Senior Cloud Engineer building FedRAMP- and NIST 800-53-aligned cloud security as code across AWS (commercial + GovCloud), Azure, and GCP.
class DustinArrington:
def __init__(self):
self.role = "Senior Cloud Engineer"
self.focus = "AWS cloud security & compliance automation"
self.clouds = ["AWS (commercial + GovCloud)", "Azure (Public + Government)", "GCP"]
self.frameworks = ["FedRAMP Rev5", "FedRAMP 20x KSIs", "NIST 800-53 Rev5",
"SOC 2", "ISO 27001:2022"]
@property
def principles(self):
return [
"Short-lived credentials only (OIDC / SSO)",
"Honest coverage-gap documentation",
"Partition-aware by default",
"Every repo scanned in CI (Checkov, Trivy, Gitleaks, tflint)",
]| Repository | Purpose | |
|---|---|---|
| 🛡️ | fedramp-terraform-library | Terraform modules implementing NIST 800-53 Rev5 Moderate/High controls + FedRAMP 20x KSIs |
| 🏗️ | fedramp-cfn-library | CloudFormation counterpart of the above |
| 🤖 | fedramp-cloud-compliance-skill | Agent Skill for Claude Code: FedRAMP 2026 Consolidated Rules (Rev5 + 20x) on AWS, Azure, GCP |
| 🧾 | grc-evidence-automation | Scheduled, tamper-evident AWS/GCP control evidence mapped to SOC 2, ISO 27001, NIST 800-53, FedRAMP 20x |
| Repository | Purpose | |
|---|---|---|
| 🧰 | aws-cloud-security-toolbox | Practical guardrails, auto-remediation, AI/ML protections (CFN + TF) |
| 🚨 | aws-remediation-orchestrator | Security Hub-driven remediation: policy registry, blast-radius guardrails, human approval gate |
| 🔍 | prowler-aws-template | Org-wide Prowler scans for under $1/month: GitHub Actions + OIDC, StackSet read-only roles, emailed HTML reports |
| 📊 | aws-observability-dashboards | CloudWatch dashboards for security posture, Bedrock, agentic AI, NHI, EKS |
| 🌱 | aws-orgseed | Multi-org account seeding via hub-and-spoke OIDC (no long-lived credentials) |
| 🔑 | aws-orgctl | Ephemeral SSO / IAM Identity Center credential manager |
| 🚢 | aws-platform | Self-service AWS platform on EKS: golden-path onboarding, OIDC-only CI/CD, policy-as-code |
| 🧩 | ai-terraform-toolkit | Security-hardened Terraform modules + Claude / Gemini AI workflows |
| Repository | Purpose | |
|---|---|---|
| 🔷 | azure-lighthouse-tf | Azure Lighthouse delegated management across Azure Public and Government |
| 🔹 | azure-baseline-tf | Azure Policy guardrails, immutable Activity Log archive, keyless GitHub Actions auth |
| ☁️ | gcp-org-baseline-tf | GCP org policy guardrails, locked audit-log archive, Workload Identity Federation |
| Repository | Purpose | |
|---|---|---|
| 🧪 | ai-agent-security-toolkit | Prompt-injection fuzzer, tool-call sandbox with taint tracking, output validation, audit log |
| Repository | Purpose | |
|---|---|---|
| 💻 | workstation-bootstrap | Workstation bootstrap (Windows / macOS / WSL2) for Terraform and AWS tooling, with automated tool-version pin checks |
- FedRAMP Moderate / High / 20x baselines
- Multi-account AWS Organizations governance
- AI/ML (Bedrock, SageMaker, agentic workloads) security
- Continuous monitoring & observability
- Zero long-lived credentials patterns



