Senior Cloud Engineer focused on AWS multi-account governance and compliance-as-code: FedRAMP (Rev5 and 20x) and NIST 800-53 controls implemented as code on AWS, in both commercial regions and GovCloud.
I build multi-account guardrails, audit evidence pipelines, and remediation workflows that run on short-lived credentials only (OIDC and IAM Identity Center, zero long-lived keys).
Every repo below has automated tests (terraform test, pytest), is scanned in CI with Checkov, Trivy, and Gitleaks, and documents its coverage gaps. Where noted, it links to proof from a live deployment.
- fedramp-terraform-library: NIST 800-53 Rev5 and FedRAMP 20x controls as Terraform modules, with plan-time tests that check the rendered IAM and bucket policies. Thirteen modules deployed and probed in a real organization, including live connections to the database, the container registry and the web ACL.
- aws-remediation-orchestrator: Security Hub findings routed through policy, blast-radius limits and a human approval gate. All six playbooks run against a real AWS organization, and one finding followed from detection to exported evidence, including an approval whose delivery failed and was recovered.
- aws-sso-broker: short-lived IAM Identity Center credentials across many accounts, with no long-lived access keys. Tested against a real Identity Center instance.
flowchart LR
subgraph prevent["Prevent"]
org["aws-org-guardrails<br/>org SCPs, permissions boundary,<br/>Bedrock and SageMaker guardrails"]
lib["fedramp-terraform-library<br/>account baselines and auditors"]
end
subgraph access["Access"]
sso["aws-sso-broker<br/>short-lived Identity Center credentials"]
end
subgraph detect["Detect"]
prowler["prowler-aws-template<br/>org-wide CSPM scans"]
sh["Security Hub findings"]
end
subgraph respond["Respond"]
rem["aws-remediation-orchestrator<br/>governed auto-remediation"]
end
subgraph prove["Prove"]
grc["grc-evidence-automation<br/>tamper-evident control evidence"]
end
prevent --> detect --> respond
sh --> rem
prevent --> prove
respond --> prove
- aws-org-guardrails: SCPs, a permissions boundary and Identity Center permission sets for AWS Organizations, tested as policy behavior against the JSON Terraform renders, plus Bedrock and SageMaker guardrails: SCPs, agent IAM audits, invocation-logging enforcement and cost controls. SCPs, the boundary and a permission set probed with 62 live API calls.
- grc-evidence-automation: scheduled, tamper-evident control evidence for SOC 2, ISO 27001, NIST 800-53 and FedRAMP 20x. Deployed and verified in a live account.
- ai-agent-security-toolkit: prompt-injection fuzzer, tool-call sandbox with taint tracking, output validation and a tamper-evident audit log for LLM agents.
- prowler-aws-template: org-wide Prowler scans for under $1/month with GitHub Actions, OIDC and StackSet read-only roles. Run against a real four-account organization.
I track AWS attack techniques in active use and update these repos as new ones are reported. Each entry in the threat response log names a technique, the control added for it, and public reporting of attackers using it. The most recent:
- Exposed AI servers hijacked for mining: the open-ingress playbook already closed SSH, RDP and database ports opened to the internet. It now also closes the LiteLLM and Ollama ports, in aws-remediation-orchestrator#26. Seen in the wild: Lumen Black Lotus Labs, 2026.
Cloud: AWS (including GovCloud)
Infrastructure as code: Terraform, GitHub Actions
Languages: Python, HCL, PowerShell, Bash
Security tooling: Checkov, Trivy, Gitleaks, Prowler, Security Hub, GuardDuty, AWS Config
Frameworks: FedRAMP Rev5 and 20x, NIST 800-53 Rev5, SOC 2, ISO 27001:2022
AI assistance: I use AI coding assistants (Claude Code) for drafting and review. I design each system, and I verify it with tests and, where noted, live deployments.