Cloud Security Engineering | Security Architecture | DevSecOps
Cloud security engineer with 8+ years in cybersecurity, turning security architecture into reviewable engineering outcomes across AWS, Microsoft Azure, and Google Cloud. My work combines Infrastructure as Code, identity and Zero Trust controls, cloud governance, detection, incident response, and security automation, with an emphasis on validation, controlled testing, remediation, and evidence.
Portfolio | LinkedIn | Engineering Writing
- Cloud security architecture across AWS, Microsoft Azure, and Google Cloud
- Terraform, Infrastructure as Code, and Git workflows
- IAM, Microsoft Entra ID, workload identity federation, permission boundaries, SCPs, Azure RBAC, and Zero Trust
- Multi-account / multi-cloud governance, CloudTrail, GuardDuty, EventBridge, and Azure identity controls
- Detection and incident response engineering
- AWS WAF, Google Cloud Armor, Azure security controls, and network security
- DevSecOps, security automation, controlled validation, remediation, revalidation, and engineering evidence
- Framework-aware engineering context: NIST, ISO 27001, HIPAA/HITRUST-aligned engineering, PCI DSS, and SOC 2. These references describe engineering context, not organizational compliance, certification, or attestation.
| Project | Case Study | GitHub Repo | What It Does |
|---|---|---|---|
| AWS Multi-Account Zero-Trust Architecture Lab | Case Study | Repository | Engineers AWS Organizations, SCPs, IAM boundaries, audit logging, GuardDuty, isolation, and policy-as-code validation for a multi-account Zero Trust lab. |
| Enterprise Multi-Cloud WAF Evaluation Platform | Case Study | Repository | Deploys and validates AWS WAF alongside equivalent Google Cloud Armor controls through reusable Terraform and evidence-backed testing. |
| HIPAA/HITRUST-Aligned Healthcare Security Engineering Platform | Case Study | Repository | Implements AWS-first segmentation, least privilege, logging, controlled validation, remediation, and teardown for a synthetic healthcare workload. |
Under Process
| Project | Case Study | GitHub Repo | What It Does |
|---|---|---|---|
| Confidential Multi-Party Data Collaboration Platform on Google Cloud | — | — | Current active project — in progress. |
| Project | Case Study | GitHub Repo | What It Does |
|---|---|---|---|
| AZ-01 — Azure Workload Identity Attack & Secretless Federation Lab | Case Study | Repository | Validates a bounded Microsoft Entra workload-identity attack path and remediates credential and authorization risk with GitHub OIDC federation and least-privilege Azure RBAC. |
| AZ-02 — Azure Cloud Security Architecture Review & Controlled Remediation Lab | Case Study | Repository | Assesses Azure governance, identity, private access, logging, and workload controls through controlled remediation, revalidation, and residual-risk review. |
| Project | Case Study | GitHub Repo | What It Does |
|---|---|---|---|
| AI-Powered Polycloud Security Incident Response Platform | Case Study | Repository | Builds an AWS-first event-driven incident-response architecture; Terraform implementation is in progress and Amazon Bedrock integration and attack simulation remain planned. |
- AWS advanced networking architecture: hybrid connectivity, Transit Gateway, Route 53, Direct Connect, VPN, VPC design, routing, network security, and troubleshooting
- Advanced AWS Organizations, IAM, SCP, Zero Trust, and policy-as-code patterns
- Microsoft Azure security engineering: Entra workload identities, OIDC federation, Azure RBAC, Terraform, and identity attack-path validation
- AI-assisted cloud security incident triage and response automation
- PMP domains: people, process, business environment, delivery, risk, stakeholder management, and agile/hybrid practices
- AWS Certified Advanced Networking – Specialty
- Project Management Professional (PMP)
Capability areas reflected in the engineering work and learning focus above.
Text summary: AWS / Azure / GCP · Identity, Zero Trust, and network security · Terraform and policy as code · Logging and investigation · Governance and framework alignment · Security automation (AI-assisted triage: learning).
View supporting certification, certificate, and training records in the portfolio
Friday Security Projects is a seven-part hands-on security engineering series. The writing hub centralizes public work across Hashnode, Medium, DEV, and LinkedIn.




