
Senior Infrastructure Security Engineer with 10+ years of progressive experience designing, engineering, and operationalizing enterprise-scale security solutions across cloud, network, endpoint, container, and SASE environments. Proven expertise in security architecture, automation, metrics, and regulatory compliance, with deep hands-on delivery in AWS, Azure, GCP, Kubernetes, SIEM, and security tooling. Adept at embedding security into infrastructure and product lifecycles, leading cross-functional initiatives, mentoring engineers, and translating complex security requirements into scalable, business-aligned solutions. Strong advocate for automation, AI-driven security workflows, and continuous improvement in dynamic, high-growth environments.
Cloud & Infrastructure Security: AWS, Azure, GCP, Hybrid Cloud Security Architecture, Secure Landing Zones, SCPs, GuardDuty, Azure Security Center
Endpoint & Zero Trust Security: Endpoint Protection Architecture, Conditional Access, Privileged Access Controls, Zero Trust Principles
Network, Email & SASE Security: Secure Access Service Edge (SASE), Conditional Access, Secure Email Gateways, Identity-Aware Proxies, Network Segmentation
Automation & Engineering: Python, PowerShell, Bash, Terraform, GitLab CI/CD, Azure Functions, Policy-as-Code, Security Automation & Metrics
Containers & DevSecOps: Kubernetes RBAC, Workload Identity Federation, AKS, GKE, OPA, Secure CI/CD Pipelines
Monitoring, Detection & Metrics: Azure Sentinel, Splunk, ELK Stack, CrowdStrike, EventHub, Security Dashboards, Risk & Control Metrics
Governance, Risk & Compliance: NIST 800-53, ISO 27001, SOX, GDPR, FFIEC, Security Framework Design, Audit Readiness