Skip to content
View tltaylor1's full-sized avatar

Sponsoring

@ankidroid

Highlights

  • Pro

Organizations

@manifest-identity

Block or report tltaylor1

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
tltaylor1/README.md
Terry Taylor, security engineer and architect: cloud security, identity, governance

Stylized portrait of Terry

Security engineer and architect in Seattle, working across cloud security, identity, infrastructure, and security automation.

I build the controls and systems behind security programs, not only the requirements around them. Thirteen years across enterprise and regulated environments, from infrastructure engineering and Severity-A cloud support through staff-level security architecture and program leadership. I have taken two organizations from Cybersecurity Maturity Model Certification gap assessment through successful certification.

Most of the engineering work here is part of control-plane, a security engineering program built in public. Plans are written before implementation, AI-assisted changes are gated and human-reviewed, engineering claims are tested, and mistakes become rules rather than disappearing into commit history.

If you like the program (control-plane) or the main application (manifest-identity), please give them a ⭐ and let me know!


Featured projects

Project What it does
manifest-identity Governance for AWS non-human identities: the roles, service accounts, and access keys that are easy to create and easy to forget. It derives identity state from observed history, adds ownership and explainable risk findings, and turns that evidence into governed review decisions. The software recommends; a person decides.
build-doctrine An enforceable engineering rulebook for AI-assisted software development. Every rule traces back to a real failure and names the check that prevents it from recurring. The repository can score another project, vet outside code, and scaffold new projects with the gates in place from the first commit.
control-plane The program surrounding the individual projects: plans before code, human-reviewed agent changes, blocking gates, monitoring, recovery exercises, architectural decisions, and a record of failures and what changed because of them.
secure-expense-mvp A deliberately small application that carries application security end to end: object-level authorization, bounded file handling, transactional audit records, dependency integrity, security-gated delivery, and tests proven by deliberately breaking the controls they protect.

Design and architecture

Project What it is
sample-diagrams Architecture and process diagrams showing how I communicate systems, trust boundaries, data flows, operational workflows, and cross-team handoffs.

References and study tools

Project What it is
aws-azure-security-mapping Ninety-nine AWS security concepts mapped to their closest Azure counterparts, including the cases where the two platforms have no clean equivalent.
anki-decks Seven maintained study decks, 1,262 cards across PowerShell, Python, KQL, Bicep, cybersecurity, the AWS Security Specialty, and compliance frameworks. Each deck also has a plain CSV source so changes can be reviewed in Git.

Certifications

CISSP badge
CISSP
Microsoft Certified Expert badge
Cybersecurity Architect Expert
Microsoft Certified Expert badge
Azure Solutions Architect Expert
Microsoft Certified Expert badge
Microsoft 365 Administrator Expert
Terraform Associate badge
Terraform Associate
CCNA badge
CCNA

Skills and tools

Azure Microsoft Entra ID AWS Terraform Bicep Salt Kubernetes Docker

Python PowerShell Bash FastAPI PostgreSQL Linux GitHub Actions


Areas of focus

Cloud security. Azure, AWS, Microsoft 365, secure landing zones, network segmentation, private connectivity, cloud security architecture.

Identity and zero trust. Entra ID, Conditional Access, PIM, non-human identities, workload identities, managed identities, service principals, SAML, OIDC, OAuth 2.0.

Security engineering and automation. Terraform, Bicep, Python, PowerShell, KQL, policy as code, CI/CD security gates, secure-by-design engineering.

Detection and observability. Microsoft Sentinel, Splunk, Cribl, Defender, CloudTrail, GuardDuty, log pipelines, detection engineering, threat hunting.

Governance and compliance. CMMC, NIST 800-171, NIST 800-53, FedRAMP, CIS Benchmarks, architecture reviews, control implementation, continuous monitoring.


The projects here are meant to be inspected. Design decisions, rejected alternatives, tests, controls, and failures are kept visible so the implementation can be evaluated rather than simply trusted.

Pinned Loading

  1. manifest-identity/manifest-identity manifest-identity/manifest-identity Public

    Inventory and governance for non-human identities: derived state, enrichment over automation, nothing acts on its own judgment. AWS first. Phase 1, building.

    Python 3 1

  2. build-doctrine build-doctrine Public

    Standards, enforcement, and verification procedures every project starts from.

    Python 1

  3. sample-diagrams sample-diagrams Public

    Hand-drawn architecture and process diagrams, kept as point-in-time illustrations.

    1

  4. secure-expense-mvp secure-expense-mvp Public

    A small expense submission and approval application, built security-first with each control recorded against the threat it addresses.

    Python 1

  5. tltaylor1 tltaylor1 Public

    Profile README.

    1

  6. tltaylor1.github.io tltaylor1.github.io Public

    A security engineering program, built in public: the map of its parts, the method they share, and the documents that span them.

    HTML 1