I’m preparing my Global Talent Stage 1 application under Exceptional Promise in Digital Technologyand would really value honest, critical feedback before I submit. My areas are Application Security, Offensive Security / Vulnerability Research, and API & GraphQL Security. I graduated in 2022 with a BSc in Computer Engineering.
Mandatory Criterion – recognised as having potential to be a leading talent
-
- Hall of Fame recognition – Apple, Amazon, Quora, Yelp, Epic Games. I’m credited on their security acknowledgement pages for responsibly disclosed vulnerabilities. For Apple, I reported a GraphQL authorisation bypass through the Apple Security research program. It was paid and the fix is deployed. I have Hall of Fame screenshots and payment confirmations, but no formal letters from these companies.
- Remuneration evidence. I’m an Application Security Engineer at a unicorn in Nigeria, one of Africa’s largest fintechs, earning ₦12.99M a year about (9,000) pound. I’ve also earned $24,000 in lifetime bug bounty income across HackerOne, Bugcrowd, YesWeHack and Apple. On top of that, I’ve made ₦3M in penetration-testing consulting through consultation.
- Speaking & media. I gave a keynote, “State of Bug Bounty in Nigeria 2025” over 100+ attended, and a talk at HackWara 2026 +200 attended, “Beyond the Tool in Bounty”. I ran the HackingAPIwithDami workshop, which trained 150+ researchers in API vulnerability research. I was also featured as co-founder of Kudilo by StartupIn60 and Zikoko.
OC1 – Innovation
-
Kudilo – co-founder & technical lead. The company is registered with CAC (May 2026) and I hold 30% equity under a formal co-founder agreement. I designed the architecture and the security model: encryption of financial data, RBAC and fraud detection. I also built an ISO 27001-aligned ISMS.
-
Kudilo – traction. I co-founded Kudilo and am its CTO. It’s a WhatsApp-native bookkeeping and credit-tracking product for informal traders in Nigeria and Ghana. In under 6 months, with 100% organic acquisition, we reached 459 monthly active users, 528 workspaces, 87% monthly retention and about £700 MRR.
OC2 – Contributions beyond my occupation
- CyBlack – mentorship & community building. Over about 2 years at CyBlack, I mentored and taught 500+ aspiring security professionals, mostly from underrepresented backgrounds in Africa. [built the hacking cohort, and over 100 mentees who got jobs.
- HackingAPIwithDami workshop. I trained 150+ researchers in hands-on API vulnerability research. Over 5 have gone on to get a job or make money from vulnerability research all backed with picture evidence.
OC3 – Significant technical contributions
- Moniepoint – AppSec leadership. I lead security for Monieworld, Moniebook, Cosmos and Retina. I’ve found 12+ high-severity access-control and authorisation-bypass vulnerabilities and written 7+ threat models. I set up and manage Moniepoint’s HackerOne bug bounty programme, which has 12+ researchers and $2,000+ paid out so far. My performance rating is 4.0/5, with a bonus awarded.
- SchemaFinder (open source). It’s a Node.js tool I built that extracts GraphQL operations from JavaScript bundles for security recon. It’s public on GitHub (abidakun1/SchemaFinder) with 14 stars and evidence of usefulness By other researcher
Recommendation letters: I have three, from people holding these titles:
- Co-founder, CyBlack / Senior Program Manager at a cloud service provider (CCSP, CISM, PMP)
- Co-founder, Exploit Forge Ltd (8+ years in offensive security)
- Co-Founder, Cyblack a PhD holder in cybersecurity
What I’d like feedback on:
- Is my MC strong enough?
- Are OC1 and OC3 the right optional criteria?
- Should I switch to OC3 + OC2, or keep OC1 + OC3
- Does the Income remuneration help or hurt?
- Anything that looks like a red flag to an assessor?
Thanks in advance. Blunt feedback is very welcome.