Subomi LawsonContact
[Cybersecurity engineer · OSCP]

Built from scratch, not inherited.

I’m Subomi Lawson, a security engineer. Two companies hired me as their first and only security person. I built the function, ran the pentests, and led the audits that passed.

5yrsIn security
3Audits led and passed
Profile[ 1.0 ]

Twice now, I have been the whole security team.

Five years in security across fintech, SaaS, and e-commerce. Twice I joined as the first and only security hire, which meant there was no program to inherit. I designed the architecture, ran the pentests, wrote the policies, and led the audits.

ISO 27001. PCI DSS. SOC 2. Three certification audits, all passed.

My range covers penetration testing, DevSecOps, and cloud security on AWS. Lately I am building AI-assisted security tooling with LLMs for threat detection and response automation. OSCP certified. ISO 27001 Lead Implementer.

The part I care about most: security engineers actually work with, not around. Built into how teams ship, not bolted on at the end.

CybersecurityPythonLinuxAWSLagos, Nigeria

[ Capabilities ][ 2.0 ]

Offensive security

Penetration testing

I break the stack before someone else does. Infrastructure and application engagements, driven through remediation to close, not handed over as a PDF.

[ 2.1 ]
Detection

Detection & response

GuardDuty detections tuned to the environment, triage that separates signal from noise, and the alert that fires at 3am answered, not snoozed.

[ 2.2 ]
DevSecOps

Security in the pipeline

Automated scanning in every CI/CD pipeline, so vulnerabilities surface at commit instead of at audit. Security as standard practice, not a gate.

[ 2.3 ]

5 years in security

Compliance[ 2.4 ]

ISO 27001, PCI DSS, SOC 2

Cloud

AWS security

Architecture reviews and hardening across the stack. I own cloud risk end to end, starting with the misconfiguration nobody caught.

[ 2.5 ]

Experience[ 3.0 ]

Feb 2025 - PresentTotowa, NJ

Security Engineer · Sprint Technology Solutions Inc.

  • Own the entire security function. I built it from zero: SIEM, threat detection, vulnerability management, access controls, and policy
  • Led the company through ISO 27001, PCI DSS, and SOC 2 certification audits. All three passed
  • Run continuous penetration testing across infrastructure and applications, and drive every finding through to a fix
  • Own AWS security end to end: architecture reviews, hardening, monitoring, and ongoing risk management
  • Building AI-assisted tooling that sharpens threat detection and automates response
SIEMAWSISO 27001PCI DSSSOC 2
Sep 2025 - Feb 2026Lagos State, Nigeria

Security Engineer · Assetrix

  • Sole security hire, one month after launch, on a fintech platform holding tokenized real estate investments and investor funds
  • Built the whole function from scratch: security architecture, cloud security, access controls, policy, incident response, and operational tooling
  • The security baseline I set is the one the platform still runs on
FintechIncident responseAccess control
Aug 2024 - Sep 2025London Area, United Kingdom

DevSecOps Engineer · Verto

  • One of three founding security engineers at a cross-border payments fintech. Security was embedded into engineering from day one
  • Automated code scanning across every CI/CD pipeline, hardened AWS, and deployed GuardDuty for continuous threat detection
  • Ran penetration testing across infrastructure and applications as part of the wider security programme
  • Contributed to the ISO 27001 programme and made DevSecOps standard practice across engineering teams
CI/CDGuardDutyPentesting
Jan 2023 - Jul 2024Massachusetts, United States

Cyber Security Engineer · SecureFlo.net

  • Ran vulnerability assessments across client infrastructure and applications, and tracked every finding through to remediation
  • Hardened systems and reviewed configurations against security baselines
  • Monitored security events, triaged alerts, and worked incidents through to resolution
  • Supported compliance and audit work with control reviews, evidence, and documentation
Vulnerability managementHardeningMonitoring
Oct 2021 - Dec 2022Kigali City, Rwanda

Cyber Security Engineer · Africa Cybersecurity Consortium (ACC)

  • Hardened client environments with firewalls, patching, and layered controls
  • Built the disaster recovery and breach contingency plans clients fell back on
  • Tested and evaluated security products before they reached client environments
  • Maintained the information security risk register and supported internal and external audits
  • Ran cybersecurity awareness training for client teams
Risk registerDisaster recoveryAwareness training
[ Certifications ][ 4.0 ]

My Certifications

Certified where it counts, audited where it matters. Every framework here was earned or taken through a full audit that passed.

ISO 27001 Lead ImplementerCompTIA Network+Certified Cybersecurity EngineerCertified Tech Risk & Compliance Management
University of LagosBASc, Building / Construction Site Management
OSCP
OffSec certified
ISO 27001
Lead Implementer
PCI DSS
Audit led · passed
SOC 2
Audit led · passed
Contact[ 5.0 ]

Need a security function built, or the one you have stress tested?

Open to security engineering work