AWS Security • Security Hub CSPM • AWS Config • Terraform • Docker • ECS/Fargate • AI Security

Cloud Security Engineer focused on securing modern AWS and AI workloads.

I build, deploy, troubleshoot, and secure cloud applications using AWS, Terraform, Docker, ECS/Fargate, IAM, WAF, FastAPI, RAG security, telemetry, and audit logging.

AWS Terraform Docker ECS/Fargate IAM CloudTrail CloudWatch Cost Governance WAF FastAPI Python RAG AI Security AWS Config Security Hub CSPM GuardDuty Inspector

Built From Scratch

  • AWS Security Lab
  • Public Cloud Application
  • Secure AI Platform
  • Containerized Deployment
  • Live AWS Demo

What I Have Built

Three hands-on projects showing AWS security, public cloud application deployment, infrastructure as code, container deployment, and AI security controls.

AWS Security Lab

Project 1

Built a security lab focused on IAM least privilege, audit logging, monitoring, encryption reasoning, and investigation workflows.

  • IAM persona-based access
  • CloudTrail and CloudWatch logging
  • S3 log destinations and KMS encryption
  • Athena and Glue analytics workflow
  • Permission troubleshooting and remediation
IAM CloudTrail CloudWatch KMS Athena Glue

AskHeyStupid Public App

Project 2

Built a public AWS application with edge delivery, WAF protection, serverless API integration, Bedrock inference, and production troubleshooting.

  • CloudFront and S3 static website delivery
  • AWS WAF edge protections
  • API Gateway and Lambda backend
  • Amazon Bedrock model integration
  • Live route debugging and CloudFront invalidation
  • Converted the architecture into Terraform modules for repeatable infrastructure deployment
CloudFront WAF API Gateway Lambda Bedrock Terraform

Secure AI Platform

Project 3

Built and deployed a containerized AI security platform with FastAPI, RAG, prompt injection detection, API authentication, rate limiting, telemetry, and audit logs.

  • Docker image build and deployment
  • Terraform infrastructure deployment and configuration management
  • Amazon ECR and ECS/Fargate hosting
  • Application Load Balancer public access
  • Prompt injection detection and blocking
  • Structured telemetry and audit logging
  • Interactive SOC dashboard with live telemetry, AI guardrails, and recruiter-friendly demonstrations.
Terraform Docker ECR ECS/Fargate ALB FastAPI RAG

Secure AI Platform Evolution

Local Development Environment | V FastAPI Application | V RAG Knowledge Platform | V Security Controls (API Auth • Rate Limiting • Prompt Injection Detection) | V Docker Containerization | V Amazon ECR | V ECS/Fargate Deployment | V Application Load Balancer | V AWS Production Deployment | V Live Recruiter Demo

Demonstrates the complete lifecycle of a modern workload: local development, security engineering, containerization, cloud deployment, operations, troubleshooting, and validation.

Security Controls Demonstrated

Cloud Security

  • IAM least privilege design and troubleshooting
  • CloudTrail and CloudWatch visibility
  • AWS WAF and CloudFront edge protection
  • S3 access controls and logging destinations
  • KMS encryption reasoning
  • Terraform infrastructure as code

Application and AI Security

  • API key authentication
  • Rate limiting
  • Prompt injection detection
  • Policy-based request blocking
  • RAG context filtering
  • Structured audit logs and request tracing

Continuous Security Monitoring & Compliance

Beyond building cloud workloads, I use AWS security services to monitor posture, identify misconfigurations, investigate findings, and validate security controls across live AWS environments.

Security Posture Management

  • AWS Config enabled with continuous resource recording
  • AWS Security Hub CSPM used for compliance posture monitoring
  • Security Hub standards reviewed across AWS Foundational Security Best Practices and CIS controls
  • Configuration findings reviewed for API Gateway, ALB, IAM, encryption, and networking controls
  • Critical and high-severity findings triaged and remediated where appropriate
AWS Config Security Hub CSPM Compliance Remediation

Threat Detection & Vulnerability Management

  • Amazon GuardDuty enabled for AWS threat detection
  • Amazon Inspector used for vulnerability assessment of ECR container images
  • Security findings reviewed after deploying the Secure AI Platform to ECS/Fargate
  • Container image findings connected to real Docker, ECR, and ECS deployment work
  • Security Hub used as the central dashboard for prioritizing cloud risk
GuardDuty Inspector ECR Scanning Container Security

Operational Governance

Security engineering also requires cost awareness, monitoring, abuse prevention, and operational controls so cloud and AI workloads do not become business risks.

  • AWS Budgets and billing alerts planned
  • Cost Anomaly Detection planned
  • Rate limiting to reduce abuse-driven cost
  • CloudWatch logging and visibility
  • Log retention strategy planned
  • Environment-aware resource management
  • Cost-aware architecture decisions

Portfolio Architecture Snapshot

This diagram separates the two live systems in the portfolio: the public AskHeyStupid application and the AWS-hosted Secure AI Platform.

AskHeyStupid Public Application Internet | +--> CloudFront + WAF | +--> S3 static website +--> API Gateway + Lambda + Bedrock Secure AI Platform Internet | +--> Application Load Balancer | +--> ECS/Fargate | +--> Docker container +--> FastAPI +--> RAG workflow +--> Security policy checks +--> Telemetry and audit logs

Live Validation

This portfolio is designed to let a recruiter or hiring manager verify that the work exists, the systems are live, and the projects are backed by code.

Verifiable Evidence

  • Public website
  • Live AWS-hosted Secure AI demo
  • GitHub repositories
  • Containerized application deployment
  • FastAPI interactive docs
  • Security controls implemented in code

Why This Matters

These projects demonstrate practical experience securing AWS workloads, deploying containerized applications, implementing infrastructure as code, and building security controls for modern AI systems.