Cloud Security Engineer | Building AI Security Tools & Shipping Cybersecurity Products
I build security tools that solve real problems — from LLM security proxies to AI threat modeling to secure cloud infrastructure. Creator of Terminals and Coffee, where I ship cybersecurity guides and courses on Gumroad.
| Project | What It Does |
|---|---|
| Multi-Cloud CSPM | Enterprise security baseline for Azure + GCP — Sentinel, Defender, Firewall, NSG, SCC, Chronicle. NIST 800-53 + ISO 27001 control mappings. Terraform + OIDC CI/CD |
| Salvo CLI | Bug bounty CLI in Go — recon (subfinder/httpx), repeater (single HTTP requests), and Intruder-style fuzzer with FUZZ keyword, all in one tool |
| AWS DevOps Portfolio | Production-grade AWS projects — ECS Fargate, EKS, ArgoCD, Aurora migrations, self-healing Lambda. Terraform + GitHub Actions + Well-Architected Framework |
| Cloud Automation Projects | Multi-cloud automation scripts in Python, PowerShell, and Bash — AWS EC2/S3/IAM, Windows Server management, Linux ops |
| Security Architecture Fundamentals | Practical security architecture reference — cloud design patterns, threat modeling, risk assessment, and framework mappings (NIST, CIS, MITRE) |
| Detection Engineering Lab | Hands-on detection-as-code lab — Wazuh SIEM rules with MITRE ATT&CK mappings, Terraform-deployed infra, threat emulation coverage |
Languages: Python, Go, Bash, PowerShell, HCL
Cloud & Infra: AWS (Lambda, API Gateway, Bedrock, DynamoDB, CloudWatch), Azure (Sentinel, Defender, Firewall), GCP (SCC, Chronicle, KMS), Terraform, GitHub Actions CI/CD
Security: LLM threat modeling, prompt injection detection, PII scanning, SIEM/detection engineering, network traffic analysis, bug bounty tooling
Frameworks: FastAPI, httpx, boto3, Scapy, Cobra




