Security Engineer in the making

Building systems.
Breaking them to understand
how to harden the next one.

Blue team operations by day, HackTheBox by night. I deploy SIEMs, instrument CI/CD pipelines with security gates, and document everything in public so the work speaks for itself.

Ibadan, Nigeria

# Expadox Lab Cohort 3 — live attack detection evidence
cyber-vortex@wazuh-server:~$ tail -f /var/ossec/logs/alerts/alerts.json | grep "SSH"
{"rule":{"id":"5710","description":"SSH authentication failed","level":5},"agent":{"name":"40RT3X"}}
{"rule":{"id":"5503","description":"SSH Brute Force attempt","level":10},"data":{"srcipt":"10.153.239.40"}}
cyber-vortex@wazuh-server:~$ cat zap-report.json | jq '.site[0].alerts[] | {name:.alert, risk:.riskdesc}'
{"name":"Content Security Policy Header Not Set","risk":"Medium (High)"}
{"name":"Cross-Domain Misconfiguration","risk":"Medium (Medium)"}
cyber-vortex@wazuh-server:~$ # CRITICAL: Pipeline blocked. 2 medium or higher severity findings detected.
01 / about

Security engineering across both sides of the fence

I build blue team environments and think like an attacker while doing it. My background in backend engineering means I understand how systems are assembled, which makes it easier to reason about how they fail.

Currently working through Expadox Lab Cohort 3, where I have deployed production-grade SIEM infrastructure, integrated AWS and Azure cloud log ingestion, built a DevSecOps pipeline with automated SOAR response, and led a team across multiple projects.

My Electrical and Electronics Engineering degree at the University of Ibadan gave me a habit of tracing systems to their failure points before considering them understood. That instinct transfers cleanly to security.

[ 01 ]

Blue Team Operations

SIEM deployment, threat detection, cloud log ingestion, incident response playbooks

[ 02 ]

Offensive Security

HackTheBox, network enumeration, exploitation writeups, attack simulation

[ 03 ]

DevSecOps

CI/CD pipeline instrumentation, DAST, SAST, secrets detection, SOAR automation

[ 04 ]

Security Tooling

Python recon tools, port scanner, subdomain enumerator, JWT analyzer

02 / projects

Selected work

Project Type Stack Link
ResponseOne
DevSecOps pipeline and SOAR automation platform. Instruments Juice Shop with SAST, DAST, dependency scanning, and secrets detection on every commit. Findings POST automatically to Shuffle Cloud. Pipeline blocks on medium or higher severity findings.
DevSecOps
GitHub ActionsOWASP ZAPSemgrepTrivyGitleaksShuffleDocker
Private — details on request
MedCore SIEM Environment
Centralized security monitoring for a simulated healthcare supply chain. Wazuh 4.14.7 all-in-one deployment, AWS CloudTrail ingestion, Azure Activity Log integration, three live attack simulations with full incident response playbooks.
Blue Team
WazuhAWS CloudTrailAzureZeroTierKali Linux
Read writeup
IronGuard Endpoint Protection
Endpoint protection and vulnerability management for a healthcare supply chain. Reduced critical CVEs from 7 to 0, achieved 87% patch compliance, built a Python SLA enforcement tracker with automatic severity classification.
Blue Team
WazuhAction1PythonCVSS
View on LinkedIn
SecureTeam
RBAC-based team management app where security is the core design constraint. Two-layer access control, JWT rotation with token version revocation, full audit logging on every privileged action.
Secure Dev
Node.jsExpressMongoDBReactJWTRBAC
github.com/DevwithMujeeb/secureteam
Vulnerable Web Lab
Intentionally broken Express app covering OWASP Top 10. Each vulnerability has an exploit path and a patched version side by side. NoSQL injection, XSS, IDOR, broken auth, sensitive data exposure.
Security Lab
Node.jsExpressMongoDBOWASP Top 10
github.com/DevwithMujeeb/vuln-lab
Security Tools
Python CLI toolkit for recon and analysis. Port scanner with service detection, subdomain enumerator with wordlist support, JWT analyzer that decodes, inspects expiry, and flags weak algorithms.
Tooling
PythonReconJWT
github.com/DevwithMujeeb/sec-tools
03 / current focus

What I am building toward

HackTheBox Academy progress

Linux FundamentalsComplete
Web RequestsComplete
Networking FundamentalsIn progress
CTF WriteupsActive