Cloud Security Engineer
I'm a Cloud Security Engineer with a focus on secure cloud design, automated threat detection, and compliance-driven architecture across AWS and Azure environments. I combine DevSecOps practices with Zero Trust principles to build cloud infrastructure that's secure by design, not secured after the fact.
Every architecture I design follows one core rule: security must be built into the pipeline, not layered on top of it. From Terraform-provisioned infrastructure to event-driven threat detection, my work blends engineering precision with operational discipline. I'm fluent in automation, observability, and compliance engineering aligning cloud architecture with NIST 800-53, ISO 27001, and GDPR as a standard part of how I build, not an afterthought.
Multi-cloud resource visibility dashboard surfacing live service inventory, cost, and region data across AWS, Azure, and GCP from a single interface. Built with FastAPI, Boto3, and Docker. Currently used internally by a cybersecurity consultancy.
Event-driven security monitoring platform built entirely with Infrastructure as Code. Detects IAM policy drift and security group changes via CloudTrail in near real time, scores severity with context-aware logic, and alerts by email within seconds. Backed by an 82-test suite.
Production Flask REST API owned end-to-end, containerized with Docker, with a GitHub Actions pipeline that tests and builds on every push. Deploys simultaneously to AWS App Runner and Azure Container Apps, with structured logging and Azure Log Analytics observability.
Load-balanced, auto-scaling three-tier web infrastructure provisioned with Terraform IaC, with VPC networking, Application Load Balancer, and multi-AZ RDS deployment for high availability.
Machine learning framework analyzing CloudTrail and VPC Flow Log data for security threat classification. Covers data ingestion, preprocessing, model training, evaluation, and deployment using AWS-native services. An exploratory project applying ML techniques to cloud security monitoring.
Automated CIS benchmark compliance checks across AWS accounts using Python and AWS Config. Built on the automated compliance work I contributed to at Neo Cloud Technologies, where similar automation cut manual audit preparation by roughly 6 hours per week.
Interactive demonstrations of cloud security concepts and attack simulations
Test cloud IAM policies against sample API actions to understand access control patterns and least privilege principles.
Simulate common cloud attack patterns and see how security controls can prevent them.
Explore how Zero Trust principles apply to cloud environments with this interactive demo.
Authenticate and authorize every request based on all available data points
Grant just-in-time and just-enough-access with risk-based adaptive policies
Minimize blast radius and segment access to prevent lateral movement
Real-time analysis of all network traffic and access patterns
Divide networks into secure zones with individual access controls
Implement AI-driven threat detection and automated remediation
Consistent security policies across all environments and devices
Data encryption in transit and at rest by default
Visualize security groups and network ACLs in a cloud environment.
Click on an instance to view its security group rules
Have a project in mind or want to discuss cloud security?
Reach out through the form or directly via email.