Atlanta, GA · U.S. Citizen · Open to roles

Cybersecurity & IT
operations professional

I'm Oreoluwa Fagbamiye — 3+ years securing and operating enterprise government infrastructure across identity & access management, endpoint lifecycle, security operations, and networking.

3+ yrs Enterprise IT & security
200+ Users supported
99.9% Uptime sustained
100% SLA compliance
Sec+ / CHFI / ITIL 4 Certifications

Who I am

I'm a cybersecurity and IT operations professional with 3+ years of hands-on enterprise experience, currently serving as a Network & Security Specialist at Fulton County Government, where I support 200+ users across identity, endpoint, and network operations.

My work spans privileged access management (CyberArk PAM), Active Directory and Entra ID identity lifecycle, endpoint deployment with SCCM/MECM and Intune, Splunk-based security monitoring, and vulnerability management with Nessus/Tenable — all under formal change management and NIST 800-53 controls.

I hold a B.S. in Cybersecurity / Computer Forensics & Counterterrorism from the University of North Georgia (an NSA/DHS Center of Academic Excellence), completed Harvard CS50, and carry CompTIA Security+, EC-Council CHFI, and ITIL 4 certifications. I'm passionate about turning manual operations into automated, well-documented workflows.

Professional experience

Three roles across enterprise government, physical security operations, and security analysis.

Network & Security Specialist Fulton County Government Dec 2023 – Present
  • Administer CyberArk PAM (PVWA/PSM) for privileged credential checkout and secure RDP, enforcing least-privilege Safe permissions with zero compliance findings during access reviews.
  • Manage the full AD and Entra ID identity lifecycle for 200+ accounts — GPO, RBAC, NTFS permissions, and M365 (Exchange Online, SharePoint, Teams, Intune) onboarding/offboarding.
  • Drive endpoint & asset lifecycle for 200+ devices via SCCM/MECM imaging, Intune, and Autopilot with zero compliance deadline misses.
  • Sustain 99.9% uptime and 100% SLA compliance with 95% first-contact resolution across Tier 1–2 support and Cisco IOS changes under ServiceNow change management.
  • Build PowerShell and Bash automation that cut recurring task time by ~30%; correlate Proofpoint and KnowBe4 data to reduce phishing susceptibility.
  • Support post-incident modernization after the 2022 county cyberattack — hybrid cloud migration, MFA via Entra ID Conditional Access, NIST 800-53 hardening.
Account Assistant Manager Allied Universal — Norfolk Southern Facility Jun 2023 – Nov 2023
  • Monitored and triaged NVR/IP camera systems with Victor VMS, maintaining continuous surveillance coverage.
  • Administered access control databases in Lenel and C•CURE for 500+ personnel profiles.
  • Supervised 8–12 staff, coordinating with client leadership and vendors with 100% schedule adherence.
  • Developed Python and Bash scripts that reduced report generation time by ~40%.
Information Security Analyst Intern TKincorporated LLC Aug 2021 – Dec 2022
  • Triaged 100+ monthly Splunk SIEM alerts, using Exabeam behavioral analytics to identify phishing, malware, and unauthorized access.
  • Ran Nessus/Tenable.io vulnerability assessments identifying 200+ vulnerabilities and driving a 35% reduction in exposure risk through prioritized CVE remediation.
  • Produced NIST 800-53-aligned incident documentation and contributed to compliance/audit readiness.

Skills & tooling

Built across enterprise identity, endpoint, security operations, networking, and automation.

Identity & Access Management

Privileged access, identity lifecycle, least-privilege enforcement, and physical access control.

CyberArk PAM (PVWA / PSM) Active Directory (GPO / OU) Entra ID / Azure AD Okta RBAC / NTFS Audit reporting Avigilon ACM / Lenel / C•CURE

Security, Monitoring & Incident Response

SIEM monitoring, EDR/XDR, threat intel, vulnerability management, and IR.

Splunk Exabeam EDR/XDR (Cortex, Taegis) Proofpoint Zscaler Varonis KnowBe4 Nessus / Tenable.io Snort IDS NIST 800-53 MITRE ATT&CK

Network & Infrastructure

Switching, firewalls, NAC, and monitoring at enterprise scale.

Cisco IOS VLAN / VPN Palo Alto Firewall Forescout NAC Barracuda WAF SolarWinds NPM SNMP / TCP-IP / DNS / DHCP pfSense

Endpoint & Asset Lifecycle

Imaging, provisioning, refresh planning, and lifecycle across 200+ devices.

SCCM / MECM Windows Autopilot Intune Workstation imaging Hardware refresh planning IMAC Asset tracking & disposal Smart Hands

Scripting & Development

Automation, REST API integration, and forensic tooling.

Python PowerShell Bash SQL / PL-SQL Java C# MongoDB GDB scripting REST APIs (JSON) HTML / CSS

Cloud & DevOps

Infrastructure as code, CI/CD, and cloud-native AI agent deployment.

AWS Terraform Ansible Docker GitHub Actions CI/CD Google Cloud (Cloud Run, IAM, VPC, BigQuery, Firestore) Vertex AI ADK / MCP / RAG vLLM

Offensive Security & Analysis

Exploitation labs, adversary emulation, and forensic / traffic analysis on owned test equipment.

Metasploit Kali Linux Netcat 802.11 / WPA2 / WPA3 Wi-Fi Pineapple Hashcat / Aircrack-ng Wireshark Ghidra Browser dev tools RCA / log analysis ATT&CK Navigator

Platforms, ITSM & Documentation

Ticketing, service management, and knowledge-base authoring.

ServiceNow BMC Helix Remedy JIRA Zendesk Microsoft 365 (Exchange, SharePoint, Teams) Windows 10 / 11 Linux (Kali, Ubuntu) ITIL 4

Projects & competitions

Hands-on security engineering and research — from offensive labs to cloud and AI automation. Write-ups and source on GitHub.

Completed

Penetration Testing & Exploitation Lab

Compromised vulnerable Windows/Linux targets in an isolated Kali lab using Metasploit — a malicious PDF exploiting Adobe Reader (CVE-2010-1240), Distcc RCE (CVE-2004-2687), and Netcat bind/reverse shells — with documented defensive countermeasures.

Metasploit Kali Linux Netcat
Completed

NSA Codebreaker Challenge 2021–2022

Adversarial network forensics with Wireshark, browser dev tools, and Splunk; decrypted TLS/RSA traffic with Ghidra and Python and automated private-key extraction via GDB scripting with 100% documented accuracy.

Wireshark Ghidra GDB Python
Completed

Cloud Run + ADK AI Agents

Three Google Cloud codelabs rebuilt as deployable projects: tool-calling agents on Cloud Run with sandboxed code execution, a Streamlit RAG app backed by Firestore vector search, and a self-hosted Gemma model on GPU wired to BigQuery over MCP — each reproducible from scripts with least-privilege IAM.

Google Cloud Cloud Run RAG / vector search IAM
Completed

Secure MVP Launchpad (DevSecOps)

Built and deployed a Python/Flask app on AWS with Docker, Terraform for infrastructure as code, and Ansible for configuration management; GitHub Actions CI/CD pipelines with security hardening and scanning integrated throughout the deployment lifecycle.

AWS Terraform / Ansible Docker GitHub Actions CI/CD
Completed

AI Job-Search Framework

A local automation framework built on Claude Code that evaluates job postings, tailors CVs, drafts cover letters, and preps interviews — API integration, prompt design, and end-to-end workflow automation.

Python LLM agents Automation
Research

Hijacking a Wi-Fi Drone / MITRE ATT&CK

Hijacked a consumer Wi-Fi drone (Ryze Tello) end to end — a one-click deauthentication attack to seize control, then an offline WPA2 handshake crack with Hashcat — using Kali and a Wi-Fi Pineapple. Every step mapped tactic-by-tactic to MITRE ATT&CK, with manufacturer and operator mitigations.

802.11 / deauth WPA2 / Hashcat Wi-Fi Pineapple MITRE ATT&CK
Completed

Snort IDS Signature Development

Conducted APT malware analysis in Ghidra and Wireshark and developed Snort IDS signatures that improved detection by ~30%.

Snort IDS Ghidra Wireshark
In progress

Home SOC Lab — Wazuh

A home SOC for detection engineering: instrumented Windows and Linux endpoints, a 13-stage adversary emulation plan run with Atomic Red Team, and detection-as-code — custom Wazuh rules and Sigma, mapped to an ATT&CK coverage layer, with incident reports and MTTD metrics. Built from code with Vagrant/Ansible.

Wazuh Sysmon / auditd Atomic Red Team Sigma Vagrant / Ansible
Completed

Cisco / pfSense Home Lab

Maintained a segmented Cisco IOS / pfSense home lab with Python and Bash automated runbooks — a sandbox for testing security controls and detection content.

Cisco IOS pfSense Python/Bash

Certifications & training

Industry credentials across security, IT service management, cloud, and data.

Certified
CompTIA Security+
CompTIA
Certified
EC-Council CHFI
Computer Hacking Forensic Investigator
Certified
ITIL 4 Foundation
IT Service Management
Certified
AWS Cloud Practitioner Essentials
Amazon Web Services
Certified
Google IT Support Professional
Google
Certified
Google Data Analytics Professional
Google
Certified
Network Fundamentals
Training
Certified
Linux Fundamentals
Training
In progress
Master ChatGPT for Ethical Hacking
EC-Council

At a glance

Headline metrics from enterprise operations. Full detail in the resume and RESUME_GUIDE.md.

3+ yrs
Enterprise IT & security
200+
Users & devices supported
8
Certifications & training
99.9%
Uptime sustained

Let's connect

Hiring managers, recruiters, or fellow security professionals — I'd welcome a conversation. The fastest way to reach me is GitHub or email below.