Open to work — hybrid, remote or relocation

Systems that stay up.
Even on a bad day.

I'm Musbaudeen Oyedeji, an IT Manager in Nigeria. I run servers, lock them down, automate the boring parts, and build the apps that sit on top.

Windows ServerMicrosoft SQL ServerAzure & Entra IDAWSIISActive DirectoryPowerShellLinuxWazuhTailscaleJenkinsGitHub ActionsDatadogGrafanaMicrosoft 365ISO 27001 Windows ServerMicrosoft SQL ServerAzure & Entra IDAWSIISActive DirectoryPowerShellLinuxWazuhTailscaleJenkinsGitHub ActionsDatadogGrafanaMicrosoft 365ISO 27001

What I do

Four jobs. One person you can call.

Most teams need someone who can hold the server, the firewall, the pipeline and the product in their head at the same time. That's the job I've been doing for six years.

Run the infrastructure

Servers, networks, Microsoft 365, backups and disaster recovery across multiple sites. I keep 150+ hosted environments online and boring.

  • Windows Server
  • MSSQL
  • Active Directory
  • DR & backup

Secure it

Hardening, incident response, vulnerability testing and SIEM. I've contained a live server compromise and written the tool that finally found it.

  • Incident response
  • Wazuh
  • VAPT
  • ISO 27001

Automate and ship

CI/CD pipelines, PowerShell tooling and cloud on Azure and AWS. Deployments and restores should be a button, not an evening.

  • Jenkins
  • GitHub Actions
  • PowerShell
  • Azure

Build on top

AI-assisted full-stack development. Not demos — products in production, paying customers, real schools using them every term.

  • Full-stack
  • AI-assisted
  • Product
  • Live in prod

Selected work

Built it, broke it, fixed it, shipped it.

Each of these started as a real problem on a real system. Screenshots are from my own builds.

Security engineering

An enterprise SIEM with nothing exposed to the internet

I deployed Wazuh behind a Tailscale mesh. The monitoring stack has no public IP and no port forwarding. Ports 443, 55000 and 9200 answer only over the mesh, and UFW allows Tailscale traffic and nothing else. Everything inbound is denied by default.

  • Wazuh manager, indexer and dashboard on Tailscale IPs (100.x.x.x)
  • No DMZ, no port forwarding, no public exposure
  • WireGuard encryption end to end, with automatic key rotation
  • Agents reporting from Windows Server, Linux, Docker, macOS and network gear
  • Wazuh
  • Tailscale
  • WireGuard
  • UFW
  • Ubuntu Server

Full write-up publishing soon.

The path in: public internet → Tailscale mesh → Wazuh cluster in a private VPC. Nothing else gets through.

Incident response · Tooling

Commercial scanners said clean. The sites were not.

Several WordPress sites were compromised. Off-the-shelf scanners found nothing, so I wrote my own in PowerShell, from scratch, during the incident.

  • Detects 50+ malicious patterns: obfuscation, backdoors, card skimmers
  • Forensic reports with risk scoring on every hit
  • Quarantines suspicious files automatically, and backs them up first
  • Runs across many WordPress installs in one pass
  • False-positive filtering so the report stays readable
  • PowerShell
  • Forensics
  • WordPress
  • IIS hardening

One run on a single site: 186 suspicious files found and quarantined.

Every hit is moved to a timestamped quarantine folder, backed up first.
End of run: 186 suspicious files, a written report and a quarantine path.

Cloud · Automation

DNS you can actually put back

A Route53 backup and restore utility in PowerShell. It exports every hosted zone to structured JSON, zips it, ships it to S3, and restores either a whole zone or one record. Built for large DNS estates, with noisy warnings suppressed so the output stays clean.

  • Export all Route53 zones to structured JSON
  • Optional compression, then upload straight to S3
  • Restore a full zone, or a single record, on demand
  • AWS Route53
  • S3
  • PowerShell
  • DR

github.com/musbaudo →

The AWS-CLOUD repo, where the Route53 zone manager script lives.

Full-stack product

NyoGrade

A school academic platform for Africa, live in production. Attendance, scores, automatic grades and class positions, PDF report cards, a student portal, and scratch-card result checking for parents.

Used by schools in Nigeria, Ghana, Kenya and Tanzania.

  • Full-stack
  • AI-assisted
  • Payments
  • PDF engine
nyograde.com →

Bare metal

Windows Server on Hetzner, over KVM

A full dedicated-server build with remote hands only: custom image, our own purchased licence, then OS, networking, IIS, SQL Server and the security baseline. Licence spend dropped roughly 85% using compliant pre-owned perpetual licences.

  • Hetzner
  • KVM
  • IIS
  • Licensing

Compliance

VAPT for China Class certification

Ran the full vulnerability assessment and penetration test a classification body demanded, with governance mapped to ISO 27001, and delivered the report that cleared the product for sign-off.

  • Acunetix
  • ISO 27001
  • Reporting

Identity

OAuth2 gateway on Entra ID

Brought a legacy application onto modern authentication with an OAuth2 gateway on Azure AD (Entra ID), and moved every client secret and connection string into Azure Key Vault.

  • Entra ID
  • OAuth2
  • Key Vault

Continuity

Backups that survive the building

Automated off-site copies of SQL databases and application files to SharePoint and AWS S3 using Rclone, PowerShell and Task Scheduler. Two destinations, two geographies, restore tested.

  • Rclone
  • AWS S3
  • SharePoint

Delivery

Releases without the ritual

Jenkins pipelines and self-hosted GitHub Actions runners deploying straight to IIS environments, so a release is a merge instead of a checklist and a late night.

  • Jenkins
  • GitHub Actions
  • ASP.NET

I show my work

If I figured it out, I write it down.

Setting up a dedicated Windows Server on Hetzner? I've done it the hard way — message me and I'll save you the weekend.

Track record

Six years, four seats, one direction.

  1. Feb 2024 — now

    IT Manager · SDSD Prestige Limited, Nigeria (hybrid)

    I own the infrastructure: servers, security, 150+ hosted sites, SQL Server, releases, vendors and budget. Built the Windows Server 2022 and SQL estate, contained a live compromise, and ran a ₦10M laptop procurement.

  2. Aug 2024 — Mar 2025

    Infrastructure Engineer / IT Security · Future Tech Pros, UK (remote)

    Ran infrastructure, servers, networks and Microsoft 365 across sites, supported ERP and CRM, and put backup, DR and security controls in place.

  3. Nov 2021 — Jan 2024

    Technical Support Team Lead · MercurySoft Limited, Nigeria

    Led the support team, took every hard escalation, ran the monitoring stack (PRTG, Datadog, Zabbix, Defender), and wrote the processes the team still works to.

  4. Jan 2020 — Jan 2021

    IT Engineer, Application Support · Datapyramids Service Limited, Nigeria

    Kept business-critical apps healthy: SQL and log-level fault diagnosis, release and QA collaboration, tickets closed inside SLA through Jira and Zendesk.

Recognition

  • ₦350K performance bonus — for delivery as IT Manager and hitting every KPA target.
  • $250 innovation bonus — for the pre-owned perpetual licensing programme, delivered inside German licensing rules.
  • Best Team Leadership — MercurySoft, best team performance of the year.
  • B.Sc., University of Ilorin — 2018.

Certificates

Paper, and the practice behind it.

Grouped honestly: what I passed an exam for, what I proved in a lab, and what I sat down and learned. Click any certificate to read it full size.

Passed exam

One sat exam, one pass. Everything below it is lab work or training, and it is labelled that way on purpose — I'd rather you know exactly what each piece of paper is.

Hands-on labs

Training & courses

Also completed: ISO/IEC 27001 information security training (HiiT Nigeria) and the Project Management Standard (Imperial Business School).

Contact

Got a system that can't go down?

I'm open to IT management, infrastructure, security and DevOps roles — hybrid, remote or relocation. Tell me what's breaking, or what you're building.

Download my CV