Security Engineer | Non-Human Identity | OSS Contributor
I build and secure cloud and distributed systems, with a focus on identity security, least-privilege architecture, threat detection, and incident response.
Member of the AWS Community Builders and The Identity Underground.
-
Identrail - Machine Identity Security A machine identity security platform for AWS, GitHub/OIDC, and Kubernetes, built to find risky trust paths, repository exposure, and authorization gaps before they become incidents.
-
Boundary - AWS JIT Access Broker A just-in-time access vending engine that reduces provisioning time from days to seconds while generating artifacts needed for SOC 2 audit evidence.
-
AWS Cloud Incident Response Lab Simulates a full-scale AWS attack and investigation, showing how responders trace identity abuse, contain the blast radius, and turn evidence into repeatable recovery actions.
-
IAM Logic Fuzzer A security testing tool that surfaces hidden privilege escalation paths in IAM policies and helps validate controls against CIS AWS benchmarks.
I contribute security fixes to enterprise infrastructure, identity, & cloud governance projects. My full open-source contribution log.
-
HashiCorp Terraform: Fixed web-identity credential precedence in the AWS provider, preventing valid configured tokens from being rejected when environment credentials are also present.
-
Keycloak: Hardened enterprise identity flows across authorization, federation, OIDC, token exchange, session cleanup, and audit pagination, reducing privilege-escalation risk and improving policy and audit reliability.
-
Better Auth: Closed authentication edge cases across OTP, multi-session cookies, cookie encoding, and OpenAPI session contracts, improving resistance to bypass and credential-handling errors.
-
Home Assistant: Hardened integrations and secret handling by removing legacy Supervisor tokens, redacting sensitive error data, and making OAuth refresh failures explicit across core integrations.
-
Authentik: Hardened self-hosted identity workflows by clearing stale authenticator state, clarifying RBAC permissions, decoding OAuth2 credentials correctly, and handling LDAP data variants.
-
Cloud Custodian: Improved cloud-policy enforcement and SecurityHub reporting by preserving
AccessDeniedsemantics, normalizing IAM condition keys, and sanitizing Lambda network configuration. -
ZITADEL: Corrected unauthenticated v1 gateway responses to return
401, preserving reliable client and security semantics in identity APIs. -
LeapStack: Security-reviewed an AWS launchpad for AI agents, focusing on the IAM, infrastructure, observability, and cost controls needed to move prototypes toward production.
|
AWS Certified Security - Specialty |
HashiCorp Terraform Associate |
|
AWS Solutions Architect - Associate |
CompTIA Security+ |
I’m open to cloud security, identity security, and security engineering roles.
Blog: https://medium.com/@oluwatobi-mustapha
website: https://oluwatobimustapha.vercel.app





