01
Headline
Most important
Goes in: the line under your name. This is the #1 field recruiters search. Keyword-dense on purpose. Pick one (220 char max).
Security Researcher | Application & AI/Agent (MCP) Security | Published CVEs + IBM-accepted advisory | Incomplete-fix & variant analysis | Immunefi-cleared
Alt, more punch
I find the bugs patches leave behind | Security Researcher, AppSec + AI/Agent (MCP) | Published CVEs, IBM-accepted advisory | Immunefi-cleared auditor
02
About
Goes in: the About section. First person, human, receipts up front. Tap to copy the whole thing.
I find the vulnerabilities that patches leave behind.
My specialty is incomplete-fix and variant analysis: I read a project's own security patch, and its fork history, and I find the residual the fix did not reach. That has earned me three published CVEs in software people run in production, File Browser (rated High, CVSS 8.2), OpenBao, and Gitea, plus accepted security advisories at IBM (their MCP Gateway) and Incus.
A lot of my recent work is in MCP and AI-agent security, the fast-moving space where AI systems get handed real credentials and infrastructure. I hunt SSRF, credential forwarding, and auth bypasses in that layer. I am also an Immunefi-cleared smart-contract auditor, with findings on dYdX and Polymarket.
I do not stop at a theory. I reproduce every finding against the real software, confirm the impact, and hand the maintainer a working fix. To keep the research compounding, I built an autonomous multi-agent pipeline that continuously discovers, verifies, and triages vulnerability candidates.
Open to security research, application security, and AI/agent security roles, remote. Reach me at kingsley@securva.net.
03
Skills
Recruiters search these
Goes in: the Skills section. Right now your top skills lead with Web Design / SEO / Marketing (Pejji), which BURIES the security. Reorder so security is on top, and add any of these you are missing. Tap to copy.
Vulnerability Research
Application Security (AppSec)
AI Security
MCP / AI-Agent Security
Source Code Review
Server-Side Request Forgery (SSRF)
Penetration Testing
Smart Contract Auditing
Security Research
Incident Response
Python
Go
Burp Suite
Threat Modeling
Cloud Security
Cryptography
Pin as your top 3: Vulnerability Research, Application Security, AI Security.
04
Experience
Keep your real roles. Just REPLACE each description with these (they lead with the security work). Your Securva role is where the CVEs go, and beef up the Upwork Pentester one, it is 3+ years of real security work that is currently thin.
Founder, Securva (paste as the description)
Security research and application-security audits. Published CVEs credited to me in software used by millions: File Browser (High, CVSS 8.2), OpenBao, and Gitea, plus accepted advisories at IBM (their MCP Gateway) and Incus. I specialize in incomplete-fix and variant analysis, finding the residual bug a patch leaves behind, and in MCP / AI-agent security (SSRF, credential forwarding, auth bypass). I also run NDPA data-protection audits for businesses, and I built an autonomous multi-agent pipeline that continuously discovers and verifies vulnerabilities.
Penetration Tester, Upwork (surface + beef up)
3+ years of freelance penetration testing and security assessments for clients across web2 and web3. Web application testing, vulnerability research, source-code review, and responsible disclosure. This hands-on client work is the foundation the published CVEs and audit practice grew out of.
Founder, Pejji (keep, tighten)
Secure-by-default web platform for African founders: privacy and NDPA compliance, cookie consent, security headers, and CI/CD security checks on every site. I own the architecture, the Cloudflare deployment, and the security posture end to end. Real sites live in production.
05
Featured
Goes in: the Featured section (add link). Pin these so the receipts are visible without scrolling.
babakizo.com (portfolio + wins)
github.com/babakizo420/security-research (tools + CVE writeups)
The File Browser advisory: github.com/advisories/GHSA-fmm7-x4gx-8jhr
Add a short caption to each, e.g. on the GitHub repo: "My incomplete-fix tooling + CVE writeups."
06
Settings that get you found
- Turn on Open to Work (set to recruiters-only if you want it discreet, or public for the banner). Add the role titles + Remote.
- Set location to Calgary + turn on Remote in job preferences.
- Clean your profile URL: linkedin.com/in/kingsley-olukanni (edit under the public profile settings).
- Add kingsley@securva.net and github.com/babakizo420 to Contact Info.
- Swap your banner to the black + gold look to match babakizo.com (I can make you one).