Field notes from enterprise security engineering
Writing on identity governance, cloud security, AWS, platform security, DevSecOps, AIOps and enterprise security operating models.
Designing Identity Governance That Auditors Actually Trust
How to model entitlements, certification campaigns, and JML lifecycle so evidence is a by-product of operations rather than a quarterly scramble.
Coming soon
Least Privilege in Multi-Account AWS Without Blocking Delivery
A practical path from broad IAM roles to scoped, reviewable permission boundaries using automation instead of ticket queues.
Coming soon
Cloud Guardrails as Code: Terraform Patterns That Hold Up
Module structure, policy-as-code checks, and drift handling for organisations that add accounts faster than they add engineers.
Coming soon
Platform Trust: Secure Boot, TPM, and Why It Still Matters
The chain of trust from firmware to OS, what breaks in the field, and how validation coverage should be structured.
Coming soon
Security Gates That Engineers Do Not Route Around
Calibrating SAST, DAST, SCA, and container scanning thresholds so pipelines stay fast and findings stay actionable.
Coming soon
AI-assisted Root Cause Analysis for CloudSecOps
Correlating cloud, platform, and security telemetry into incident narratives, and where AI assistance genuinely reduces MTTR.
Coming soon
Building an Enterprise Security Operating Model
Aligning identity, cloud, platform, and pipeline security into one accountable model with metrics leadership can read.
Coming soon