What I've built
Security-as-code, compliance tooling, and cloud infrastructure — built in public.
Azure Cloud Security WAF Lab
A cloud security lab that balances threat operations with modern infrastructure engineering. It deploys an Azure Web Application Firewall (WAF) to defend a deliberately vulnerable target (DVWA), while utilizing a DevSecOps CI/CD pipeline to automate provisioning, enforce shift-left security, and validate SIEM telemetry.
AI Policy Gate
A Policy-as-Code deployment gate that blocks non-compliant AI systems before they reach production and emits a tamper-evident audit record for every decision — evaluating each system against the EU AI Act, NIST AI RMF, ISO/IEC 42001, and GDPR, enforced at both the CI/CD and Kubernetes admission boundaries.
Entra Conditional Access Library
17 production-ready Microsoft Entra ID identity-security patterns as code - Conditional Access, tenant authorization, and PIM - mapped to MITRE ATT&CK and deployed via Terraform and Microsoft Graph.
NIS2-Compliant AWS Landing Zone
An open-source AWS Landing Zone built with Terraform, focused on deploying automated security baselines and robust cloud infrastructure controls to meet strict NIS2 & ISO 27001 Annex A regulatory compliance.