I build secure infrastructure and automate security at scale. Currently focused on:
- 🛡️ Kubernetes security and policy-as-code
- 🔄 DevSecOps pipeline integration
- ☁️ Cloud security architecture (AWS)
Security Engineering roles where I can help teams build secure-by-default systems.
| Project | Description | Technologies |
|---|---|---|
| Terraform AWS Security Hardening | IaC security audit with automated Checkov, tfsec & OPA pipeline — controls mapped to CIS AWS Benchmark | Terraform, Checkov, tfsec, OPA, GitHub Actions |
| Kubernetes Security Portfolio | RBAC, Pod Security Standards & network policies on a 3-node cluster — reduced CIS K8s non-compliance from 38% to 6% | Kubernetes, OPA, Falco, CIS Benchmarks |
| DevSecOps Pipeline | Automated container security scanning integrated into CI/CD | GitHub Actions, Docker, Trivy |
| Healthcare Threat Model | STRIDE-based threat model for a fictional EHR system — 12 high-severity threats mapped to NIST SP 800-53 | STRIDE, NIST SP 800-53, Threat Modelling |
- HashiCorp Terraform Associate 003 (2025)
- AWS Certified Cloud Practitioner (2025)
- GitHub Actions (2025)
- Google Cybersecurity Professional Certificate — Google (2024)
- SailPoint Certified IdentityNow Associate (2024)
- BCS Information Security Management Principles (2024)
- Hands-On Essentials: Data Warehousing Workshop — Snowflake (2026)
Open to security engineering opportunities. Let's build something secure together!

