Specializing in AWS security automation, compliance frameworks, and building tools that make cloud environments more secure and compliant.
I'm a Governance, Risk, and Compliance (GRC) professional with expertise in AWS cloud security and automation. I build Python-based tools to automate security audits, remediation, and compliance reporting.
With certifications including ISO 27001 Lead Auditor, AWS Certified Security - Specialty, CISSP, and CRISC, I bring a comprehensive approach to cloud security and compliance.
My portfolio includes 9 production-ready AWS security automation tools that demonstrate real-world problem-solving and enterprise-level architecture skills.
AWS Security Automation & GRC Tools
Enterprise-scale Lambda function aggregating Security Hub findings across AWS accounts with Excel reporting. Processed 446+ findings.
View on GitHubServerless pipeline generating professional compliance reports from Security Hub findings with CloudFormation deployment.
View on GitHubAutomatically enables versioning on non-compliant S3 buckets with dry-run safety mode for secure operations.
View on GitHubDetects overly permissive IAM policies with full admin access patterns and generates detailed CSV reports.
View on GitHubAdvanced IAM policy analyzer detecting 5 types of least-privilege violations with severity-based findings and actionable recommendations.
View on GitHubIdentifies and removes unattached EBS volumes for cost optimization and security improvement.
View on GitHubEvent-driven security monitoring with AWS SNS email alerts for IAM policy violations.
View on GitHubAudits S3 buckets for versioning and public access compliance with detailed reporting.
View on GitHubIdentifies IAM users without MFA enabled to enforce security best practices.
View on GitHubDetects risky security group rules exposing sensitive ports to the internet.
View on GitHubLet's connect and discuss cloud security and GRC!