Summary
Highly analytical and results-driven Cloud Security Engineer with 6 years of experience specializing in AWS and Azure environments. Proven ability to design, implement, and manage robust security solutions, enhancing cloud infrastructure resilience and ensuring compliance with industry standards. Expert in IAM, network security, data protection, and automating security processes to minimize risk and optimize operational efficiency.
Experience
Senior Cloud Security EngineerAmazon Web Services (AWS)
- Architected and implemented security controls for AWS serverless applications, reducing potential vulnerabilities by 35% across 5 critical services.
- Developed and maintained CI/CD security pipelines using Terraform and GitHub Actions, automating security checks for over 100 microservices.
- Led incident response for major cloud security events, minimizing downtime by 25% and ensuring rapid recovery and post-incident analysis.
Cloud Security EngineerExpedia Group
- Implemented endpoint detection and response (EDR) solutions across 2,000+ cloud instances, enhancing threat visibility by 40%.
- Developed Python scripts to automate security compliance checks against SOC 2 and PCI DSS standards, reducing manual audit efforts by 30 hours per month.
- Administered Azure Security Center and AWS Security Hub, aggregating security alerts and reducing critical alert response time by 15%.
- Configured and managed WAF rules and DDoS protection for public-facing applications, mitigating over 50 malicious attacks per week.
Projects
Automated Cloud Security Scanner
- Developed a Python-based tool leveraging AWS Lambda and Boto3 to automatically scan S3 buckets and EC2 instances for common misconfigurations.
- Integrated with Slack to push real-time alerts for identified vulnerabilities, reducing detection time by 70% compared to manual checks.
IAM Policy Generator
- Created a command-line tool in Python that generates least-privilege AWS IAM policies based on service access patterns.
- Improved security posture by providing developers with compliant and minimal privilege policies, reducing over-provisioned permissions by 45%.
Serverless Security Logging Pipeline
- Designed and implemented a cost-effective serverless architecture using AWS Kinesis, Lambda, and S3 for centralized security log collection and processing.
- Enabled real-time streaming of security events to a Splunk SIEM, enhancing anomaly detection capabilities and reducing log analysis latency by 60%.
Education
University of WashingtonM.S. in Cybersecurity
- Specialized in Cloud Security Architecture and Incident Response.
- Graduated with a 3.8/4.0 GPA, focusing on securing distributed systems.
University of California, BerkeleyB.S. in Computer Science
- Concentrated in System Security and Networking.
- Awarded Dean's List for 4 semesters for academic excellence.
Skills
Cloud Platforms
AWSAzureGCPKubernetesDockerServerless Functions
Security Tools
SplunkDatadogQualysTenable.ioCrowdStrike FalconPalo Alto Networks
IAM & Compliance
AWS IAMAzure ADOktaOAuth 2.0SAMLSOC 2ISO 27001GDPR
DevSecOps & Automation
TerraformCloudFormationAnsiblePythonPowerShellBashCI/CDGit
Network Security
VPCSecurity GroupsWAFIDS/IPSVPNFirewalls
