Skip to content
View nagasesank's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report nagasesank

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
nagasesank/README.md

Surya Naga Sesank M

Cloud Security Engineering | Security Architecture | DevSecOps

Cloud security engineer with 8+ years in cybersecurity, turning security architecture into reviewable engineering outcomes across AWS, Microsoft Azure, and Google Cloud. My work combines Infrastructure as Code, identity and Zero Trust controls, cloud governance, detection, incident response, and security automation, with an emphasis on validation, controlled testing, remediation, and evidence.

Portfolio | LinkedIn | Engineering Writing

Security Engineering Focus

  • Cloud security architecture across AWS, Microsoft Azure, and Google Cloud
  • Terraform, Infrastructure as Code, and Git workflows
  • IAM, Microsoft Entra ID, workload identity federation, permission boundaries, SCPs, Azure RBAC, and Zero Trust
  • Multi-account / multi-cloud governance, CloudTrail, GuardDuty, EventBridge, and Azure identity controls
  • Detection and incident response engineering
  • AWS WAF, Google Cloud Armor, Azure security controls, and network security
  • DevSecOps, security automation, controlled validation, remediation, revalidation, and engineering evidence
  • Framework-aware engineering context: NIST, ISO 27001, HIPAA/HITRUST-aligned engineering, PCI DSS, and SOC 2. These references describe engineering context, not organizational compliance, certification, or attestation.

Featured Projects by Domain

AWS

Project Case Study GitHub Repo What It Does
AWS Multi-Account Zero-Trust Architecture Lab Case Study Repository Engineers AWS Organizations, SCPs, IAM boundaries, audit logging, GuardDuty, isolation, and policy-as-code validation for a multi-account Zero Trust lab.
Enterprise Multi-Cloud WAF Evaluation Platform Case Study Repository Deploys and validates AWS WAF alongside equivalent Google Cloud Armor controls through reusable Terraform and evidence-backed testing.
HIPAA/HITRUST-Aligned Healthcare Security Engineering Platform Case Study Repository Implements AWS-first segmentation, least privilege, logging, controlled validation, remediation, and teardown for a synthetic healthcare workload.

GCP

Under Process

Project Case Study GitHub Repo What It Does
Confidential Multi-Party Data Collaboration Platform on Google Cloud — — Current active project — in progress.

Azure

Project Case Study GitHub Repo What It Does
AZ-01 — Azure Workload Identity Attack & Secretless Federation Lab Case Study Repository Validates a bounded Microsoft Entra workload-identity attack path and remediates credential and authorization risk with GitHub OIDC federation and least-privilege Azure RBAC.
AZ-02 — Azure Cloud Security Architecture Review & Controlled Remediation Lab Case Study Repository Assesses Azure governance, identity, private access, logging, and workload controls through controlled remediation, revalidation, and residual-risk review.

AI / Security Automation

Project Case Study GitHub Repo What It Does
AI-Powered Polycloud Security Incident Response Platform Case Study Repository Builds an AWS-first event-driven incident-response architecture; Terraform implementation is in progress and Amazon Bedrock integration and attack simulation remain planned.

Currently Learning

  • AWS advanced networking architecture: hybrid connectivity, Transit Gateway, Route 53, Direct Connect, VPN, VPC design, routing, network security, and troubleshooting
  • Advanced AWS Organizations, IAM, SCP, Zero Trust, and policy-as-code patterns
  • Microsoft Azure security engineering: Entra workload identities, OIDC federation, Azure RBAC, Terraform, and identity attack-path validation
  • AI-assisted cloud security incident triage and response automation
  • PMP domains: people, process, business environment, delivery, risk, stakeholder management, and agile/hybrid practices

Certifications in Progress

  • AWS Certified Advanced Networking – Specialty
  • Project Management Professional (PMP)

Cloud Security Capability Stack

Capability areas reflected in the engineering work and learning focus above.

Cloud security capability stack: cloud platforms, identity and network security, DevSecOps and IaC, detection, governance, and security automation; AI-assisted triage is a learning focus.

Text summary: AWS / Azure / GCP · Identity, Zero Trust, and network security · Terraform and policy as code · Logging and investigation · Governance and framework alignment · Security automation (AI-assisted triage: learning).

Engineering Approach

Engineering Approach — evidence-driven cloud security engineering workflow covering design, Infrastructure as Code, deployment, validation, controlled failure, investigation, remediation, revalidation, evidence capture, and cleanup.

Credentials & Training

Credentials and Training — certifications, professional credentials, professional certificates, and continuous technical training.

View supporting certification, certificate, and training records in the portfolio

Security Labs & Writing

Friday Security Projects is a seven-part hands-on security engineering series. The writing hub centralizes public work across Hashnode, Medium, DEV, and LinkedIn.

Connect

Portfolio · LinkedIn · GitHub

Pinned Loading

  1. hipaa-hitrust-healthcare-security-project hipaa-hitrust-healthcare-security-project Public

    Multi-cloud healthcare security engineering lab aligned with HIPAA Security Rule and HITRUST CSF objectives, using synthetic ePHI, AWS, GCP, Terraform, and evidence-driven security validation.

    HCL

  2. multicloud-waf-platform multicloud-waf-platform Public

    Enterprise Multi-Cloud Web Application Firewall Evaluation Platform built with Terraform, AWS WAF, and Google Cloud Armor.

    HCL

  3. AI-Powered-Polycloud-Security-Incident-Response-Platform AI-Powered-Polycloud-Security-Incident-Response-Platform Public

    Terraform-first cloud security platform exploring AI-assisted incident triage and response with event-driven AWS architecture and human-in-the-loop controls.

    HCL

  4. AZ-01-azure-workload-identity-security-lab AZ-01-azure-workload-identity-security-lab Public

    Azure security lab demonstrating workload identity attack paths, overprivileged RBAC, credential-risk validation, and remediation using Microsoft Entra workload identity federation, GitHub OIDC, le…

    PowerShell