Aws Cybersecurity Architect
Hanover, Md, Us
· Configured baseline controls for 16+ accounts for AWS Control Tower aligning to FedRAMP Moderate. Making sure accounts met the standards and security requirements to allow automated account creation in the future allowing for continued and secure expansion in AWS.· Worked with AWS CodeCommit, Codebuild, CodePipeline, CloudFormation, SSM, and Config to configure auto-remediation for security related issues. · Created critical API alerts for SOC so they could respond in timely manner using Amazon EventBridge, CloudFormation, and CodeComit, including alerts for GuardDuty. · Developed, documented, and disseminated the first Internet ingress architecture for public workloads for Federal and Commercial workloads including AWS WAF rules, AWS Advanced Shield, RACI, and ALB/EC2 security groups and network ACL rules aligned to NIST 800-53 moderate level for a hybrid environment.· Developed and documented the ABAC strategy including tagging, integration into AWS Organizations for compliance checking, and IAM polices/roles. · Created and presented training for security teams on Amazon GuardDuty, Amazon Macie, AWS Security Hub, AWS Shield, AWS Identity & Access Management (IAM), and AWS general knowledge remotely.· Used NIST 800-53 moderate standards to review workloads, created user-stories, and explained how and why the security requirements were required and offered solutions to align.· Create, present, and review security architecture to transform on-premises solutions into secure cloud native workloads including IBM mainframe applications, data transfer, and identity solutions.· Reviewed all workloads for security best practices before they went live and provided methods to fix.· Passed Federal background check