0 viewsjobseeker
Seun A. — Mid-Level Application Security Engineer from Nigeria

Seun A.

Mid-Level Application Security Engineer

Nigeria 3-6 years
Open to offersNew to Platform
Languages
EnglishSpanish
Video Introduction
No video introduction yet
The candidate has not added a video.
Contact information and social networks are private. Connect to unlock.
Hidden

About

Ajewole S., an experienced Application Security Engineer based in Lagos, Nigeria, has a proven track record in the financial services sector with a focus on web and mobile application penetration testing, secure code analysis, and vulnerability lifecycle management. He leverages OWASP methodologies and Checkmarx SAST tooling to ensure comprehensive security assessments. Ajewole has played a pivotal role at Unity Bank Plc, applying his skills in conducting penetration tests, managing vulnerabilities, and ensuring compliance with standards such as ISO 27001:2022 and PCI DSS. His hands-on experience extends to deploying threat intelligence platforms like MISP and OpenCTI, while also automating intelligence tasks using Python. Previously, he supported various projects as a remote Penetration Tester for CelsusBit, and as a Cybersecurity Administrator for Virtually Testing Foundation, he provided actionable security compliance insights. Holding a variety of certifications, including ISC2 Certified in Cybersecurity, Ajewole is also pursuing the Certified Ethical Hacker credential.

Experience

  • Penetration Tester (Remote)

    CelsusBit · 2024 — Present
    Performed web application penetration testing for third-party clients, applying OWASP Top 10 and API Top 10 methodologies while delivering detailed technical and executive-level reports. Conducted security assessments for mobile applications (Android) through static analysis with JADX and Checkmarx, and dynamic analysis using Burp Suite and Genymotion to identify authentication flaws, insecure data storage, and API vulnerabilities. Compiled comprehensive penetration test reports addressing risk ratings, proof-of-concept exploits, and prioritized remediation roadmaps for non-technical stakeholders.
  • Threat Intelligence & Vulnerability Management Analyst

    Unity Bank Plc · 2023 — Present
    Conducted web application and network penetration tests utilizing Burp Suite, Nmap, and Kali Linux tooling while applying OWASP Top 10 and OWASP API Top 10 methodologies to identify and address critical vulnerabilities in banking systems. Performed SAST reviews with Checkmarx CX-SAST to spot insecure code patterns in in-house developed applications, providing remediation guidance to the development teams. Executed phishing simulations and verified vulnerability exploitability with Metasploit Pro, generating evidence-backed remediation reports. Deployed OpenBas for attack simulation and threat injection to assess security controls against realistic attack scenarios. Managed the entire vulnerability lifecycle with Rapid7 InsightVM, overseeing discovery, severity prioritization, and remediation tracking across various endpoints. Executed quarterly PCI DSS ASV scans using Smart Comply to maintain compliance and audit readiness. Contributed to the organization’s recertification of ISO 27001:2022 by supporting audit documentation and evidence collection. Integrated and deployed MISP and OpenCTI threat intelligence platforms, ingesting IoCs from various sources, such as VirusTotal and AlienVault OTX. Generated actionable threat intelligence reports and developed profiles for threat actors to proactively combat emerging threats in the financial sector. Created Python scripts to automate NIST vulnerability feed extraction and ARP scanning for enhanced asset visibility.
  • Cybersecurity Administrator (Remote)

    Virtually Testing Foundation · 2023 — 2023
    Audited organizational processes for security compliance, identifying gaps and developing data protection policies. Conducted OSINT investigations to pinpoint potential insider threats and external reconnaissance activities. Tested SQL Injection vulnerabilities in controlled environments to provide actionable recommendations for server hardening.
  • IT Support Specialist

    Listed Hosting · 2022 — 2023
    Reviewed security configurations and assessed security features on internally developed websites and mobile applications during quality assurance cycles. Provided technical support to web hosting clients and conducted quality assurance for in-house digital products.
  • Junior Frontend Developer

    Google Developers — Ekiti State Chapter · 2017 — 2020
    Designed and maintained landing pages, login pages, and blog sites using HTML, CSS, Bootstrap, and WordPress.

Skills & Expertise

Education

  • Master of Information Technology (In View)
    Miva Open University
  • B.Sc. Geology
    Ekiti State University