Cloud Security Engineering
Compliance Engineering Platform
Most compliance work is reactive. Something fails an audit, someone builds a control, and the cycle repeats. This platform was built around a different premise: compliance should be enforced at the point where infrastructure is defined, not discovered after it deploys.
Eleven labs across AWS and GCP. Policy libraries, tamper-evident evidence vaults, HIPAA gap remediation on a live patient intake API, zero long-lived credentials anywhere in the pipeline. Real cloud accounts. Real infrastructure. Real deployments.
The five systems below grew directly from that foundation. Each one solves a specific business problem. Each one has a live interactive demo.
What was built
- 01S3 NIST 800-53 controlsPreventive and detective controls mapped to NIST 800-53 across S3 resources with automated policy enforcement.
- 02GCP Terraform module with CMEKCustomer-managed encryption keys enforced across GCP resources via reusable Terraform module.
- 03S3 Object Lock evidence vaultTamper-evident compliance artifact storage with WORM protection and retention policy enforcement.
- 04Rego policy libraryModular OPA/Rego policies covering S3, IAM, and network resources mapped to NIST and HIPAA control frameworks.
- 05Conftest policy gatePre-deployment IaC evaluation that blocks violations before any resource reaches a live environment.
- 06GitHub Actions evidence pipeline with OIDCFully automated evidence collection triggered on every deploy. Zero long-lived credentials throughout.
- 07Cosign keyless signingCryptographic signing of every compliance artifact with a verifiable timestamp and identity claim.
- 08CloudTrail, Config, and Security Hub baselineContinuous compliance monitoring across the AWS environment. Configuration drift detected in real time.
- 09GCP Workload Identity Federation and Data Access logsLong-lived GCP credentials eliminated. All access authenticated via workload identity with a full audit trail.
- 10OSCAL with trestleMachine-readable compliance documentation in OSCAL format, accepted by major audit frameworks.
- 11HIPAA gap remediation capstoneLive patient intake API. 14 HIPAA Security Rule control gaps identified and closed before audit.
Five production systems
Each system below is active and interactive. Click through to see the business problem it solves, run a live demo against real infrastructure, and read the changelog.