Cloud Security Engineer transitioning from automotive/embedded security into AWS cloud security — building production-style, end-to-end security architectures and documenting what's real vs. simulated in every project.
Currently focused on: IAM/IRSA, Kubernetes security (PSS, NetworkPolicies, RBAC), automated threat detection & remediation (GuardDuty → EventBridge → Lambda), and Infrastructure as Code with Terraform.
🎓 Certifications: AWS Certified Solutions Architect – Associate · AWS Certified Cloud Practitioner
🔧 Background: ~1.5 years in automotive/embedded security — WiFi pentesting on ECUs, UART fuzzing, MITM attacks, cryptographic API development in Python, Splunk/SIEM.
📌 Featured projects (see pinned repos below):
- EKS Security Pipeline — 7-layer AWS EKS security architecture: private-subnet nodes, IRSA, Pod Security Standards, Trivy CI scanning, RBAC privilege-escalation simulation, and automated GuardDuty→Lambda remediation
- Secure Web App on AWS — Defense-in-depth deployment behind WAF/ALB with real OWASP ZAP validation
- GuardDuty Auto-Remediation — Real-time threat detection with automated Lambda-based incident response
📫 Connect: LinkedIn