Skip to content
GABBYTECH.

Gabriel Odusanya · Application Security EngineerNigeria · Working Worldwide

I secure applications.
I teach people how to secure them.

Application Security Engineer · Educator · YouTuber · Mentor.
I work across application security, web & API security, penetration testing, threat modeling, and DevSecOps — helping organizations build more secure software and helping the next generation of security professionals become better practitioners.

ChatGPT-inspired AI security image
Gabriel OdusanyaApplication Security Engineer
  • APPLICATION SECURITY
  • API SECURITY
  • MOBILE SECURITY
  • PENETRATION TESTING
  • THREAT MODELING
  • SECURITY ENGINEERING

Application security
with a purpose.

06 areas of focus
01

Application Security

Assess applications throughout their lifecycle, from architecture and threat modeling to testing and remediation.

02

API Security

Identify weaknesses across authentication, authorization, business logic, data exposure and API architecture.

03

Penetration Testing

Perform evidence-driven security testing designed to demonstrate realistic attack paths and business impact.

04

Mobile Security

Assess mobile applications and their supporting APIs for authentication, data exposure, insecure storage and implementation weaknesses.

05

Threat Modeling

Identify attack surfaces, trust boundaries and abuse cases before vulnerabilities become expensive production problems.

06

Security Engineering

Help teams integrate practical security controls into development workflows and the software delivery lifecycle.

Security work that solves real problems.

Case study / 01

APPLICATION SECURITY REVIEW

Identifying weaknesses across authentication, authorization and business logic.

Focus
Authentication · Authorization · Business logic
Outcome
— add outcome, only once verified —
Case study / 02

API SECURITY ASSESSMENT

Testing APIs beyond automated scanners to uncover authorization and business-logic weaknesses.

Focus
Authorization · Data exposure · API architecture
Outcome
— add outcome, only once verified —
Case study / 03

SECURITY ENGINEERING

Bringing security closer to the software development lifecycle.

Focus
Secure SDLC · Developer workflows · Practical controls
Outcome
— add outcome, only once verified —

Built through real security work.

— add dates —

Application Security Engineering

Reviewing applications across the development lifecycle, from design and threat modeling through testing and remediation.

— add dates —

Penetration Testing

Evidence-driven testing of web, API and mobile targets, focused on realistic attack paths over checklist coverage.

— add dates —

Security Engineering

Working with engineering teams to build practical security controls into everyday development workflows.

— add dates —

Cybersecurity Education & Mentorship

Teaching application security concepts and mentoring practitioners moving into the field.

— add dates —

Security Product Building

Building OffShield Security, an applied security brand and product line.

Thinking about security.

THREAT MODELING

Why every developer should threat model before writing a single line of code — a practical level 2

A practical guide to making threat modeling a developer-first habit before design and code are locked in.

Read article
DOCKER SECURITY

Getting started with Docker for application security: deploying OWASP CRAPI

How Docker can be used to deploy appsec tooling and secure development environments with OWASP CRAPI.

Read article
CLOUD SECURITY

Microsoft Entra ID: moving Azure AD from Access Manager to Trust Interpreter

An exploration of Entra ID, Azure AD evolution, and how identity should be treated for security and trust.

Read article
ACCESS CONTROL

Breaking into the VulnBank admin dashboard: a lesson in broken access control

A real-world write-up showing how broken access control can turn a vulnerable admin panel into a breach path.

Read article
API SECURITY

Why broken access control is more dangerous in APIs than in web applications

Why API authorization gaps are often more serious than UI-level access control issues.

Read article
WEB SECURITY

Understanding the modern web attack surface — AppSec

A breakdown of the modern application attack surface and what defenders need to protect first.

Read article
SECURITY MINDSET

The hacker’s mindset: no butter, just strategy

A security mindset essay that focuses on strategy and practical thinking rather than tricks or jargon.

Read article
AI SECURITY

Securing an application built with AI: lessons from a real-world test

Practical lessons from testing AI-powered applications and the security controls they need.

Read article
WEB SECURITY

SQL injection on DVWA — write-up

A write-up showing SQL injection techniques on DVWA and what secure coding should prevent.

Read article
AUTHORIZATION

Breaking access: understanding IDOR vulnerability and how to find it using Burp Suite

An IDOR tutorial that shows how to discover broken object access control with Burp Suite.

Read article
API BASICS

What is an API? A simple guide for beginners

A beginner-friendly explanation of APIs, how they work, and why they matter for developers and security.

Read article
What guides the work
01

Evidence before assumption.

Security findings should be backed by evidence, not fear.

02

Impact before theatre.

The goal is not to make a vulnerability sound frightening. The goal is to understand what it means and what deserves attention first.

03

Clarity before volume.

A shorter, prioritized security assessment is more useful than a massive report nobody can act on.

Have a security problem worth solving?

Whether you’re securing a new product, reviewing an existing application, or building security into your engineering process, start with a few details and I’ll open WhatsApp with your request.

For organizations

Need an application, API or mobile security assessment?

Share the details of your project and what you need most: assessments, threat modeling, secure architecture advice, or a practical security review.

What I help with

  • Application Security Assessments
  • API & Authorization Reviews
  • Threat Modeling & Secure Design
  • DevSecOps and Engineering Collaboration