Skip to content
View Oluwatobi-Mustapha's full-sized avatar

Block or report Oluwatobi-Mustapha

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Oluwatobi-Mustapha/README.md

Hi, I'm Tobi.

Security Engineer | Non-Human Identity | OSS Contributor

I build and secure cloud and distributed systems, with a focus on identity security, least-privilege architecture, threat detection, and incident response.

Member of the AWS Community Builders and The Identity Underground.


Projects

  • Identrail - Machine Identity Security A machine identity security platform for AWS, GitHub/OIDC, and Kubernetes, built to find risky trust paths, repository exposure, and authorization gaps before they become incidents.

  • Boundary - AWS JIT Access Broker A just-in-time access vending engine that reduces provisioning time from days to seconds while generating artifacts needed for SOC 2 audit evidence.

  • AWS Cloud Incident Response Lab Simulates a full-scale AWS attack and investigation, showing how responders trace identity abuse, contain the blast radius, and turn evidence into repeatable recovery actions.

  • IAM Logic Fuzzer A security testing tool that surfaces hidden privilege escalation paths in IAM policies and helps validate controls against CIS AWS benchmarks.


Open Source Contributions

I contribute security fixes to enterprise infrastructure, identity, & cloud governance projects. My full open-source contribution log.

  • HashiCorp Terraform: Fixed web-identity credential precedence in the AWS provider, preventing valid configured tokens from being rejected when environment credentials are also present.

  • Keycloak: Hardened enterprise identity flows across authorization, federation, OIDC, token exchange, session cleanup, and audit pagination, reducing privilege-escalation risk and improving policy and audit reliability.

  • Better Auth: Closed authentication edge cases across OTP, multi-session cookies, cookie encoding, and OpenAPI session contracts, improving resistance to bypass and credential-handling errors.

  • Home Assistant: Hardened integrations and secret handling by removing legacy Supervisor tokens, redacting sensitive error data, and making OAuth refresh failures explicit across core integrations.

  • Authentik: Hardened self-hosted identity workflows by clearing stale authenticator state, clarifying RBAC permissions, decoding OAuth2 credentials correctly, and handling LDAP data variants.

  • Cloud Custodian: Improved cloud-policy enforcement and SecurityHub reporting by preserving AccessDenied semantics, normalizing IAM condition keys, and sanitizing Lambda network configuration.

  • ZITADEL: Corrected unauthenticated v1 gateway responses to return 401, preserving reliable client and security semantics in identity APIs.

  • LeapStack: Security-reviewed an AWS launchpad for AI agents, focusing on the IAM, infrastructure, observability, and cost controls needed to move prototypes toward production.


Certifications

AWS Certified Security - Specialty badge
AWS Certified Security - Specialty
HashiCorp Terraform Associate badge
HashiCorp Terraform Associate
AWS Solutions Architect - Associate badge
AWS Solutions Architect - Associate
CompTIA Security+ badge
CompTIA Security+

Open to Work

I’m open to cloud security, identity security, and security engineering roles.

Blog: https://medium.com/@oluwatobi-mustapha

website: https://oluwatobimustapha.vercel.app

LinkedIn

Pinned Loading

  1. Open-Source-Contributions Open-Source-Contributions Public

    A curated list of my merged open-source PRs.

    3

  2. identrail/identrail identrail/identrail Public

    Machine identity security platform for AWS, GitHub/OIDC, and Kubernetes. Find risky trust paths, repository exposure, and authorization gaps before they become incidents.

    Go 3 3

  3. boundary boundary Public

    Serverless Just-In-Time (JIT) access broker for AWS. Features Slack ChatOps, policy-as-code, and automated zero-trust revocation.

    Python 6 1

  4. iam-fuzzer iam-fuzzer Public

    Automated fuzzing tool for identifying AWS IAM logic flaws, and permission boundaries.

    Python 8