associate badge
AWS Solutions Architect - Associate
CompTIA Security+ badge
CompTIA Security+

Open to Work

I’m open to cloud security, identity security, and security engineering roles.

Blog: https://medium.com/@oluwatobi-mustapha

website: https://oluwatobimustapha.vercel.app

LinkedIn: https://www.linkedin.com/in/oluwatobimustapha

Pinned Loading

  1. identrail/identrail identrail/identrail Public

    Machine identity security platform for AWS, GitHub/OIDC, and Kubernetes. Find risky trust paths, repository exposure, and authorization gaps before they become incidents.

    Go 4 3

  2. boundary boundary Public

    Serverless Just-In-Time (JIT) access broker for AWS. Features Slack ChatOps, policy-as-code, and automated zero-trust revocation.

    Python 13 1

  3. Open-Source-Contributions Open-Source-Contributions Public

    A curated list of my merged open-source PRs.

    4

  4. iam-fuzzer iam-fuzzer Public

    Automated fuzzing tool for identifying AWS IAM logic flaws, and permission boundaries.

    Python 8