Scene 05 of 06Model cardRef. EO-MC-v2026.09Card updated 2026-09-24Back to the case file
Model card
Me, documented the way AI models are: what I am for, what I am not for, what I was trained on, how I was evaluated, and where I fall short.
In plain English: AI companies publish a “model card” so buyers know what a model is good at and where it fails. This is mine, with a glossary of every technical term on this site.
Model card
Model: ezekiel-ologunde
v2026.09D.Eng. checkpoint expected 2027-09
license: open-to-work
Security engineering, AI security and governance, GRC, detection and cybersecurity education roles. Birmingham, Alabama. Remote available.
How to get startedpython, illustrative
# the only step that needs a human
from hiring import load
model = load("ezekiel-ologunde", revision="v2026.09")
model.assign(role="security engineering") # or AI security, GRC, detection, teaching
# endpoint: ologundeomotola@gmail.com
01Summary
In plain English: who I am, what I do now, and what I want next, in three short paragraphs.
I started out keeping strangers’ computers alive in an internet cafe in Ilorin, Nigeria, and spent the next ten years in IT support, web work and, eventually, wiring oil pump controls into SCADA pipelines.
A master’s in cyber forensics taught me to ask what happened and how we know. That question followed me into AI-era security: my doctoral work at George Washington University (D.Eng., expected September 2027) is on AI and ML threat modeling, adversarial machine learning and explainable AI, and at Cyntraix I advise on security risk, AI risk included.
I teach this at three institutions, test what I recommend in my own lab first, and I am looking for the next role.
Card authored by the model. Conflict of interest: total. To compensate, every number below points to an exhibit you can check.
02Model details
In plain English: the basic facts: name, job, location, and the doctorate that is still in progress.
| Maintainer | Ezekiel Ologunde |
|---|---|
| Model type | Security consultant, cybersecurity instructor, doctoral researcher in AI security |
| Organization | Cyntraix, founder and principal consultant, since 2025-01 |
| Lineage | IT support and systems, 2011 to 2022M.S. Cyber Forensics, 2024AI security research and teaching, 2024 onward |
| First commit | 2011-06, Ilorin, Nigeria |
| Deployed at | Birmingham, Alabama. Remote available. |
| Current revision | v2026.09 |
| Next checkpoint | Doctor of Engineering, Cybersecurity Analytics, The George Washington University, expected 2027-09. Pending; do not cite as awarded. |
| Paper | ACM-format paper on Breakwater, in preparation |
| Repository | github.com/ezekielologunde |
| Memberships | ISSA, ISACA, MS-ISAC, CAMI, IEEE (student). Mentor, Cyber Ready Professionals. |
03Intended use
In plain English: the kinds of jobs I am a good fit for, each with the proof.
| Task | Supported by |
|---|---|
| security-engineering | Six builds, each with the security design written down before the code. Exhibit E |
| ai-security-and-governance | Doctoral research on AI and ML threat modeling and adversarial ML; AI risk advisory at Cyntraix. Exhibit D |
| grc | Risk governance and Zero Trust architecture at Cyntraix; a public health insurance agency that handled sensitive health data; a CMMC 2.0 course. |
| detection | A running SIEM and host-based detection lab with scheduled searches and a daily digest. Exhibit B |
| teaching | High school to university: Syracuse, Lawson State, UAGC, Adrian College. |
Also accepts: research collaborations, and Cyntraix engagements: security assessments, Zero Trust architecture, risk governance and AI security risk.
04Out-of-scope use
In plain English: the jobs and claims I am not the right fit for, stated up front so nobody is surprised.
The model should not be used for the following. Listed here so nobody finds out in the interview.
| Use | Why |
|---|---|
| SAST, DAST or secret scanning in CI/CD | No pipeline of mine runs these tools yet. A small public repo is planned. |
| Infrastructure as Code (Terraform, Ansible) | The lab was configured by hand in Proxmox and the shell. Not claimed. |
| Hands-on AWS services | No account work or artifact on file. Not claimed. |
| Paid SOC tier work | The SIEM lab is real; a paid SOC role is not. Not claimed. |
| Addressing the model by a doctoral title | Checkpoint not released until 2027-09 at the earliest. |
05Training data
In plain English: my education and every job I have held, in order.
Two corpora, collected over fifteen years. Overlaps are real; some years had two jobs.
Formal education
| Dataset | Source | Completed |
|---|---|---|
| A.S. Computer Science | Kwara State Polytechnic | 2014-08 |
| B.S. Computer Science and Education, dual major | University of Ilorin | 2019-10 |
| M.S. Cyber Forensics, GPA 3.9 | University of Baltimore | 2024-05 |
| D.Eng. Cybersecurity Analytics | The George Washington University | exp. 2027-09 |
Work experience
| # | Source | Role | Domain | Range |
|---|---|---|---|---|
| 01 | Global Link Internet Cafe | Cafe manager, Ilorin | systems | 2011-06 .. 2012-11 |
| 02 | Dreamlabs Softwares | Manager and website administrator, internship | web | 2014-06 .. 2015-09 |
| 03 | Pulse Technologies | Technical support agent | access | 2016-02 .. 2020-10 |
| 04 | Ebonyi State Health Insurance Agency | IT officer, Abakaliki | regulated-data | 2019-11 .. 2020-10 |
| 05 | Dreamlabs Softwares | IT support specialist | systems | 2020-10 .. 2022-08 |
| 06 | Lubcon Group | IT intern | systems | 2021-06 .. 2021-12 |
| 07 | Total Secure | Integration technician, OT and SCADA | ot-scada | 2021-10 .. 2022-03 |
| 08 | Boston University | Graduate teaching assistant, Experience Design | teaching | 2022-09 .. 2022-12 |
| 09 | Enterprise Community Partners | Community development intern, Baltimore | community | 2023-05 .. 2023-09 |
| 10 | Syracuse City School District | Cybersecurity instructor | teaching | 2024-08 .. 2025-06 |
| 11 | Cyntraix | Founder and principal consultant. Clients: withheld | advisory | 2025-01 .. now |
| 12 | Lawson State Community College | Computer science instructor, Birmingham | teaching | 2025-06 .. now |
| 13 | Cyber Ready Professionals | Mentor to early-career professionals | mentoring | 2025-09 .. now |
| 14 | University of Arizona Global Campus | Online faculty, network penetration testing | teaching | 2026-03 .. now |
| 15 | Adrian College, via Rize Education | Ethical hacking instructor | teaching | 2026-fall .. now |
Rows marked with a bar are still held.
Supplementary data
CompTIA Security+ (2026-05). Google Cybersecurity Professional Certificate (2023-11). App Academy AI-Powered Software Development and Generative AI Engineering (2025-07). Introduction to Generative AI, Google Cloud (2023-05). IC3 and a CMMC 2.0 course (2026-02). SANS AI Cybersecurity Forum (2024). Agentic AI Bootcamp, Howard AI Network (2026). Full ledger
06Evaluation
In plain English: measured results, each taken from something real, with the setting it was measured in.
No benchmark was invented for this card. Each result is a count or a measurement from a real artifact, next to the setting it was measured in. Where the setting is a simulation or a home lab, the table says so.
| Eval | Setting | Metric | Value |
|---|---|---|---|
| homelab/siem | live SIEM index, 2 nodes at home | events ingested, 24 h | 304,708 |
| homelab/siem | same | log sources | 5 |
| homelab/hids | host agents, 7 days | host-based alerts | ~3,700 |
| breakwater/discovery | simulated OT/IoT, 26 declared devices | hosts admitted | 20 (77%) |
| breakwater/discovery | same | phantom hosts | 0 |
| breakwater/vuln | NVD match on admitted identities | CVEs matched | 248 |
| breakwater/creds | simulation only | default-credential findings | 19 |
| ai-security/witness | Breakwater paper | AI techniques tied to a required witness | 7 of 7 |
| builds/design | own software | builds with a written security design | 6 of 6 |
| written/ssrn | 2024 to 2026, not peer reviewed | preprints | 24 |
| teaching/sites | high school to university | institutions taught at | 4 |
07Limitations and biases
In plain English: where my evidence is thinner than it looks, stated honestly.
- Small lab, labeled as such. The lab is two small machines at home, not an enterprise. Its numbers are real and small.
- Simulated network. Breakwater runs against simulated containers. Nothing in it is presented as client work.
- Preprints are not peer review. Twenty-four SSRN preprints show output, not refereeing. The ACM paper is still in preparation.
- Known gaps. No CI security pipeline, Infrastructure as Code, hands-on AWS or paid SOC work on file yet. Each has a small public repo planned, and none moves onto this card until it exists.
- Evidence bias. Fine-tuned on forensics, the model asks “how do we know?” before agreeing to anything. This is intended behavior.
- Author bias. The card was written by the model. Every number links to its exhibit for that reason.
08Safety and security
In plain English: how I keep my own systems, and this website, safe.
Practices the maintainer applies to his own systems, including this page.
| private-by-default | Repositories that hold private data or move money stay private. Client names stay out of public pages. |
|---|---|
| leak-guard | Every commit on HoWz passes a leak guard; backups are encrypted and signed. |
| sanitized-figures | Lab figures are redrawn excerpts: source names and counts only, no addresses or hostnames. The Breakwater subnet is withheld even though it is fake. |
| human-approval | Where a language model can suggest changes to my systems, it can only propose. Code validates every proposal, and nothing is written until I approve it. |
| local-model | The lab’s small model runs on a CPU, was installed only after its release checksum was verified, and listens on the lab network only. |
| least-privilege | Scheduled SIEM searches run under a search-only service account that can read one index and nothing else. |
| this-page | Content Security Policy, no trackers, no analytics, no cookies, no third-party scripts. Fonts are the only outside request. |
09Changelog
In plain English: my career as a dated list, newest first.
- 2027-09PENDD.Eng. Cybersecurity Analytics, George Washington University. Expected; not released.
- 2026-fallRELv2026.09 (current). Doctoral coursework done; praxis research begins on explainable AI, AI and ML threat modeling and AI-enabled security governance. Teaching Ethical Hacking at Adrian College.
- 2026-summerRESBreakwater later phases: federated intrusion detection with poisoning and privacy defenses; RL agents behind safety controllers. Agentic AI Bootcamp, Howard AI Network.
- 2026-05RESBreakwater Phase 1: discovery run against a simulated OT/IoT network, checked against declared ground truth.
- 2026-05CERTCompTIA Security+.
- 2026-03ROLEOnline faculty, CYB102 Network Penetration Testing, University of Arizona Global Campus.
- 2026-02CERTIC3. CMMC 2.0 course, LinkedIn Learning.
- 2025-12PUBEssay: why risk management matters more than ever in the age of AI.
- 2025-10PUBBootKitty preprint, and a paper aligning threat actor TTPs to the kill chain.
- 2025-09ROLEMentor to early-career professionals, Cyber Ready Professionals.
- 2025-07CERTApp Academy AI-Powered Software Development and Generative AI Engineering.
- 2025-06ROLEComputer science instructor, Lawson State. Helped redesign the CIS curriculum into one stackable pathway.
- 2025-01RELFounded Cyntraix: security assessments, Zero Trust architecture, risk governance.
- 2024-08ROLEFirst classroom of my own: high school cybersecurity, Syracuse City School District.
- 2024PUBFirst SSRN preprints, including cryptographic protocols for electronic voting. SANS AI Cybersecurity Forum.
- 2024-05RELM.S. Cyber Forensics, GPA 3.9. From keeping systems up to explaining what happened to them.
- 2023-11CERTGoogle Cybersecurity Professional Certificate.
- 2023-05CERTIntroduction to Generative AI, Google Cloud. The AI thread starts here.
- 2022-09ROLEGraduate teaching assistant, Experience Design, Boston University.
- 2021-10ROLEFirst OT work: oil pump control and monitoring into OT networks and SCADA data pipelines, Total Secure.
- 2019-11ROLEFirst regulated environment: IT officer, Ebonyi State Health Insurance Agency.
- 2019-10EDUB.S. Computer Science and Education, University of Ilorin.
- 2016-02ROLETechnical support agent, Pulse Technologies. Four years of who is allowed to open what.
- 2014-08EDUA.S. Computer Science, Kwara State Polytechnic.
- 2014-06ROLEWebsite administrator internship, Dreamlabs Softwares.
- 2011-06INITInitial commit: running an internet cafe in Ilorin. The machines, the network, and every customer whose email would not open.
10Citation
In plain English: how to reference this page in a paper or report.
If this model is useful in your work, please cite it. Better yet, hire it.
@misc{ologunde2026,
author = {Ologunde, Ezekiel},
title = {ezekiel-ologunde: a model card},
year = {2026},
version = {v2026.09},
note = {D.Eng. checkpoint expected 2027-09. ORCID 0009-0005-7207-8506},
howpublished = {\url{https://ezekielologunde.github.io/}}
}
11Glossary
In plain English: short explanations of the technical terms used on this site.
- Adversarial machine learning
- Attacks that trick or corrupt AI models, and the defenses against those attacks.
- AI
- Artificial intelligence: software that learns patterns from data and makes suggestions or predictions.
- Attack graph
- A map of the steps an attacker could take, from a starting point to a target.
- Capture the flag
- A security exercise where students solve hacking puzzles to find hidden answers, called flags.
- CI
- Continuous integration: automated checks that run every time the code changes.
- CMMC
- Cybersecurity Maturity Model Certification: the U.S. Defense Department’s security standard for its contractors.
- CPE
- A standard name for a product and version, used to match it to its known flaws.
- CVE
- Common Vulnerabilities and Exposures: the public ID number given to each known security flaw.
- CVSS
- A 0 to 10 score of how severe a security flaw could be.
- D.Eng.
- Doctor of Engineering, a doctoral degree focused on applied research. His is expected in September 2027.
- Differential privacy
- A mathematical way to learn from data without exposing any single person’s or site’s records.
- Digital forensics
- Investigating computers and networks to find out what happened, and proving it with evidence.
- EDR
- Endpoint detection and response: software on each computer that watches for attacks and helps stop them.
- EPSS
- A 0 to 1 estimate of how likely a security flaw is to be used by attackers soon.
- Ethical hacking
- Hacking with permission, to find and fix weaknesses.
- Explainable AI
- AI whose decisions can be explained to a person, so they can be checked.
- Federated learning
- Training one AI model across several sites without sending their raw data to one place.
- GRC
- Governance, risk and compliance: making sure an organization manages its risks and follows the rules it must follow.
- Host-based detection
- Software on each computer that watches for signs of an attack on that machine.
- IoT
- Internet of Things: everyday devices on a network, such as cameras, speakers and thermostats.
- KEV
- The U.S. government’s (CISA) catalog of flaws that attackers are known to be using.
- Language model
- An AI system that reads and writes text, such as a chat assistant.
- LLM
- Large language model: the kind of AI behind chat assistants, which reads and writes text.
- MQTT
- A lightweight messaging system many smart devices use to talk to each other.
- NIST
- The U.S. National Institute of Standards and Technology, which publishes widely used security frameworks.
- NVD
- The U.S. National Vulnerability Database, the public record of known security flaws.
- OT
- Operational technology: computers that run physical equipment such as pumps, valves and production lines.
- Penetration testing
- Authorized, simulated attacks that find weaknesses before criminals do.
- Preprint
- A research paper shared publicly before, or without, formal peer review.
- Prompt injection
- Hidden instructions slipped into text an AI reads, trying to make it do something it should not.
- Proxmox VE
- Software that runs many virtual computers on one physical machine.
- Reinforcement learning
- Training an AI by trial and reward, the way a game-playing AI learns.
- RLS
- Database rules that decide which rows of data each user is allowed to see.
- SBOM
- Software bill of materials: a list of every component inside a piece of software.
- SCADA
- Supervisory control and data acquisition: systems that monitor and control industrial equipment from a distance.
- SIEM
- Security information and event management: software that gathers activity records from many systems in one place and raises alerts.
- SSRN
- An online library where researchers post papers, often before or without formal peer review.
- Threat model
- A structured list of what could go wrong in a system, how, and what stops it.
- Zero Trust
- A security approach where no user or device is trusted by default, even inside the network.
12Contact
In plain English: how to reach me.
Write about a security engineering, AI security, GRC, detection or teaching role, a research collaboration, or a Cyntraix engagement.