Tolulope Babajide
I run client-facing security engagements end to end: threat analysis with MITRE ATT&CK, IAM and API review across cloud environments, and GRC gap assessments against ISO 27001 and PCI DSS, translated into board-level risk summaries.
Based in London. I pair hands-on testing (Nessus, Zabbix, OWASP, APT analysis) with the consultative, stakeholder-facing side of security work.
Products I have taken from a real-world constraint to a working, testable system.
Threat intelligence · Cloud · SecOps · IAM · GRC
Problem: Security teams need technical evidence translated into prioritized controls, defensible governance, and decisions stakeholders can act on.
Solution: Placement and controlled-engagement work spanning malware and threat analysis, Azure network segmentation, JWT/API testing, IAM review, AI governance, and PCI DSS assessment.
Notable: Produced technical and executive-facing deliverables while keeping confidential client evidence separate from public portfolio material.
Three connected capabilities, demonstrated through the products and engagements above.
The disciplines that shaped how I discover, build, communicate, and protect products.
Why I build differently
Entrepreneurship taught me ownership. Sales taught me discovery and value. Operations taught me reliability under pressure. Security taught me trust and risk. Engineering lets me bring those disciplines together in products people can depend on.
I'm currently open to cybersecurity, solutions engineering, and customer enablement roles.
Open to Skilled Worker sponsorship