Application Security Engineer | DevSecOps Engineer | Secure Software Engineering
I'm Michael Oladele, an Application Security & DevSecOps Engineer from Nigeria with a background in software engineering and offensive security.
I work at the intersection of software engineering, application security, and security automation — helping engineering teams identify vulnerabilities, build secure applications, and integrate security throughout the software delivery lifecycle.
My engineering background gives me the ability to understand how applications are actually built, while my security experience allows me to approach those systems from an adversarial perspective.
- 🔐 Application Security — Secure Code Review, Web & API Security, Vulnerability Assessment
- ⚙️ DevSecOps — Security automation across CI/CD and the SDLC
- 🧪 Security Testing — SAST, DAST, SCA, API Testing and Penetration Testing
- 🛡️ Secure SDLC — Security requirements, security controls, testing and remediation
- ☁️ Cloud Security — Security controls for cloud-native applications and infrastructure
- 🤖 Security Automation — Building tools and pipelines that continuously identify security weaknesses
- 🏗️ Secure Software Engineering — Designing and improving applications with security built in
I'm currently deepening my capabilities across the senior-level AppSec and DevSecOps engineering stack:
Secure Software Engineering
↓
Application Security
↓
Security Testing & Code Review
↓
CI/CD Security
↓
DevSecOps Automation
↓
Cloud & Container Security
↓
Security Architecture
↓
Senior AppSec / DevSecOps Engineering
My goal is not simply to find vulnerabilities.
I want to understand the system, attack it, fix it, automate the control, and document the result.
Security Engineering
- Secure Code Review
- Web Application Security
- API Security
- Authentication & Authorization Security
- Session Management
- Input Validation
- Injection Prevention
- Cryptography & Secrets Management
- Security Headers
- Dependency & Supply Chain Security
- Vulnerability Management
- Security Testing
- OWASP Top 10
- OWASP API Security
- Threat Modeling
Security Testing
- Burp Suite
- SAST
- DAST
- SCA
- API Security Testing
- Vulnerability Assessment
- Penetration Testing
- Exploit Validation
- Security Regression Testing
I focus on integrating security into the software delivery pipeline, rather than treating security as a final-stage assessment.
PLAN → CODE → BUILD → TEST → SCAN → DEPLOY → MONITOR → RESPOND
│ │ │ │ │
└─────── Security Controls ─────┘
Areas of focus:
- Secure CI/CD Pipelines
- Security Gates
- SAST / DAST / SCA Integration
- Container Security
- Secrets Detection
- Dependency Scanning
- Infrastructure Security
- Supply Chain Security
- Security Automation
- Continuous Security Testing
- Security Metrics & Reporting
I use projects and open-source work to demonstrate practical security engineering, not just theoretical knowledge.
An open-source security control and compliance automation project designed to help engineering teams implement and continuously validate security controls.
Focus: Security Automation • DevSecOps • Compliance Automation • Python
👉 Explore: OpenControl
Hands-on security engineering covering:
- Secure code review
- Authentication security assessments
- API security testing
- Vulnerability discovery and validation
- Security remediation
- Security regression testing
- Security documentation
- Automated security controls
My approach to security engineering is:
01. UNDERSTAND
Understand the architecture, code and trust boundaries.
02. TEST
Attack the application and identify weaknesses.
03. LEARN
Understand why the vulnerability exists.
04. FIX
Implement and validate the remediation.
05. RESET
Re-test from an attacker's perspective.
06. AUTOMATE
Turn the security control into a repeatable process.
07. DOCUMENT
Record the vulnerability, impact, remediation and evidence.
08. DONE
Produce a measurable security outcome.
The objective is not to generate more vulnerability reports.
The objective is to make the software harder to break.
I'm interested in building and contributing to projects that improve:
- Application Security
- DevSecOps
- Secure Software Engineering
- Security Automation
- African Cybersecurity Ecosystems
- Developer Security Education
- Open-Source Security Tooling
I also write about Application Security, DevSecOps, secure software engineering and practical cybersecurity.
I'm open to conversations around:
- Application Security Engineering
- DevSecOps
- Secure Software Engineering
- Security Automation
- Open Source Security
- Cybersecurity Engineering Opportunities
- Security Architecture
📧 Email: micheaol80@gmail.com
💼 LinkedIn: linkedin.com/in/micheaol
🐙 GitHub: github.com/micheaol
Build it. Break it. Secure it. Automate it.