Cloud Security Engineer
Current- Automated application delivery with AWS CodePipeline: Designed and built CI/CD pipelines using AWS CodePipeline to streamline application builds and deployments.- Infrastructure as code with Terraform: Leveraged Terraform for IaC to automate provisioning and manage AWS resources consistently and for scalability.- Optimized and maintained the AWS Landing Zone foundation: Ensured a stable and reliable foundation for workloads across multiple AWS accounts by maintaining and optimizing the Landing Zone.- Enforced governance with AWS Control Tower: Utilized AWS Control Tower to implement organizational policies and best practices throughout the AWS environment.- Proactive security monitoring with AWS Security Hub and GuardDuty: Actively monitored findings from AWS security services to identify and address security threats and vulnerabilities.- Enforced security and compliance with SCPs: Created and managed Service Control Policies (SCPs) to guarantee security, compliance, and access control across AWS accounts and organizational units.- Implemented least privilege access control with IAM: Developed and maintained IAM and IAM Identity Center policies and roles for user authentication and authorization, adhering to the principle of least privilege.- Automated security controls with Cloud Custodian: Reduced operational burden by implementing GuardRails using Cloud Custodian to automate policy enforcement and security controls.