Technical Skills

Cloud & Platform

  • AWS (EC2, EKS, VPC, IAM, S3, RDS, Lambda, CloudWatch)
  • Kubernetes & Docker
  • Helm
  • Terraform (Infrastructure as Code)
  • Ansible
  • Auto-scaling & High Availability Architecture

Pipelines & Supply Chain

  • GitHub Actions
  • GitLab CI
  • OIDC Federation (no long-lived credentials)
  • Gitleaks (secret scanning)
  • Trivy (container & dependency scanning)
  • SonarQube (static analysis)

Detection & Response

  • Graylog SIEM
  • VictoriaMetrics
  • Loki
  • Grafana & Alertmanager
  • Zabbix
  • Incident Response & Root Cause Analysis

Security & Compliance

  • IAM Hardening
  • Network Segmentation (VPC Design, Security Groups, NACLs)
  • AWS WAF
  • IPsec
  • CIS Benchmarks
  • Compliance Frameworks (ISO 27001, PCI DSS, GDPR)

Systems & Programming

  • Linux Administration
  • Nginx
  • APISIX (API Gateway, EKS ingress)
  • Python (Boto3, pandas, scikit-learn)
  • Bash Scripting

Certifications

AWS Certified Solutions Architect – Associate

Amazon Web Services

AWS Certified Cloud Practitioner

Amazon Web Services

CompTIA Security+ CE

CompTIA

Google Cybersecurity Certificate

Google

Current Focus

My current work is production payments infrastructure: keeping it available, keeping it defensible, and being able to prove both. I'm particularly focused on:

  • Reliability under real load: Running AWS and Kubernetes at 99.99% uptime against a 99.9% SLA, where every minute of downtime is a failed transaction.
  • Supply chain and pipeline security: Security gates inside the pipelines engineers already use, and no long-lived cloud credentials anywhere.
  • Detection and response: Observability and SIEM built to shorten the time between something going wrong and somebody knowing about it.
  • Where I'm heading: Securing AI systems and training pipelines. My MSc dissertation applied machine learning to security detection, and that's the direction I want to take further. Stated as interest, not expertise.