I design and automate the security controls
that keep cloud infrastructure safe — at scale.

I'm a Cloud Security Engineer focused on AWS-native security automation. Every project in this portfolio is fully deployed with Terraform, backed by unit tests that run without AWS credentials, and designed to reflect real security engineering work — not tutorial walkthroughs.

My approach: automate the response, not just the detection. When GuardDuty flags a compromised instance, a Lambda isolates it in seconds. When Macie finds PII in an S3 bucket, another Lambda quarantines the object before a human even reads the alert.

I've built layered security controls across networking (VPC, NACLs, WAFv2), identity (IAM, SCPs, permission boundaries), detection (GuardDuty, Inspector v2, Macie), and automated response (EventBridge → Lambda pipelines) — all managed as reproducible Infrastructure as Code.

I hold the AWS Solutions Architect – Associate, ISC2 Certified in Cybersecurity, and CompTIA CySA+ certifications, and I'm targeting the AWS Security Specialty next.