Automated AWS Cloud Security Incident Response
Designed a production-style platform that correlates GuardDuty and CloudTrail events, then triggers MITRE ATT&CK-mapped actions such as WAF blocking, IAM disabling, and EC2 isolation.
I help engineering teams find risk earlier, respond faster, and build more secure applications and cloud environments.
profile = { focus: "application + cloud security", approach: "practical, evidence-led", toolkit: ["Python", "AWS", "Burp"], status: "open to opportunities" }
Projects that combine detection, automation, secure design, and clear remediation.
Designed a production-style platform that correlates GuardDuty and CloudTrail events, then triggers MITRE ATT&CK-mapped actions such as WAF blocking, IAM disabling, and EC2 isolation.
Assessed AWS and Azure environments against NCSC Cloud Security Principles and CIS Benchmarks, identifying IAM, network, and logging gaps with prioritised remediation.
Built a prototype using the OpenAI API to classify and prioritise SIEM alerts, helping reduce manual review effort across high-volume finding sets.
Used Burp Suite and OWASP Top 10-based threat modelling to identify injection flaws, authentication weaknesses, and broken access controls, then translated findings into practical fixes.
Hands-on security work across AI safety, application security, cloud, IAM, and DevSecOps.
Evaluated 50+ LLM outputs per week for safety, security, policy compliance, harmful content, and correctness within a high-throughput model safety pipeline.
Built SIEM detection and log-correlation pipelines, conducted application and architecture reviews, created Python security automation, and delivered NIST-aligned risk reports and security awareness training.
Partnered with development teams on secure SDLC practices, managed AWS IAM governance, and integrated Python and Bash security tooling into Jenkins CI/CD pipelines.
A practical mix of engineering, cloud, detection, and risk skills.
OWASP Top 10 · Burp Suite · Threat modelling · Secure architecture · Secure SDLC
AWS IAM · GuardDuty · Security Hub · CloudTrail · WAF · Azure Defender · Entra ID · Sentinel
SIEM correlation · Incident response · MITRE ATT&CK · Playbook development · SOC workflows
Python · Bash · Jenkins · GitHub Actions · Ansible · Terraform (familiar)
NIST CSF · CIS Benchmarks · ISO 27001 controls · IAM reviews · Least privilege
CompTIA Security+ · Certified Penetration Tester · 1st place RedTeam HackerAcademy CTF
Available for cyber security engineering and application security opportunities.