Skip to content
View Oluwatobi-Mustapha's full-sized avatar

Block or report Oluwatobi-Mustapha

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Oluwatobi-Mustapha/README.md

Hi, I'm Oluwatobi.

Security Engineer | Non-Human Identity | OSS Contributor

I build and secure cloud and distributed systems, with a focus on identity security, least-privilege architecture, threat detection, and incident response.

Member of the AWS Community Builders and The Identity Underground.


Projects

  • Identrail - Machine Identity Security A machine identity security platform for AWS, GitHub/OIDC, and Kubernetes, built to find risky trust paths, repository exposure, and authorization gaps before they become incidents.
  • Boundary - AWS JIT Access Broker A just-in-time access vending engine that reduces provisioning time from days to seconds while generating artifacts needed for SOC 2 audit evidence.
  • IAM Logic Fuzzer A security testing tool that surfaces hidden privilege escalation paths in IAM policies and helps validate controls against CIS AWS benchmarks.

Open Source Contributions

I contribute security fixes to enterprise infrastructure and cloud governance projects. My full open-source contribution log

  • Keycloak Improved fine-grained admin permissions by closing policy-evaluation gaps around protected group memberships, and contributed fixes across OIDC and OID4VCI flows.
  • Home Assistant Core Improved Google Sheets authentication reliability by fixing OAuth error handling so invalid credentials trigger secure re-authentication while transient provider failures retry safely.
  • Authentik Fixed an OAuth2 credential-decoding flaw that broke authentication when secrets contained special characters, restoring reliable sign-in for automated workflows.
  • Better Auth Delivered security patches that closed OTP bypass paths and tightened cryptographic validation to reduce session takeover risk.
  • Zitadel Fixed native gRPC status-error propagation across service boundaries.
  • Cloud Custodian Fixed an AWS IAM monitoring blind spot so legitimate AccessDenied events surface correctly during multi-account compliance and security audits.

Certifications

AWS Certified Security - Specialty badge
AWS Certified Security - Specialty
HashiCorp Terraform Associate badge
HashiCorp Terraform Associate
AWS Solutions Architect - Associate badge
AWS Solutions Architect - Associate
CompTIA Security+ badge
CompTIA Security+

Open to Work

I’m open to cloud security, identity security, and security engineering roles.

LinkedIn

Email: oluwatobimustapha539@gmail.com

Pinned Loading

  1. identrail/identrail identrail/identrail Public

    Machine identity security platform for AWS, GitHub/OIDC, and Kubernetes. Find risky trust paths, repository exposure, and authorization gaps before they become incidents.

    Go 3 3

  2. boundary boundary Public

    Serverless Just-In-Time (JIT) access broker for AWS. Features Slack ChatOps, policy-as-code, and automated zero-trust revocation.

    Python 6 1

  3. iam-fuzzer iam-fuzzer Public

    Automated fuzzing tool for identifying AWS IAM logic flaws, and permission boundaries.

    Python 8

  4. OSS-Contributions OSS-Contributions Public

    A curated list of my merged open-source PRs.

    3