Cloud Security Engineer focused on securing modern AWS and AI workloads.
I build, deploy, troubleshoot, and secure cloud applications using AWS, Terraform, Docker, ECS/Fargate, IAM, WAF, FastAPI, RAG security, telemetry, and audit logging.
Built From Scratch
- ✓ AWS Security Lab
- ✓ Public Cloud Application
- ✓ Secure AI Platform
- ✓ Containerized Deployment
- ✓ Live AWS Demo
What I Have Built
Three hands-on projects showing AWS security, public cloud application deployment, infrastructure as code, container deployment, and AI security controls.
AWS Security Lab
Project 1Built a security lab focused on IAM least privilege, audit logging, monitoring, encryption reasoning, and investigation workflows.
- IAM persona-based access
- CloudTrail and CloudWatch logging
- S3 log destinations and KMS encryption
- Athena and Glue analytics workflow
- Permission troubleshooting and remediation
AskHeyStupid Public App
Project 2Built a public AWS application with edge delivery, WAF protection, serverless API integration, Bedrock inference, and production troubleshooting.
- CloudFront and S3 static website delivery
- AWS WAF edge protections
- API Gateway and Lambda backend
- Amazon Bedrock model integration
- Live route debugging and CloudFront invalidation
- Converted the architecture into Terraform modules for repeatable infrastructure deployment
Secure AI Platform
Project 3Built and deployed a containerized AI security platform with FastAPI, RAG, prompt injection detection, API authentication, rate limiting, telemetry, and audit logs.
- Docker image build and deployment
- Terraform infrastructure deployment and configuration management
- Amazon ECR and ECS/Fargate hosting
- Application Load Balancer public access
- Prompt injection detection and blocking
- Structured telemetry and audit logging
- Interactive SOC dashboard with live telemetry, AI guardrails, and recruiter-friendly demonstrations.
Secure AI Platform Evolution
Demonstrates the complete lifecycle of a modern workload: local development, security engineering, containerization, cloud deployment, operations, troubleshooting, and validation.
Security Controls Demonstrated
Cloud Security
- IAM least privilege design and troubleshooting
- CloudTrail and CloudWatch visibility
- AWS WAF and CloudFront edge protection
- S3 access controls and logging destinations
- KMS encryption reasoning
- Terraform infrastructure as code
Application and AI Security
- API key authentication
- Rate limiting
- Prompt injection detection
- Policy-based request blocking
- RAG context filtering
- Structured audit logs and request tracing
Continuous Security Monitoring & Compliance
Beyond building cloud workloads, I use AWS security services to monitor posture, identify misconfigurations, investigate findings, and validate security controls across live AWS environments.
Security Posture Management
- AWS Config enabled with continuous resource recording
- AWS Security Hub CSPM used for compliance posture monitoring
- Security Hub standards reviewed across AWS Foundational Security Best Practices and CIS controls
- Configuration findings reviewed for API Gateway, ALB, IAM, encryption, and networking controls
- Critical and high-severity findings triaged and remediated where appropriate
Threat Detection & Vulnerability Management
- Amazon GuardDuty enabled for AWS threat detection
- Amazon Inspector used for vulnerability assessment of ECR container images
- Security findings reviewed after deploying the Secure AI Platform to ECS/Fargate
- Container image findings connected to real Docker, ECR, and ECS deployment work
- Security Hub used as the central dashboard for prioritizing cloud risk
Operational Governance
Security engineering also requires cost awareness, monitoring, abuse prevention, and operational controls so cloud and AI workloads do not become business risks.
- ✓ AWS Budgets and billing alerts planned
- ✓ Cost Anomaly Detection planned
- ✓ Rate limiting to reduce abuse-driven cost
- ✓ CloudWatch logging and visibility
- ✓ Log retention strategy planned
- ✓ Environment-aware resource management
- ✓ Cost-aware architecture decisions
Portfolio Architecture Snapshot
This diagram separates the two live systems in the portfolio: the public AskHeyStupid application and the AWS-hosted Secure AI Platform.
Live Validation
This portfolio is designed to let a recruiter or hiring manager verify that the work exists, the systems are live, and the projects are backed by code.
Verifiable Evidence
- ✓ Public website
- ✓ Live AWS-hosted Secure AI demo
- ✓ GitHub repositories
- ✓ Containerized application deployment
- ✓ FastAPI interactive docs
- ✓ Security controls implemented in code
Why This Matters
These projects demonstrate practical experience securing AWS workloads, deploying containerized applications, implementing infrastructure as code, and building security controls for modern AI systems.