- Lead the design and implementation of secure AWS network architectures for multiple clients, ensuring compliance with industry standards and best practices.
- Collaborate with DevOps and development teams to integrate security into CI/CD pipelines using Infrastructure as Code (IaC) tools such as Terraform and CloudFormation.
- Conduct regular security assessments and vulnerability scans to identify and remediate potential security risks. - Implement and configure AWS security services such as VPC, Security Groups, Network ACLs, AWS WAF, and AWS Firewall Manager to safeguard environments against cyber threats.
- Manage and maintain AWS Identity and Access Management (IAM) policies, roles, and permissions to enforce the principle of least privilege.
- Monitor network traffic and logs using AWS CloudWatch, AWS Config, and third-party SIEM tools to detect and respond to security incidents in real-time.
- Collaborate with compliance teams to ensure adherence to regulatory requirements such as GDPR, HIPAA, and PCI-DSS.
- Provide mentorship and training to junior engineers on AWS security best practices and emerging technologies.
- Designed and implemented a highly available and secure AWS network infrastructure for a global e-commerce platform, resulting in a 30% reduction in security incidents.
- Conducted regular security audits and penetration testing to identify vulnerabilities and recommend corrective actions to ensure continuous security improvements.
- Implemented AWS Transit Gateway to streamline inter-VPC communication and reduce operational complexity.
- Collaborated with external auditors during compliance audits and provided documentation to demonstrate security controls and processes.
- Worked closely with development teams to implement Web Application Firewall (WAF) rules and security groups to mitigate application layer attacks.
- Assisted in incident response efforts by analyzing network traffic patterns and logs to identify the root cause of security incidents.
- Cloud Security: AWS security services (VPC, Security Groups, IAM, WAF, Firewall Manager), network monitoring, intrusion detection/prevention
- Infrastructure as Code (IaC): Terraform, CloudFormation
- Networking: Routing and switching, VPN, IPsec, SSL/TLS, DNS, Load Balancing
- Compliance: GDPR, HIPAA, PCI-DSS, NIST, ISO 27001
- Tools: AWS CloudWatch, AWS Config, SIEM tools (Splunk, ELK), Wireshark
Certifications: - AWS Certified Security - Specialty - AWS Certified Solutions Architect - Associate - Certified Information Systems Security Professional (CISSP)