Offensive security engineer and GRC engineering practitioner with close to 10 years of experience in private and public sectors. I have performed testing on UAS, cloud infrastructure, and web applications, and I build the compliance automation, policy-as-code controls, and security architecture that GRC engineering requires, not just assess them from the outside. My other areas of experience include custom tool development and command and control development.
Currently building out hands-on infrastructure labs that pair offensive security with GRC engineering.
Offensive security
GRC engineering
Cloud & infrastructure
| Project | Summary | Stack |
|---|---|---|
| Kubernetes GRC Engineering | Automated k3d cluster with layered controls: OPA Gatekeeper admission control, tfsec/kubesec/trivy scanning, and ESO-injected secrets, reconciled continuously by Argo CD. | Terraform · k3d · Argo CD · OPA Gatekeeper · ESO |
| IAM Privilege Escalation Lab | A self-contained AWS IAM misconfiguration lab proving a full attack chain end to end (overpermissive Lambda role → unscoped iam:PassRole), then closed with OPA/tfsec policy and fixed Terraform. |
Terraform · AWS IAM · Lambda · OPA/Rego · tfsec |
| Azure GRC Evidence Pipeline | Terraform-built GRC pipeline on Azure: discovers configuration drift, collects Defender for Cloud findings into an owned evidence store, and generates POA&M/SAR mapped to NIST 800-53 Rev. 5 and CSF 2.0. | Terraform · Azure Policy · Defender for Cloud · Cosmos DB |


