APPLICATION SECURITY REVIEW
Identifying weaknesses across authentication, authorization and business logic.
- Focus
- Authentication · Authorization · Business logic
- Outcome
- — add outcome, only once verified —
Gabriel Odusanya · Application Security Engineer—Nigeria · Working Worldwide
Application Security Engineer · Educator · YouTuber · Mentor.
I work across application security, web & API security, penetration testing, threat modeling, and DevSecOps — helping organizations build more secure software and helping the next generation of security professionals become better practitioners.

Assess applications throughout their lifecycle, from architecture and threat modeling to testing and remediation.
Identify weaknesses across authentication, authorization, business logic, data exposure and API architecture.
Perform evidence-driven security testing designed to demonstrate realistic attack paths and business impact.
Assess mobile applications and their supporting APIs for authentication, data exposure, insecure storage and implementation weaknesses.
Identify attack surfaces, trust boundaries and abuse cases before vulnerabilities become expensive production problems.
Help teams integrate practical security controls into development workflows and the software delivery lifecycle.
Identifying weaknesses across authentication, authorization and business logic.
Testing APIs beyond automated scanners to uncover authorization and business-logic weaknesses.
Bringing security closer to the software development lifecycle.
Reviewing applications across the development lifecycle, from design and threat modeling through testing and remediation.
Evidence-driven testing of web, API and mobile targets, focused on realistic attack paths over checklist coverage.
Working with engineering teams to build practical security controls into everyday development workflows.
Teaching application security concepts and mentoring practitioners moving into the field.
Building OffShield Security, an applied security brand and product line.
A practical guide to making threat modeling a developer-first habit before design and code are locked in.
How Docker can be used to deploy appsec tooling and secure development environments with OWASP CRAPI.
An exploration of Entra ID, Azure AD evolution, and how identity should be treated for security and trust.
A real-world write-up showing how broken access control can turn a vulnerable admin panel into a breach path.
Why API authorization gaps are often more serious than UI-level access control issues.
A breakdown of the modern application attack surface and what defenders need to protect first.
A security mindset essay that focuses on strategy and practical thinking rather than tricks or jargon.
Practical lessons from testing AI-powered applications and the security controls they need.
A write-up showing SQL injection techniques on DVWA and what secure coding should prevent.
An IDOR tutorial that shows how to discover broken object access control with Burp Suite.
A beginner-friendly explanation of APIs, how they work, and why they matter for developers and security.
Security findings should be backed by evidence, not fear.
The goal is not to make a vulnerability sound frightening. The goal is to understand what it means and what deserves attention first.
A shorter, prioritized security assessment is more useful than a massive report nobody can act on.
Whether you’re securing a new product, reviewing an existing application, or building security into your engineering process, start with a few details and I’ll open WhatsApp with your request.
Share the details of your project and what you need most: assessments, threat modeling, secure architecture advice, or a practical security review.
What I help with