Skip to content
View vjaiii's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report vjaiii

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
vjaiii/README.md

Vijay Kumar Devineni - cloud security, governance, risk and compliance

LinkedIn Medium Email

AI, Cloud and Infrastructure Security Architect - Governance, Risk and Compliance.

13 years across GCP, AWS and Azure in regulated financial services, retail, and healthcare. I build the boring parts that keep enterprises out of the news: landing zones, org policy, IAM guardrails, evidence pipelines, and the governance that makes AI workloads auditable. Most of what I publish here is reference material I wish had existed when I needed it.

Focus

Cloud GRC as code. Controls mapped to NIST 800-53, ISO 27001, SOC 2, HIPAA and PCI DSS, implemented as policy and Terraform rather than spreadsheets.

AI governance. NIST AI RMF, ISO 42001, EU AI Act readiness, and security for LLM, RAG and agent (MCP) workloads.

Secure platform foundations. GCP landing zones on Cloud Foundation Fabric, DevSecOps pipelines, Kubernetes hardening.

Architecture review boards. TRB and ARB governance, exception handling, and the tooling behind them.

Repositories

Repo What it is
cloud-grc-control-library ci 27 machine-readable controls mapped across NIST, ISO, SOC 2, HIPAA, PCI and CIS, with OPA policies, Terraform gates and evidence collectors for GCP, AWS and Azure
terraform-cloud-security-blueprints Reference Terraform for secure cloud foundations across GCP, AWS and Azure
devsecops-security-pipeline-patterns CI/CD reference patterns with SAST, secrets, IaC and container scanning and policy gates
cloud-incident-response-playbooks Runbooks for cloud, IAM, Kubernetes and data exposure incidents
genai-cloud-security-patterns Security patterns for GenAI and LLM workloads across the three clouds
kubernetes-security-hardening-guide Workload protection, access control and runtime hardening for Kubernetes

Next up: an AI governance toolkit - intake, risk tiering and agent security review mapped to NIST AI RMF and ISO 42001.

Writing

Short-form on LinkedIn, long-form on Medium.

Pinned Loading

  1. genai-cloud-security-patterns genai-cloud-security-patterns Public

    Practical security patterns for GenAI, LLM, and AI workloads across GCP, AWS, and Azure.

  2. terraform-cloud-security-blueprints terraform-cloud-security-blueprints Public

    Reference Terraform patterns for building secure cloud foundations across GCP, AWS, and Azure.

  3. devsecops-security-pipeline-patterns devsecops-security-pipeline-patterns Public

    Secure CI/CD reference patterns with SAST, secrets scanning, IaC checks, container scanning, and policy gates.

  4. kubernetes-security-hardening-guide kubernetes-security-hardening-guide Public

    Practical Kubernetes security guidance for workload protection, access control, and runtime hardening.

  5. cloud-incident-response-playbooks cloud-incident-response-playbooks Public

    Practical incident response playbooks for cloud, IAM, Kubernetes, and data exposure scenarios.

  6. cloud-grc-control-library cloud-grc-control-library Public

    Machine-readable cloud security controls mapped across NIST 800-53, ISO 27001, SOC 2, HIPAA and PCI DSS, with OPA enforcement, Terraform gates and evidence collection for GCP, AWS and Azure.

    Python