Oxford, England
Introduction
Work Experience
Education
Certifications
Professional Affiliations
Skills & Tools
Oxford, England
English

Abiola Oyegun

Cyber Security Engineer

Cyber security professional with a career progression from IT infrastructure and system administration into threat management and, most recently, DevSecOps at Akrivia Health — covering endpoint protection, CI/CD pipeline security, and incident response, most notably leading the response to a live, high-severity security incident.

The role also brings application security checks into delivery pipelines, including SAST scanning. Experienced across Windows, Linux, and macOS, identity systems (Active Directory, Entra ID), and AWS cloud security, with direct exposure to balancing security controls against day-to-day business operations.

Background in Cyber Essentials Plus, ISO 27001, and GDPR compliance, with a track record of producing incident documentation and audit evidence for leadership and regulators, underpinned by an MSc in Cybersecurity (Distinction).

Outside the day job, I take on freelance penetration testing, contribute to AI model training and evaluation, and I'm building Xcevia, a security consultancy for UK SMEs.

Work Experience

Akrivia Health Ltd – OxfordJuly 2024 – Present
DevSecOps Engineer · previously System Administrator and Threat Management Engineer
  • Led the response to a live, high-severity security incident, from containment and investigation through to recovery and the documentation for leadership and regulators
  • Manage and mitigate security alerts across the endpoint estate on Windows, macOS, and Linux, escalating and responding per incident severity and response protocols
  • Led a security tooling review and vendor evaluation, consolidating onto a single platform covering every operating system and the cloud, cutting annual security tooling spend by around 60%
  • Onboarded a dedicated patch and vulnerability management platform, complementing endpoint protection with continuous remediation
  • Support cloud security operations, including access control, audit-log monitoring, and correlating cloud activity with endpoint telemetry
  • Run the annual Cyber Essentials Plus certification cycle, from internal assessment and evidence collation through to working with the external assessor during the audit
  • Managed and delivered the annual penetration testing programme for over two years, coordinating scope, vendor engagement, and remediation tracking through to closure
  • Develop and maintain IT security policies, SOPs, and incident documentation aligned to ISO 27001 and GDPR
  • Conduct Business Continuity (BCP) and Disaster Recovery (DR) reviews with senior management and engineering teams
  • Manage the organisation's AI tools and their security, and deliver security awareness training and phishing simulations across the organisation
  • Collaborate cross-functionally with DevOps, compliance, and governance teams to operationalise risk reduction
Birmingham City University – BirminghamMarch 2024 – July 2024
Enterprise Associate – Innovate UK Funded Project
  • Led a feasibility study for a complaint management system (CMS) for PBL Care Limited, mapping processes and building a scalable proof-of-concept to automate triage, SLAs, and reporting for the home care business
  • Aligned the solution with CQC (Care Quality Commission) information governance expectations for healthcare services, embedding privacy by design and data minimisation controls
  • Performed data protection impact considerations and documented risks and retention, ensuring compatibility with GDPR and organisational policies
  • Built a lightweight GUI platform automation in Python/Node.js for data validation and integrity checks, later merged into PHP for seamless API integration
Reuben College – University of OxfordJan 2024 – March 2024
Information Technology Administrator Assistant
  • Provided technical support for staff and academic users, resolving hardware, software, and connectivity issues across Windows and macOS systems
  • Deployed and managed Sophos Endpoint Protection agents across all devices, ensuring compliance with the University's endpoint security policies
  • Monitored and maintained endpoint health and alerts within the Sophos Central Admin Console, enforcing policies for malware protection and threat response
  • Assisted with user onboarding, account setup, and device provisioning through Active Directory and Office 365, maintaining secure identity and access management
  • Collaborated with the IT Manager on network configuration, documentation, and firewall reviews to improve performance and minimise security gaps
SDSD – Marine Fleet Management System – LondonDec 2021 – Aug 2022
Information Technology Engineer
  • Solely managed the company's Maritime Asset Management System (MAMS), supporting vessels and remote clients across the USA, Europe, China, India, Canada, and Australia
  • Delivered 1st, 2nd, and 3rd line IT support for onboard systems, addressing software, network, and configuration problems in time-critical maritime operations
  • Collaborated with development teams to patch vulnerabilities and strengthen system security and endpoint controls for remote assets
  • Built the analytical, troubleshooting, and systems hardening foundation for a transition into cybersecurity, DevSecOps, and threat management

Education

Birmingham City UniversityMSc Cybersecurity – Distinction · 2022 – 2023 · Birmingham, United Kingdom
Ladoke Akintola University of TechnologyB.Tech Computer Science · 2012 – 2017 · Ogbomosho, Oyo State, Nigeria

Certifications

Certified Ethical Hacker (CEH)EC-Council
SentinelOne Incident ResponderSentinelOne · 2026
SentinelOne Security AdministratorSentinelOne · 2025
SentinelOne University trainingSingularity Cloud Security Foundations; Singularity Administration (deploying the agent; administering accounts, sites and groups); ThreatOps Challenge (3 CPE) · 2025
Introduction to Cybersecurity and Cybersecurity EssentialsCisco · 2021 – 2022
Certified DevSecOps Professional (CDP)Practical DevSecOps · in progress

Professional Affiliations

EC-CouncilMember (Certified Ethical Hacker)
ISACAInformation Systems Audit and Control Association
ISC2Candidate

Skills & Tools

Security Alert Triage & Incident ResponseEDR console management, escalation, containment, and recovery support, including leading the response to a live, high-severity security incident.
SentinelOne Singularity EDR/XDR
Microsoft Defender
Alert Logic
SIEM & Endpoint PlatformsSophos Endpoint Protection (Central Admin Console), SentinelOne Singularity EDR/XDR, and patch and vulnerability management with Vicarius vRx.
Sophos Central
SentinelOne
Vicarius vRx
Cloud SecurityAWS Security Hub, CloudTrail, access control, and incident correlation with endpoint telemetry, alongside Microsoft 365 and Ubuntu Pro Landscape.
AWS Security Hub
CloudTrail
AWS CLI
Microsoft 365
Ubuntu Pro Landscape
Identity, Systems & NetworkingActive Directory, Entra ID, Intune (MDM), Windows Server, Linux (Kali-Purple, Ubuntu Pro), macOS, FortiGate Firewall, and Perimeter 81 VPN (now Check Point SASE).
Active Directory
Entra ID
Intune
Windows Server
Linux
macOS
FortiGate
Perimeter 81 / Check Point SASE
CI/CD & DevSecOpsJenkins, Bitbucket, and Apache Airflow for pipeline orchestration, with SAST integration (Semgrep, SonarQube Scanner) for code-level vulnerability checks.
Jenkins
Bitbucket
Apache Airflow
Semgrep
SonarQube Scanner
Security Testing & AnalysisNessus, Nmap, Burp Suite, WPScan, Wireshark, the OSINT Framework, and the Kali distribution.
Nessus
Nmap
Burp Suite
WPScan
Wireshark
OSINT Framework
Kali Linux
Governance & ComplianceCyber Essentials Plus readiness (from gap assessment to working with the assessor at audit stage), ISO 27001, GDPR, risk assessments, and security policy and SOP authorship.
ISO 27001
ISO 9001
Cyber Essentials Plus
GDPR
SOC 2
SOX
NIST
PCI DSS
DSPT
HIPAA
CIS Controls
COBIT
Stakeholder CollaborationPartnering with IT, DevOps, developers, compliance, and leadership to embed security into daily operations.
Cross-functional