Cloud Security Engineer | AWS | Azure | Wiz | Terraform | Python
Cloud security automation built for fast, controlled response.
I build CSPM workflows, remediation playbooks, infrastructure guardrails, and audit-ready automation that help security teams prioritize real cloud risk and respond with confidence.
Profile
Cloud security engineer focused on automation, evidence, and safe remediation.
I build practical cloud security workflows across AWS, Azure, Wiz, Terraform, Python, and SQL. My work focuses on turning security findings into repeatable operational processes: enrich the context, route to the right owner, validate remediation safety, and leave a clean audit trail.
This portfolio is designed to show how I think as an engineer: not just identifying cloud risk, but building systems that help teams respond faster while keeping control over production change.
Featured Work
Wiz Security Automation Portfolio
These case studies show how I think through cloud findings, workflow design, remediation safety, evidence capture, and production operations.
Wiz Auto Remediation Architecture
A cross-account remediation workflow where Wiz controls trigger automation rules, events flow through SNS and SQS, Lambda validates eligibility, assumes a scoped customer-account role, applies the approved fix, and records audit evidence.
Wiz Alert Notification Playbooks
Python-based alert workflows for validating Wiz payloads, enriching context, routing issues, and sending clear messages to responsible teams.
RemediationAuto Remediation Playbooks
Guardrailed automation for cloud misconfigurations, risky security group patterns, and policy-driven response actions.
AzureAzure NSG Exposure Remediation
Detection and remediation logic for overly permissive Azure NSG rules using source, port, priority, and rule intent checks.
EvidenceAudit Logging and Metrics
SQL-based audit trails for automation activity, remediation status, exceptions, failures, and leadership-ready operational metrics.
IaCTerraform Security Infrastructure
Secure static portfolio infrastructure using private S3, CloudFront, encryption, versioning, tagging, and repeatable Terraform deployment.
APIWiz API and GraphQL Automation
API-driven workflows for querying Wiz issues, mapping controls, updating automation logic, and supporting scalable security operations.
Architecture
Designed for repeatable security operations
The automation pattern starts with a Wiz issue or cloud event, routes it through a message layer, validates context in Python, then either notifies the owner or executes a pre-approved remediation with full audit logging.
Operating Model
Professional security automation habits
Core Skills
Cloud Security Engineering Stack
Contact
Let’s connect
I am open to cloud security engineering, DevSecOps, and security automation conversations. The fastest way to reach me is email.