Stephen Adewole Tanimowo

Senior Application Security & DevSecOps Engineer
Lagos, NG.

About

Highly accomplished Senior Application Security & DevSecOps Engineer with over 6 years of expertise in integrating robust security measures across the SDLC and CI/CD pipelines. Specializes in securing cloud-native applications, vulnerability management, penetration testing, and API security. Leverages strong proficiency in AWS, Azure, Terraform, Docker, and Kubernetes to drive security automation and ensure comprehensive protection for complex systems.

Work

Cyberoutcome Limited
|

Senior DevSecOps & Application Security Engineer

Remote, N/A, N/A

Summary

Leads advanced DevSecOps and Application Security initiatives, embedding robust security practices into the software development lifecycle for enhanced system integrity and compliance.

Highlights

Integrated and optimized SAST/DAST tools, including SonarQube and OWASP ZAP, into CI/CD pipelines (GitHub Actions, Jenkins), enhancing automated vulnerability detection by an estimated 30%.

Directed comprehensive application penetration testing efforts, identifying critical vulnerabilities and coordinating remediation strategies to significantly reduce attack surface.

Engineered and deployed advanced API security solutions, including OAuth2, API key rotation, and WAF protections, safeguarding critical data and preventing unauthorized access.

Managed and enforced cryptographic standards utilizing AWS KMS and device certificates, ensuring robust data encryption and compliance with industry regulations.

Creovantage Business Solutions
|

Technical Security Specialist - DevOps & Cloud

Remote, N/A, N/A

Summary

Specialized in designing and implementing secure, multi-cloud DevOps solutions, focusing on infrastructure automation and robust security posture management.

Highlights

Designed and deployed secure multi-cloud workloads across AWS and Azure environments, implementing hardened IAM policies to minimize access risks and enhance security posture.

Automated infrastructure provisioning and configuration management using Terraform and Ansible, integrating HashiCorp Vault for secure secrets management to improve operational efficiency by 25%.

Conducted regular vulnerability scanning and compliance reporting across cloud infrastructure, identifying and addressing security gaps to maintain regulatory adherence.

Flutterwave
|

iOS Developer - AppSec Focus

Lagos, Lagos, Nigeria

Summary

Developed secure iOS applications with a strong focus on application security, integrating robust authentication and encryption for fintech transactions.

Highlights

Developed and secured APIs with advanced authentication mechanisms, including OAuth2 and JWT, to protect sensitive financial data for iOS applications.

Integrated Jenkins and Fastlane pipelines with automated security checks, streamlining the secure delivery of iOS applications and reducing deployment vulnerabilities by 15%.

Enforced strong encryption-in-transit and at-rest protocols for all fintech transactions, ensuring data integrity and compliance with financial security standards.

Education

University of Maryland, College Park
College Park, Maryland, United States of America

Diploma

Information Technology

Grade: N/A

Federal University of Technology, Owerri
Owerri, Imo, Nigeria

B.Tech

Computer Science

Grade: N/A

Certificates

Imperva Application Security Specialist

Issued By

Issued

Check Point CCSA

Issued By

Issued

AWS Certified Security – Specialty

Issued By

Issued

(ISC)² Certified in Cybersecurity (CC)

Issued By

Issued

CompTIA Security+

Issued By

Issued

Microsoft SC-200

Issued By

Issued

Terraform Essentials

Issued By

Issued

GitHub Actions CI/CD

Issued By

Issued

Skills

Application Security

Vulnerability Scanning, Penetration Testing, SAST/DAST, API Security, Cryptography, HSMs, Secrets Management.

Cloud Security

AWS, Azure, Cloud-Native Security, IAM Policies.

DevSecOps & Automation

Terraform, Ansible, Jenkins, GitLab CI/CD, GitHub Actions, Docker, Kubernetes, Security Automation.

Programming & Scripting

Python, C#, Java, OAuth2, JWT.

Projects

Secure CI/CD Pipeline (GitLab + SonarQube)

Summary

Designed and implemented a robust CI/CD pipeline leveraging GitLab and SonarQube for automated static analysis and container scanning, identifying security flaws early in the development cycle.

API Security Hardening

Summary

Developed and deployed advanced security measures for APIs, focusing on authentication, certificate management, and web application firewall integration.

Terraform + Vault Secrets Management

Summary

Automated infrastructure provisioning and secrets management using Terraform and HashiCorp Vault, ensuring secure handling and rotation of sensitive credentials.

Penetration Testing Lab

Summary

Constructed a simulated environment using Kali Linux to practice and demonstrate penetration testing techniques against common OWASP vulnerabilities.