Knowledge Sharing

Field notes from enterprise security engineering

Writing on identity governance, cloud security, AWS, platform security, DevSecOps, AIOps and enterprise security operating models.

IAM9 min read

Designing Identity Governance That Auditors Actually Trust

How to model entitlements, certification campaigns, and JML lifecycle so evidence is a by-product of operations rather than a quarterly scramble.

Coming soon

Cloud Security11 min read

Least Privilege in Multi-Account AWS Without Blocking Delivery

A practical path from broad IAM roles to scoped, reviewable permission boundaries using automation instead of ticket queues.

Coming soon

AWS8 min read

Cloud Guardrails as Code: Terraform Patterns That Hold Up

Module structure, policy-as-code checks, and drift handling for organisations that add accounts faster than they add engineers.

Coming soon

Platform Security10 min read

Platform Trust: Secure Boot, TPM, and Why It Still Matters

The chain of trust from firmware to OS, what breaks in the field, and how validation coverage should be structured.

Coming soon

DevSecOps7 min read

Security Gates That Engineers Do Not Route Around

Calibrating SAST, DAST, SCA, and container scanning thresholds so pipelines stay fast and findings stay actionable.

Coming soon

AIOps12 min read

AI-assisted Root Cause Analysis for CloudSecOps

Correlating cloud, platform, and security telemetry into incident narratives, and where AI assistance genuinely reduces MTTR.

Coming soon

Enterprise Security10 min read

Building an Enterprise Security Operating Model

Aligning identity, cloud, platform, and pipeline security into one accountable model with metrics leadership can read.

Coming soon