How Babatunde Michael Oluwafemi’s career connects hands-on technology, third-party security governance and a distinctly human approach to responsible digital systems
Cybersecurity is often described through tools, threats and technical controls. Yet much of the work that keeps organizations secure happens in quieter places: the review of a supplier’s evidence, the careful documentation of a weakness, the follow-up that turns a finding into remediation, and the training that helps employees recognize risk before it becomes an incident.
That practical view of security has shaped the career of Babatunde Michael Oluwafemi, an information technology and cybersecurity professional whose experience spans information security engineering, third-party risk management, infrastructure support and technical instruction. His professional journey reflects a broader change taking place across the technology sector: cyber resilience increasingly depends not only on defensive tools, but also on disciplined governance, clear communication and people who can connect technical findings with business decisions.
From technical foundations to security governance
Oluwafemi’s background began with computer science, hardware engineering and data processing. He later completed a Higher National Diploma in Computer Engineering, adding to earlier qualifications in Computer Science and Computer Hardware Engineering. This combination gave him a working understanding of devices, operating systems, networks and maintenance before his responsibilities expanded into information security.
His early work as an IT technician involved configuring desktop and laptop computers, supporting networks, transferring data, installing software and performing system upgrades. In parallel, he became a computer engineering instructor, teaching computer repair, networking, software installation and preventive maintenance. The two roles reinforced each other: resolving real technical problems sharpened the lessons he could bring to learners, while teaching required him to explain complex systems in clear and practical terms.
That ability to translate technical detail became increasingly valuable as his career moved toward security governance. Cybersecurity teams rarely operate in isolation. Their findings must be understood by procurement teams, legal professionals, business owners, vendors and executives—each of whom sees risk through a different lens.
Strengthening third-party security decisions
As a Senior Information Security Engineer at Lolubyte Consult Inc., a role he has held since 2016, Oluwafemi has worked with business, legal and procurement stakeholders on the security onboarding and ongoing monitoring of suppliers and vendors. His responsibilities include reviewing Standardized Information Gathering and Cloud Security Alliance questionnaires, together with assurance materials such as SOC reports, ISO 27001 documentation, PCI DSS reports and penetration-testing results.
The objective is not simply to collect documents. Effective third-party risk management requires professionals to interpret evidence, identify control gaps, document findings and help the relevant owners determine what should happen next. Oluwafemi’s work has included coordinating remediation, maintaining risk information, preparing scorecards and escalating unresolved issues when necessary.
He has also supported security-awareness programs, phishing exercises, audit evidence collection, vulnerability reviews, policy compliance and responses to customer security questionnaires. These activities sit at the intersection of assurance and operations: they help an organization show how its controls are designed while also examining whether those controls function in practice.
Working across standards without losing sight of context
Oluwafemi’s experience includes work with frameworks and regulatory requirements such as ISO 27001, NIST SP 800-53, the CIS Controls, HIPAA, GDPR, CCPA and PCI DSS. Each framework has a different purpose, but organizations frequently need to understand how their policies, evidence and security activities relate across several of them at once.
During his time as an Information Security Analyst at Larmax Homes from 2017 to 2022, he assessed vendor questionnaires and supporting records, documented weaknesses, contributed to security policies and procedures, and supported risk profiles and reassessments. This experience strengthened a consistent theme in his work: controls become useful only when they are connected to clear ownership, reliable evidence and follow-through.
His practical toolset has included governance and workflow platforms such as OneTrust, ZenGRC, Venminder, Jira and Salesforce; security-awareness technology such as KnowBe4; and technical assessment tools including Wireshark, Nmap, Nessus, Nikto and Astra Pentest. The breadth matters because governance decisions are stronger when they are informed by both documentary assurance and technical understanding.
A human-centered perspective on responsibility
An unusual dimension of Oluwafemi’s professional story is his experience in assisted-living and hospice support. For several years, he worked as a medication technician, assisting residents with scheduled medication support and daily living needs. In 2026, he began serving as a hospice Certified Nursing Assistant, providing personal assistance to patients in homes and care facilities.
These responsibilities are distinct from cybersecurity, but they share important professional habits: accurate documentation, respect for privacy, careful communication, reliability and awareness that procedures affect real people. In environments involving health information and vulnerable individuals, trust is not abstract. It is built through consistency and responsible handling of both information and human needs.
That perspective is increasingly relevant to technology professionals. Security controls protect more than systems; they protect customers, patients, employees and communities whose lives are shaped by digital services. A human-centered understanding of risk can therefore improve the judgment behind technical and governance decisions.
The next stage of cyber resilience
Oluwafemi’s career illustrates how modern cybersecurity work is evolving. Organizations need specialists who can assess technical evidence, understand recognized control frameworks, communicate with nontechnical stakeholders and sustain remediation over time. They also need professionals who recognize that security maturity is not achieved through a single assessment or product, but through repeated, accountable decisions.
By combining hands-on IT knowledge, security governance, teaching experience and service-focused work, Oluwafemi has developed a multidisciplinary approach to risk. His record is a reminder that some of the most valuable cybersecurity contributions are made by professionals who can move between systems and people—examining the evidence, clarifying the risk and helping others take the next responsible action.
Suggested short bio
Babatunde Michael Oluwafemi is an information technology and cybersecurity professional with experience in third-party risk management, security controls assessment, vulnerability management, IT support and technical instruction. His work focuses on connecting security evidence, governance and practical remediation.
Editorial note: Confirm the byline, employer naming permissions, role dates and any additional measurable outcomes before submission. The draft intentionally avoids unsupported rankings, awards and performance figures.



