Leonard Kachi - Cloud Security Engineer

Obidiegwu Onyedikachi Henry

Cloud Security Engineer

About Me

I'm a Cloud Security Engineer with a focus on secure cloud design, automated threat detection, and compliance-driven architecture across AWS and Azure environments. I combine DevSecOps practices with Zero Trust principles to build cloud infrastructure that's secure by design, not secured after the fact.

Every architecture I design follows one core rule: security must be built into the pipeline, not layered on top of it. From Terraform-provisioned infrastructure to event-driven threat detection, my work blends engineering precision with operational discipline. I'm fluent in automation, observability, and compliance engineering aligning cloud architecture with NIST 800-53, ISO 27001, and GDPR as a standard part of how I build, not an afterthought.

What I Do

  • Design AWS security architecture using least-privilege IAM, VPC segmentation, and centralized CloudTrail/GuardDuty logging
  • Build event-driven security automation with Lambda, SNS, and Security Hub to detect and alert on configuration drift
  • Provision infrastructure as code with Terraform and CloudFormation across multi-account AWS Organizations
  • Integrate security into CI/CD pipelines using GitHub Actions and Docker
  • Apply NIST 800-53, ISO 27001, and GDPR frameworks to real compliance and audit work
  • Teach cloud computing fundamentals and AWS architecture to working professionals

Technical Toolkit

AWS (IAM, EC2, S3, Lambda, GuardDuty, CloudTrail, Security Hub, VPC, Config, Organizations) Azure Google Cloud Platform Docker Kubernetes (EKS)
Zero Trust Architecture IAM & SCPs Threat Modeling Nmap, Wireshark, OpenVAS NIST 800-53 ISO 27001 CIS Benchmarks GDPR
PythonBash/ShellJavaScriptSQLPowerShellYAML
TerraformAnsibleCloudFormationGitHub ActionsJenkinsCI/CD Security
CloudWatchPrometheusGrafanaELK Stack

Featured Projects

Cloud Resource Map

Cloud Resource Map

Multi-cloud resource visibility dashboard surfacing live service inventory, cost, and region data across AWS, Azure, and GCP from a single interface. Built with FastAPI, Boto3, and Docker. Currently used internally by a cybersecurity consultancy.

PythonFastAPIBoto3TerraformDockerAWSAzureGCP
View on GitHub
AWS Security Monitor

AWS Security Monitor

Event-driven security monitoring platform built entirely with Infrastructure as Code. Detects IAM policy drift and security group changes via CloudTrail in near real time, scores severity with context-aware logic, and alerts by email within seconds. Backed by an 82-test suite.

PythonTerraformAWS CloudTrailKMSAmazon SNSAPI GatewayAWS Lambda
View on GitHub
Flask CI/CD Dual Cloud Pipeline

Flask CI/CD Dual-Cloud Pipeline

Production Flask REST API owned end-to-end, containerized with Docker, with a GitHub Actions pipeline that tests and builds on every push. Deploys simultaneously to AWS App Runner and Azure Container Apps, with structured logging and Azure Log Analytics observability.

Python & FlaskDockerGitHub ActionsAWS App RunnerAzure Container Apps
View on GitHub
AWS Three-Tier Web Architecture

AWS Three-Tier Architecture

Load-balanced, auto-scaling three-tier web infrastructure provisioned with Terraform IaC, with VPC networking, Application Load Balancer, and multi-AZ RDS deployment for high availability.

TerraformEC2 Auto ScalingApplication Load BalancerAurora MySQLCloudWatch
View on GitHub
AI-Powered Threat Detection

AI-Powered Threat Detection

Machine learning framework analyzing CloudTrail and VPC Flow Log data for security threat classification. Covers data ingestion, preprocessing, model training, evaluation, and deployment using AWS-native services. An exploratory project applying ML techniques to cloud security monitoring.

PythonTensorFlowAWS SageMakerKinesisLambdaGuardDuty
View Writeup
Compliance Automation Framework

Compliance Automation Framework

Automated CIS benchmark compliance checks across AWS accounts using Python and AWS Config. Built on the automated compliance work I contributed to at Neo Cloud Technologies, where similar automation cut manual audit preparation by roughly 6 hours per week.

AWS ConfigPythonCIS BenchmarksServerless
View Writeup

Cloud Security Lab

Interactive demonstrations of cloud security concepts and attack simulations

IAM Policy Simulator

Test cloud IAM policies against sample API actions to understand access control patterns and least privilege principles.

IAM Policy

Test Actions

Results

Real-time Attack Simulation

Simulate common cloud attack patterns and see how security controls can prevent them.

Zero Trust Architecture

Explore how Zero Trust principles apply to cloud environments with this interactive demo.

Core Principles

🔐
Verify Explicitly

Authenticate and authorize every request based on all available data points

📉
Least Privilege

Grant just-in-time and just-enough-access with risk-based adaptive policies

🔄
Assume Breach

Minimize blast radius and segment access to prevent lateral movement

🔍
Continuous Monitoring

Real-time analysis of all network traffic and access patterns

🧩
Microsegmentation

Divide networks into secure zones with individual access controls

🤖
Automated Response

Implement AI-driven threat detection and automated remediation

📜
Policy Enforcement

Consistent security policies across all environments and devices

🔗
Encryption Everywhere

Data encryption in transit and at rest by default

Network Security

Visualize security groups and network ACLs in a cloud environment.

VPC Architecture

Public Subnet
Web Server
NAT Gateway
Private Subnet
App Server
Database

Security Group Details

Click on an instance to view its security group rules

Latest Articles

Certifications

Sort by:

Professional Resume

Resume Preview
Download PDF

Get In Touch

Contact Information

Have a project in mind or want to discuss cloud security?
Reach out through the form or directly via email.

+234 913 121 9185
GMT+1
×
💻

Desktop Experience Recommended

This project contains detailed architectural diagrams and technical documentation that are best viewed on a laptop or desktop screen.

Please switch to a larger device for the complete experience.