Cloud security & compliance for regulated fintech.
I build cloud infrastructure and then defend it. Currently founding engineer on a SAMA-regulated payments platform, where I own the GCP estate end to end β Terraform, Kubernetes, CI/CD, SIEM detections, and the compliance evidence behind all of it.
Before that, five years of DevSecOps delivery across banking, healthcare and telecom on AWS, Azure and GCP.
- ποΈ Building and defending a SAMA-regulated payments platform on GCP β private networking, Terraform IaC, blue-green delivery
- π Driving SAMA CSF maturity from Level 2 to Level 3 β control mapping, evidence, audit readiness
- π‘οΈ Contributing to OWASP www-project-eks-goat
- βοΈ Writing Runs in Production β system design, security, and lessons from things that actually shipped
| Assess | Cloud, pipeline and Kubernetes reviewed against production and audit standards |
| Implement | Security enforced as a gate, infrastructure defined in code, clusters that hold up under load |
| Advise | Ongoing architecture and posture review for teams not ready to hire it full time |
| Repo | What it is |
|---|---|
| www-project-eks-goat | OWASP project β contributed region-aware EKS cleanup |
| postgres-gist-500m-lab | GiST index behaviour at 500M rows, measured and written up |
| AWS-DevOps-Professional | Study notes for the AWS DevOps Pro certification |
| Study-guide-AZ-400 | Same, for the Microsoft DevOps Engineer track |
| Getting-Started-with-GitHub-Actions | Practical walkthrough of Actions workflows |
| Terraform-Using-AWS | Terraform patterns for AWS infrastructure |
Cloud
Containers & Infrastructure as Code
Delivery & Security
Data & Observability






