I design secure, observable, and compliance-ready cloud platforms using
automation, policy-driven controls, and feedback loops. Proven delivery
across AWS environments under real production constraints.
Cloud Security Architecture
AWS Security
Kubernetes / OpenShift
Security Automation
NIST / Compliance Engineering
About
What I Do
I design secure, observable, and compliant infrastructure on AWS, then prove the impact with measurable outcomes (fewer regressions, faster recovery, lower risk). I keep it practical: CIS/OWASP for guardrails, ISO 27001 at the estate level, and SIEM to close the loop. Now pursuing Google Cloud certifications to deliver vendor-neutral SecOps across hybrid estates.
Now
Bangalore (India) : targeting India / EU remote roles. Currently focused on cloud security architecture, automated governance, and observability-driven risk reduction across AWS environments. Preparing for EU-remote Cloud Security Architect roles.
Featured Projects & Impact
EdTech Infra Turnaround
Inherited severely mismanaged infra; stabilized and rebuilt to compliance-ready state. Built ELK observability. Enabled cyber-insurance audit pass.
RBAC
CIS
ELK
Windows & Linux
Security Incident Response
Neutralized multiple crypto-mining compromises. Root-caused, cleaned, killed interdependent processes, and hardened systems without downtime spillover.
Incident Management
Threat Hunting
Automation
SIEM Platform (Wazuh + TheHive)
Designed and deployed SIEM on AWS EC2 with TheHive, integrated with QuickSight for estate analytics; ML classifier planned for correlation and YARA generation.
Wazuh
TheHive
QuickSight
AWS
Education
Media
Manufacturing
Active Certifications
Completed certifications demonstrate operational capability in cloud security, governance, and compliance frameworks.
Aligns AWS security controls with NIST CSF audits and enterprise risk reporting. NIST CSF + RMF frameworks bridge technical implementation to board-level governance.
Structured coverage of cloud security domains across identity, data protection, and incident response—vendor-neutral foundation for multi-cloud operations.
Baseline for privacy principles, anonymization, and data handling practices that make compliance frameworks technically enforceable.
Currently Building
AI-SecOps Lite - Vendor-Neutral, Production-Grade SOC Prototype
- Detection → Decision → Adaptation: Suricata + Wazuh + DuckDB + MLflow + n8n pipeline with explainable ML (IsolationForest, Prophet, SHAP) and automated SOAR feedback loops.
- Governance & Compliance: Built-in model lineage, pseudonymization, human-in-loop controls aligned with NIS2/GDPR/EU AI Act.
- Future-Ready: Reinforcement agents for adaptive playbooks, federated DuckDB for MSPs, and sandboxed simulations for risk and policy testing.