Subomi L.

DevSecOps Engineer

Lagos, Nigeria

Experience

Aug 2024 - Present
1 year 4 months
London, United Kingdom

DevSecOps Engineer

VertoFX

  • Architect and operationalize security automation across CI/CD pipelines using SAST, DAST, and IaC scanning tools to detect vulnerabilities pre-deployment while maintaining development velocity and delivery timelines.
  • Conduct vulnerability assessments and penetration testing using specialized tooling (Burp Suite, custom automation) across cloud and on-premise environments, delivering remediation guidance for critical/high-severity findings.
  • Design security policies, lead compliance audits (ISO, GDPR, SOC2), and establish incident response protocols, enabling rapid threat mitigation and zero-downtime remediation strategies.
Dec 2022 - Jul 2024
1 year 8 months
United States

Cybersecurity Engineer

SecureFLO

  • Embedded threat modeling and secure coding practices into SDLC to reduce vulnerability introduction across development lifecycle.
  • Achieved regulatory compliance (ISO 27001, NIST 800-53, PCI-DSS) through control implementation, documentation, and cross-functional alignment.
  • Conducted enterprise penetration testing on web applications, APIs, and infrastructure; delivered critical vulnerability findings with remediation guidance.
Oct 2021 - Dec 2022
1 year 3 months
Kigali, Rwanda

Cybersecurity Engineer

Africa Cybersecurity Consortium

  • Maintained an information security risk register and assisted with 12 internal and external audits relating to information security.
  • Identified and remediated 20+ vulnerabilities through infrastructure hardening, threat assessments, and threat hunting.
  • Developed security training, policies, and incident response procedures to support organizational compliance maturity.

Languages

English
Advanced

Education

University of Lagos

Bachelor of Building Construction Management · Building Construction Management · Lagos, Nigeria

Certifications & licenses

AWS Certified Security

Certified Ethical Hacker (CEH)

Certified In Risk And Information Systems Control (CRISC)

CompTIA Security+

Offensive Security Certified Professional (OSCP)

Tech Risk And Compliance Professional (OneTrust)

OneTrust

Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions