I'm a multi-cloud Engineer skilled in both AWS and Azure, supporting cloud infrastructure in regulated environments. My background spans network engineering, cloud security, GRC, and infrastructure automation -- with a current focus on building secure, compliant infrastructure using OpenTofu/Terraform, Python/boto3, and GitHub Actions CI/CD pipelines.
I bring a strong compliance foundation to everything I build. My background in RMF authorization, NIST 800-53, and FedRAMP shapes how I approach infrastructure as code -- security controls aren't an afterthought, they're baked into the pipeline from day one. I hold a CISSP alongside AWS and Azure certifications, and I'm currently pursuing AWS Security Specialty Certification.
I'm also passionate about giving back -- I mentor aspiring security professionals through the WiCyS Professional Mentorship Program, helping others navigate their path into cloud and cybersecurity.
Interactive security checklist covering 16 domains and 140+ controls aligned to NIST 800-53 and CIS AWS Foundations Benchmark. Built as a free community tool.
Terraform + Checkov pipeline with GitHub Actions that enforces NIST 800-53 controls as code. Built for a GRC Engineering Club live session with a Python findings parser and security gate logic.
Python/boto3 tool that audits EC2 inventory and S3 bucket configurations for common security misconfigurations and generates a structured findings report.
GitHub Actions pipeline that integrates Trivy container image scanning into the CI/CD workflow, blocking deployments on Critical or High CVEs with structured findings output.
Serverless auto-remediation system using AWS Config rules, EventBridge, and Lambda to detect and automatically fix common compliance violations in near real time.
Certified Information Systems Security Professional
GIAC Defensible Security Architecture
AWS Solutions Architect Associate
Microsoft Certified: Azure Administrator Associate
Microsoft Certified: Azure Network Engineer Associate
Cisco Certified Network Associate
CompTIA Security+
CompTIA Cybersecurity Analyst
Certified Ethical Hacker
eLearnSecurity Junior Penetration Tester
I'm always interested in connecting with fellow cloud and security professionals, discussing new projects, or exploring opportunities in cloud security engineering and DevSecOps.