Lawal.
Platform Security Engineer / DevSecOps
Infrastructure as Code|Kubernetes|Cloud Security|Applied AI
Australia · Remote
I build secure platforms and harden cloud-native infrastructure at scale. My work sits across infrastructure as code, Kubernetes security, and applied AI workload protection. I bring depth from AWS, research from two funded master's degrees, and hands-on work from production environments.
5+
Certifications
3+
Peer-reviewed publications
2
Funded master's degrees
How a change reaches production
Plan it, sign it, scan it, then prove the cluster agrees. Nothing ships unverified.
lawal@hypdev:~$pipeline
planReviewed before anything is applied. Nothing is changed by hand in a console.
signAn image without verifiable provenance does not reach the cluster.
scanGated on CRITICAL. Zero is the only number that passes.
enforceThe cluster proves the policy holds. I do not assume that it does.
Tab completes, Up and Down recall history.
planReviewed before anything is applied. Nothing is changed by hand in a console.
signAn image without verifiable provenance does not reach the cluster.
scanGated on CRITICAL. Zero is the only number that passes.
enforceThe cluster proves the policy holds. I do not assume that it does.
Lawal Alabe
Platform Security Engineer / DevSecOps
Australia · Remote
I build secure platforms and harden cloud-native infrastructure at scale.
Cloud and infrastructure
awsVPC, EC2, S3, RDS, Lambda, ECS, EKS, CloudWatch, GuardDuty, CloudTrail, WAF
azureAzure VNet, Azure Monitor, Entra application proxy
iac and devopsTerraform, CloudFormation, Ansible, CI/CD (GitHub Actions, AWS CodePipeline)
architectureHybrid cloud, cloud migration, multi-AZ architecture, disaster recovery planning
automationPython, C++, PowerShell, Bash
Security, networking and compliance
frameworksEssential 8, ISO 27001, NIST 800-171 and 177, PCI DSS, GDPR
perimeterPalo Alto Networks, Fortinet, Checkpoint, WAF, security groups, network ACLs
identityIAM and RBAC, MFA, Active Directory, Group Policy, access control systems
networkingTCP/IP, DNS, DHCP, VLAN, SD-WAN, MPLS, Cisco, Aruba, Meraki
threat protectionDefender for Cloud Apps, Defender for Endpoint, Windows Defender Exploit Guard
monitoringPRTG, WhatsUp Gold, Cacti
Systems and virtualisation
operating systemsLinux (Ubuntu and RHEL), Windows Server 2016 to 2022
virtualisationVMware vSphere and ESXi, Hyper-V, virtual desktop infrastructure
endpointSCCM, MDM
ticketingServiceNow, Jira, Spiceworks
5 credentials, each verifiable on Credly:
How I think about security
Four layers, in the order I reason about them on every platform I build.
Perimeter
WAF, network firewall, zero trust access. Threats are rejected before they reach compute.
blast radius firstIdentity
Least-privilege IAM, IRSA, RBAC. Overly broad roles are the most common breach vector.
least privilegeData protection
KMS, Secrets Manager, Vault. Key management is where real security judgment lives.
encryption at restDetection
GuardDuty, Falco, CloudTrail, Security Hub. Prevention always fails. Detection speed is the metric.
MITRE ATT&CK mappedTech stack
Tools and platforms I run in production.
CLOUD & INFRA
CI/CD & AUTOMATION
LANGUAGES & DEV
Live from the GitHub API
- Public repositories
- Stars earned
- Last push