Cloud Security Engineering | Security Architecture | DevSecOps
Cloud security engineer with 10+ years in cybersecurity, focused on security architecture, Infrastructure as Code, identity, governance, detection, incident response, and security automation across AWS and Google Cloud.
Portfolio | LinkedIn | Engineering Writing
- Cloud security architecture across AWS and Google Cloud
- Terraform, Infrastructure as Code, and Git workflows
- IAM, permission boundaries, SCPs, and Zero Trust
- Multi-account governance, CloudTrail, GuardDuty, and EventBridge
- Detection and incident response engineering
- AWS WAF, Google Cloud Armor, and network security
- DevSecOps, security automation, controlled validation, remediation, revalidation, and engineering evidence
- Framework-aware engineering context: NIST, ISO 27001, HIPAA/HITRUST-aligned engineering, PCI DSS, and SOC 2. These references describe engineering context, not organizational compliance, certification, or attestation.
| Project | Focus | Status | Links |
|---|---|---|---|
| Enterprise Multi-Cloud WAF Evaluation Platform | Terraform-led comparison of AWS WAF and Google Cloud Armor with repeatable validation. | Validated | Repository · Case Study |
| AI-Powered Polycloud Security Incident Response Platform | AWS-first, event-driven incident-response architecture moving through Terraform implementation. Amazon Bedrock integration and attack simulation are planned. | In Progress | Repository · Case Study |
| AWS Multi-Account Zero-Trust Architecture Lab | Engineering lab for Organizations, SCPs, IAM boundaries, audit logging, GuardDuty, isolation, and control validation. | Active Engineering | Repository · Case Study |
| HIPAA/HITRUST-Aligned Healthcare Security Engineering Platform | Terraform-led security engineering for a synthetic healthcare workload: segmentation, IAM, logging, controlled validation, remediation, revalidation, and teardown evidence. | In Progress | Repository · Case Study |
AWS · Google Cloud
Terraform · Infrastructure as Code · Git workflows
IAM · Permission Boundaries · SCPs · Zero Trust
CloudTrail · GuardDuty · EventBridge · Investigation
AWS WAF · Google Cloud Armor · Network Security
Multi-account architecture · Governance controls · NIST · ISO 27001 · HIPAA/HITRUST-aligned engineering · PCI DSS · SOC 2
DevSecOps · Security Automation · Controlled Validation · Remediation · Revalidation · Evidence and Documentation
Design → Infrastructure as Code → Deploy → Validate → Controlled failure where applicable → Investigate → Remediate → Revalidate → Capture evidence → Cleanup / destroy. This workflow keeps implementation state, validation, limitations, and evidence reviewable.
- ISO 27001 Lead Auditor
- AWS Certified Solutions Architect – Associate
- EC-Council Certified Ethical Hacker (CEH)
- AWS Well-Architected Proficient
See the portfolio credential record for supporting certification and training information.
Friday Security Projects is a seven-part hands-on security engineering series. The writing hub centralizes public work across Hashnode, Medium, DEV, and LinkedIn.

