Skip to content
View DustyStudy's full-sized avatar

Block or report DustyStudy

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
DustyStudy/README.md
Dustin Arrington - Senior Cloud Engineer

Senior Cloud Engineer building FedRAMP- and NIST 800-53-aligned cloud security as code across AWS (commercial + GovCloud), Azure, and GCP.

LinkedIn


About Me

class DustinArrington:
    def __init__(self):
        self.role = "Senior Cloud Engineer"
        self.focus = "AWS cloud security & compliance automation"
        self.clouds = ["AWS (commercial + GovCloud)", "Azure (Public + Government)", "GCP"]
        self.frameworks = ["FedRAMP Rev5", "FedRAMP 20x KSIs", "NIST 800-53 Rev5",
                           "SOC 2", "ISO 27001:2022"]

    @property
    def principles(self):
        return [
            "Short-lived credentials only (OIDC / SSO)",
            "Honest coverage-gap documentation",
            "Partition-aware by default",
            "Every repo scanned in CI (Checkov, Trivy, Gitleaks, tflint)",
        ]

The Suite

FedRAMP & Compliance

Repository Purpose
🛡️ fedramp-terraform-library Terraform modules implementing NIST 800-53 Rev5 Moderate/High controls + FedRAMP 20x KSIs
🏗️ fedramp-cfn-library CloudFormation counterpart of the above
🤖 fedramp-cloud-compliance-skill Agent Skill for Claude Code: FedRAMP 2026 Consolidated Rules (Rev5 + 20x) on AWS, Azure, GCP
🧾 grc-evidence-automation Scheduled, tamper-evident AWS/GCP control evidence mapped to SOC 2, ISO 27001, NIST 800-53, FedRAMP 20x

AWS Security & Governance

Repository Purpose
🧰 aws-cloud-security-toolbox Practical guardrails, auto-remediation, AI/ML protections (CFN + TF)
🚨 aws-remediation-orchestrator Security Hub-driven remediation: policy registry, blast-radius guardrails, human approval gate
🔍 prowler-aws-template Org-wide Prowler scans for under $1/month: GitHub Actions + OIDC, StackSet read-only roles, emailed HTML reports
📊 aws-observability-dashboards CloudWatch dashboards for security posture, Bedrock, agentic AI, NHI, EKS
🌱 aws-orgseed Multi-org account seeding via hub-and-spoke OIDC (no long-lived credentials)
🔑 aws-orgctl Ephemeral SSO / IAM Identity Center credential manager
🚢 aws-platform Self-service AWS platform on EKS: golden-path onboarding, OIDC-only CI/CD, policy-as-code
🧩 ai-terraform-toolkit Security-hardened Terraform modules + Claude / Gemini AI workflows

Multi-Cloud Baselines

Repository Purpose
🔷 azure-lighthouse-tf Azure Lighthouse delegated management across Azure Public and Government
🔹 azure-baseline-tf Azure Policy guardrails, immutable Activity Log archive, keyless GitHub Actions auth
☁️ gcp-org-baseline-tf GCP org policy guardrails, locked audit-log archive, Workload Identity Federation

AI Agent Security

Repository Purpose
🧪 ai-agent-security-toolkit Prompt-injection fuzzer, tool-call sandbox with taint tracking, output validation, audit log

Tooling

Repository Purpose
💻 workstation-bootstrap Workstation bootstrap (Windows / macOS / WSL2) for Terraform and AWS tooling, with automated tool-version pin checks

Tech Stack

Cloud

AWS GovCloud Azure GCP Kubernetes

Infrastructure as Code

Terraform CloudFormation GitHub Actions

Languages

Python HCL PowerShell Bash

Security Tooling

Checkov Trivy Gitleaks Prowler Security Hub Bedrock


Focus Areas

  • FedRAMP Moderate / High / 20x baselines
  • Multi-account AWS Organizations governance
  • AI/ML (Bedrock, SageMaker, agentic workloads) security
  • Continuous monitoring & observability
  • Zero long-lived credentials patterns

Dustin Arrington | Senior Cloud Engineer | AWS Cloud Security | FedRAMP / NIST 800-53 | Multi-Account Governance | Open Source

Pinned Loading

  1. fedramp-terraform-library fedramp-terraform-library Public

    Terraform modules implementing NIST 800-53 Rev5 Moderate/High controls and FedRAMP 20x Key Security Indicators for AWS.

    HCL 1

  2. aws-orgctl aws-orgctl Public

    Ephemeral AWS multi-account credential manager built on IAM Identity Center / SSO.

    Python

  3. ai-agent-security-toolkit ai-agent-security-toolkit Public

    Fuzz, contain, validate and audit LLM agents: prompt-injection fuzzer, tool-call allowlist/sandbox with taint tracking, output validation + tamper-evident audit log, and a STRIDE-for-agents threat …

    Python

  4. aws-platform aws-platform Public

    Self-service AWS platform on EKS: golden-path Terraform for tenant onboarding, OIDC-only CI/CD, and policy-as-code guardrails.

    HCL

  5. grc-evidence-automation grc-evidence-automation Public

    Scheduled, tamper-evident AWS/GCP control evidence mapped to SOC 2, ISO 27001:2022, NIST 800-53 and FedRAMP 20x KSIs, delivered to S3 or a GRC ingestion API. Lambda + Terraform.

    Python

  6. aws-cloud-security-toolbox aws-cloud-security-toolbox Public

    Practical AWS security guardrails, auto-remediation, and AI/ML protections — CloudFormation + Terraform, commercial & GovCloud.

    HCL