Currently — Breachrr & Verixar

Mohammed
Orunsolu.

Security Engineer and Founder specializing in Application & Product Security. I build secure products and stand up security programs from zero.

See field notes

Who I am

Security engineer and founder with a track record of building secure products and standing up security programs from the ground up. I founded and operate Breachrr, a credential exposure monitoring platform, and lead information security at Verixar Ltd., a seed-stage InsurTech, where I designed and implemented the company's entire information security program with no existing structure in place.

My work sits at the intersection of application security, product security, and operational security. I care about practical security that ships; threat modeling, auth design, continuous monitoring, policy that teams actually follow, and closing findings instead of collecting them.

Experience

Founder

Breachrr
2026 - Present · Remote

Continuous credential exposure monitoring for small companies; the kind of security tooling that used to require a Fortune 500 budget. Built and shipped end-to-end as sole engineer: application code, security architecture, infrastructure, and operations.

  • Free public audit tool as the primary lead magnet; returns actionable findings in under 10 seconds and converts anonymous visitors into trial users without signup.
  • Built the platform's security end-to-end; authentication and session architecture around refresh-token rotation with reuse detection (RFC 6819), authorization on every API endpoint, multi-tenant isolation, role-based team access, and plan-aware feature gating.
  • Operating the full production stack solo; deployment, scheduling, monitoring, database, and billing, with zero engineering headcount.

Information Security Lead

Verixar Ltd.
2026 - Present · London, UK · Remote

Sole security lead at a seed-stage InsurTech building a customer data verification and fraud prevention platform. Responsible for designing and implementing the company's entire information security program from scratch.

  • Delivered a working security program end-to-end; Information Security Policy, Cyber Incident Response Plan, BCDR, and Cyber Security Risk Register, plus the company's first formal penetration test with every tracked finding closed before sign-off.
  • Leading NCSC Cyber Essentials certification, established MFA across all accounts, and hardened a fully BYOD environment (FDE, screen lock, Cloudflare DNS filtering) without an MDM.
  • Hardened the platform's auth and API surface (JTI blocklist for logout invalidation, refresh-token replay rejection, authorization checks on every endpoint) and wired dependency scanning, Semgrep, and TruffleHog full-history secret scanning into CI as block-on-merge.

Range

My practice covers application and product security; threat modeling, auth and session architecture, secure development, controls in CI and on the production stack. It covers program development; policy, incident response, risk management, penetration testing, and certification. And it covers infrastructure; TLS posture, secret management, detection and logging, and cloud configuration.

The tools change project to project. The discipline is constant.

Education and certifications

  • CompTIA Security+ (SY0-701) - Score: 803/900 Passed · 2026
  • Google Professional Cybersecurity Certificate Completed · 2025
  • AWS Cloud Practitioner Essentials Completed · 2026
  • TS Academy - Cybersecurity Program Completed · 2026
  • GoMyCode - Cybersecurity Bootcamp (Security+ 701) Completed · 2026
  • TechCrush - Cloud Computing Bootcamp Completed
  • B.Tech - Federal University of Technology Akure (FUTA) Graduated 2023

Get in touch

Open to security engineering roles, freelance security engagements, and early-stage product work. If you are building something that needs serious security thinking from the start, or a security program that actually works, reach out.