
01 / ASSESSMENT
AWS Cloud Security Assessments
Assess AWS architectures against security standards and best practices, identify risks, and deliver a prioritized improvement roadmap.
Let’s talk ↗
ABOUT
I’m a Cloud Security Engineer with over four years of experience securing AWS and GCP infrastructure across banking e-commerce platforms, energy, and pharmaceutical environments.
I design preventive and detective security controls for multi-account cloud environments: identity and privileged access management, Kubernetes security, AWS WAF, and network protection. I connect CloudTrail, EventBridge, Security Hub, and GuardDuty with custom Python solutions to automate detection and remediation.
My work also includes securing AI agents built with Amazon Bedrock AgentCore and designing AWS organizational foundations with Terraform. Other projects include a Temporary Elevated Access Management (TEAM) mechanism for AWS and an open-source SIEM implementation. As a security consultant, I assess cloud architectures against security standards and recommend concrete improvements.
Outside of work, I explore offensive security, practice web application penetration testing in labs, and write about solutions I’ve implemented throughout my career. I’m naturally curious: understanding how things work is what keeps me learning.
SERVICES
I help teams assess, design, and improve secure cloud environments through practical engineering and automation.

01 / ASSESSMENT
Assess AWS architectures against security standards and best practices, identify risks, and deliver a prioritized improvement roadmap.

02 / ARCHITECTURE
Design secure AWS organizations with Organizations, OUs, IAM Identity Center, guardrails, centralized logging, Terraform, and emergency access.

03 / AUTOMATION
Build cloud detection and response workflows and connect security signals to your existing SOC or SIEM.

04 / AI SECURITY
Secure agentic workloads with Bedrock AgentCore, guardrails, IAM, encryption, network controls, event logging, and controlled red team assessments.

05 / EFFICIENCY
Review cloud security, logging, and infrastructure costs to identify savings opportunities while preserving the required security coverage.
NOV 2025 — PRESENT
Netrix Global · Remote
I work on production cloud security projects across industries, from AI agent infrastructure to AWS organizational foundations and cross-cloud connectivity.
AI agent security. Secured infrastructure for an energy-sector organization’s agent built with Amazon Bedrock AgentCore, implementing encryption, network security controls, event logging, and AWS-provided guardrails.
AWS foundations. Co-designed and implemented an AWS organization using Terraform for a US-based cell engineering technology company, following the AWS Well-Architected Framework and client requirements. The foundation includes organizational units, IAM Identity Center, security guardrails, and centralized logging. I also designed and implemented a custom break-glass access mechanism.
SOC visibility. Built a serverless integration with Lambda and S3 Event Notifications to normalize WAF logs into CloudWatch format and feed an existing Kinesis Data Streams pipeline to Splunk, closing a security visibility gap for the SOC.
Cross-cloud networking. Configured the AWS side of a production site-to-site VPN connecting an AWS VPC with an Azure VNet for private connectivity.
JAN 2024 — OCT 2025
Aper · Remote
I designed Kubernetes policies with OPA and Gatekeeper aligned with the OWASP Kubernetes Top 10, and managed application and network protection with AWS WAF, Firewall Manager, and GCP security tools.
I automated detection and remediation with Lambda, CloudWatch, CloudTrail, and EventBridge, deployed infrastructure with Terraform, and supported secure, highly available e-commerce architectures aligned with NIST, CIS, and PCI requirements.
Alongside security engineering, I led AWS cost optimization initiatives that delivered recurring savings of up to 90% in targeted monthly costs and over $10,000 annually.
SEP 2022 — JAN 2024
Aper · Remote
I managed users, roles, and permissions across AWS, GCP, GitLab, and Google Workspace, applying least-privilege access across the platforms.
I also analyzed and resolved CrowdStrike Falcon security alerts. This role built my foundation in day-to-day security operations, identity management, and incident investigation.
SHARED RESOURCES
I write technical articles about solutions I’ve built and lessons from my work in cloud security. Here you’ll find articles I’ve written, open-source tools I develop, and talks where I share my experience with the community.
A CLI I built to analyze WAF logs in S3 with Athena and generate shareable HTML reports. Evaluate Count rules before enforcement and investigate blocked traffic across resources.
Using AWS Security Agent with custom security requirements to catch vulnerabilities in pull requests.
Centralizing AWS WAF logs with Firehose, Lambda, and S3 across AWS accounts.
I took the red team role in a live AI agent security event, demonstrating the offensive perspective on attacking and defending agents in a controlled environment.
GET IN TOUCH
Have a project, a question, or an idea to exchange?
I’d be happy to hear from you.