Skip to content
View micheaol's full-sized avatar
  • AppSec Security Engineer
  • Lagos/Abuja, Nigeria
  • X @micheaol

Block or report micheaol

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
micheaol/README.md

Michael Oladele

Application Security Engineer | DevSecOps Engineer | Secure Software Engineering

LinkedInGitHubEmail


👋 About Me

I'm Michael Oladele, an Application Security & DevSecOps Engineer from Nigeria with a background in software engineering and offensive security.

I work at the intersection of software engineering, application security, and security automation — helping engineering teams identify vulnerabilities, build secure applications, and integrate security throughout the software delivery lifecycle.

My engineering background gives me the ability to understand how applications are actually built, while my security experience allows me to approach those systems from an adversarial perspective.

What I Do

  • 🔐 Application Security — Secure Code Review, Web & API Security, Vulnerability Assessment
  • ⚙️ DevSecOps — Security automation across CI/CD and the SDLC
  • 🧪 Security Testing — SAST, DAST, SCA, API Testing and Penetration Testing
  • 🛡️ Secure SDLC — Security requirements, security controls, testing and remediation
  • ☁️ Cloud Security — Security controls for cloud-native applications and infrastructure
  • 🤖 Security Automation — Building tools and pipelines that continuously identify security weaknesses
  • 🏗️ Secure Software Engineering — Designing and improving applications with security built in

🎯 Current Focus

I'm currently deepening my capabilities across the senior-level AppSec and DevSecOps engineering stack:

Secure Software Engineering
        ↓
Application Security
        ↓
Security Testing & Code Review
        ↓
CI/CD Security
        ↓
DevSecOps Automation
        ↓
Cloud & Container Security
        ↓
Security Architecture
        ↓
Senior AppSec / DevSecOps Engineering

My goal is not simply to find vulnerabilities.

I want to understand the system, attack it, fix it, automate the control, and document the result.


🛡️ Application Security

Security Engineering

  • Secure Code Review
  • Web Application Security
  • API Security
  • Authentication & Authorization Security
  • Session Management
  • Input Validation
  • Injection Prevention
  • Cryptography & Secrets Management
  • Security Headers
  • Dependency & Supply Chain Security
  • Vulnerability Management
  • Security Testing
  • OWASP Top 10
  • OWASP API Security
  • Threat Modeling

Security Testing

  • Burp Suite
  • SAST
  • DAST
  • SCA
  • API Security Testing
  • Vulnerability Assessment
  • Penetration Testing
  • Exploit Validation
  • Security Regression Testing

⚙️ DevSecOps

I focus on integrating security into the software delivery pipeline, rather than treating security as a final-stage assessment.

PLAN → CODE → BUILD → TEST → SCAN → DEPLOY → MONITOR → RESPOND
          │       │       │       │       │
          └─────── Security Controls ─────┘

Areas of focus:

  • Secure CI/CD Pipelines
  • Security Gates
  • SAST / DAST / SCA Integration
  • Container Security
  • Secrets Detection
  • Dependency Scanning
  • Infrastructure Security
  • Supply Chain Security
  • Security Automation
  • Continuous Security Testing
  • Security Metrics & Reporting

🧰 Security & Engineering Stack

Application Security

DevSecOps & Infrastructure

Programming & Development


🚀 Security Engineering Projects

I use projects and open-source work to demonstrate practical security engineering, not just theoretical knowledge.

🔐 OpenControl

An open-source security control and compliance automation project designed to help engineering teams implement and continuously validate security controls.

Focus: Security Automation • DevSecOps • Compliance Automation • Python

👉 Explore: OpenControl


🛡️ Application Security Engineering

Hands-on security engineering covering:

  • Secure code review
  • Authentication security assessments
  • API security testing
  • Vulnerability discovery and validation
  • Security remediation
  • Security regression testing
  • Security documentation
  • Automated security controls

📚 Security Engineering Methodology

My approach to security engineering is:

01. UNDERSTAND
    Understand the architecture, code and trust boundaries.

02. TEST
    Attack the application and identify weaknesses.

03. LEARN
    Understand why the vulnerability exists.

04. FIX
    Implement and validate the remediation.

05. RESET
    Re-test from an attacker's perspective.

06. AUTOMATE
    Turn the security control into a repeatable process.

07. DOCUMENT
    Record the vulnerability, impact, remediation and evidence.

08. DONE
    Produce a measurable security outcome.

The objective is not to generate more vulnerability reports.

The objective is to make the software harder to break.


🌍 Open Source & Security Community

I'm interested in building and contributing to projects that improve:

  • Application Security
  • DevSecOps
  • Secure Software Engineering
  • Security Automation
  • African Cybersecurity Ecosystems
  • Developer Security Education
  • Open-Source Security Tooling

I also write about Application Security, DevSecOps, secure software engineering and practical cybersecurity.


📈 GitHub Activity


🤝 Let's Connect

I'm open to conversations around:

  • Application Security Engineering
  • DevSecOps
  • Secure Software Engineering
  • Security Automation
  • Open Source Security
  • Cybersecurity Engineering Opportunities
  • Security Architecture

📧 Email: micheaol80@gmail.com

💼 LinkedIn: linkedin.com/in/micheaol

🐙 GitHub: github.com/micheaol


Build it. Break it. Secure it. Automate it.

Pinned Loading

  1. secure-core-banking secure-core-banking Public

    Python

  2. Leaderboard-project Leaderboard-project Public

    Leaderboard app was built to showcase my capability of working with Javascript, webpack, API. Leaderboard I practice fetching data from API and send data to the API

    JavaScript 4

  3. covid-19-vaccine-data-tracker covid-19-vaccine-data-tracker Public

    A mobile web application that displays comprehensive data for the novel coronavirus vaccine in Africa. Real live data is obtained from the MMediaGroup API and displayed to the user. Built with Reac…

    JavaScript 2

  4. Awesome-books Awesome-books Public

    Awesome book app was built to showcase the capability of Javascript, CSS, and HTML. The project is to build to model library app for book lovers to manage book they have/haven't read. Built with Ja…

    JavaScript 1

  5. to-do-list-app to-do-list-app Public

    To-do list app is built to practice JavaScript's Objects, Factory Functions, and Module Patterns concepts. Built with JavaScript, CSS, and Webpack.

    JavaScript 1

  6. budget-app budget-app Public

    Budge app allows you to track your speding. It allows you to categorize them into different categories.

    Ruby 1