Cloud Security Engineering | Security Architecture | DevSecOps
Cloud security engineer with 10+ years in cybersecurity, focused on security architecture, Infrastructure as Code, identity, governance, detection, incident response, and security automation across AWS, Microsoft Azure, and Google Cloud.
Portfolio | LinkedIn | Engineering Writing
- Cloud security architecture across AWS, Microsoft Azure, and Google Cloud
- Terraform, Infrastructure as Code, and Git workflows
- IAM, Microsoft Entra ID, workload identity federation, permission boundaries, SCPs, Azure RBAC, and Zero Trust
- Multi-account / multi-cloud governance, CloudTrail, GuardDuty, EventBridge, and Azure identity controls
- Detection and incident response engineering
- AWS WAF, Google Cloud Armor, Azure security controls, and network security
- DevSecOps, security automation, controlled validation, remediation, revalidation, and engineering evidence
- Framework-aware engineering context: NIST, ISO 27001, HIPAA/HITRUST-aligned engineering, PCI DSS, and SOC 2. These references describe engineering context, not organizational compliance, certification, or attestation.
| Project | Focus | Status | Links |
|---|---|---|---|
| Enterprise Multi-Cloud WAF Evaluation Platform | Terraform-led comparison of AWS WAF and Google Cloud Armor with repeatable deployment, validation, evidence capture, and lifecycle documentation. | Completed / Validated | Repository · Case Study |
| AZ-01 — Azure Workload Identity Attack & Secretless Federation Lab | Controlled Azure identity-security lab covering Microsoft Entra workload credential risk, bounded Azure RBAC attack validation, GitHub OIDC federation, least-privilege remediation, revalidation, teardown verification, and DevSecOps hardening. | Completed / Validated | Repository |
| Project | Focus | Status | Links |
|---|---|---|---|
| AI-Powered Polycloud Security Incident Response Platform | AWS-first, event-driven incident-response architecture moving through Terraform implementation. Amazon Bedrock integration and attack simulation remain planned. | In Progress | Repository · Case Study |
| AWS Multi-Account Zero-Trust Architecture Lab | AWS Organizations, SCPs, IAM boundaries, audit logging, GuardDuty, isolation, policy-as-code, and control validation. | Active Engineering | Repository · Case Study |
| HIPAA/HITRUST-Aligned Healthcare Security Engineering Platform | Terraform-led security engineering for a synthetic healthcare workload with segmentation, least privilege, logging, controlled failure testing, remediation, revalidation, and teardown evidence. | In Progress | Repository · Case Study |
| AZ-02 — Azure Cloud Security Architecture Review & Controlled Remediation Lab | Azure cloud security architecture review and controlled remediation project in the AZ-series. Implementation evidence and repository linkage will be added as the project baseline is published. | In Progress | Repository pending |
- AWS advanced networking architecture: hybrid connectivity, Transit Gateway, Route 53, Direct Connect, VPN, VPC design, routing, network security, and troubleshooting
- Advanced AWS Organizations, IAM, SCP, Zero Trust, and policy-as-code patterns
- Microsoft Azure security engineering: Entra workload identities, OIDC federation, Azure RBAC, Terraform, and identity attack-path validation
- AI-assisted cloud security incident triage and response automation
- PMP domains: people, process, business environment, delivery, risk, stakeholder management, and agile/hybrid practices
- AWS Certified Advanced Networking – Specialty
- Project Management Professional (PMP)
AWS · Microsoft Azure · Google Cloud
Terraform · Infrastructure as Code · Git workflows · GitHub Actions
AWS IAM · Microsoft Entra ID · Azure RBAC · GitHub OIDC · Workload Identity Federation · Permission Boundaries · SCPs · Zero Trust
CloudTrail · GuardDuty · EventBridge · Investigation
AWS WAF · Google Cloud Armor · Network Security
Multi-account architecture · Multi-cloud security · Governance controls · NIST · ISO 27001 · HIPAA/HITRUST-aligned engineering · PCI DSS · SOC 2
DevSecOps · Security Automation · Controlled Validation · Remediation · Revalidation · Evidence and Documentation
Design → Infrastructure as Code → Deploy → Validate → Controlled failure where applicable → Investigate → Remediate → Revalidate → Capture evidence → Cleanup / destroy. This workflow keeps implementation state, validation, limitations, and evidence reviewable.
- ISO 27001 Lead Auditor
- AWS Certified Solutions Architect – Associate
- Google Cloud Professional Cloud Architect
- Palo Alto Networks Certified Network Security Engineer (PCNSE)
- EC-Council Certified Ethical Hacker (CEH)
- CSPM-AWS
- GenAI Cybersecurity: OWASP & MITRE ATLAS
- AWS Well-Architected Foundations training
See the portfolio credential record for supporting certification and training information.
Friday Security Projects is a seven-part hands-on security engineering series. The writing hub centralizes public work across Hashnode, Medium, DEV, and LinkedIn.

