Cloud, AI & Security Architect · Bahrain
Security architecture for regulated enterprises moving into AI.
I am Shujat Azim — a cloud and AI security architect working with banks and enterprise technology providers across the Gulf. My work is the unglamorous part: identity boundaries, posture management, and governance that survives an audit.

Ten years ago I was writing IAM policies and hardening baselines. Today I decide how a bank's cloud estate is allowed to work.
That path — HCL, Accenture, Adobe, then architect-level work from July 2022 — means the standards I write are shaped by having implemented them first. I spent four years as principal cloud security architect for a leading GCC financial institution, running posture management across Azure, AWS and GCP against CIS, NIST CSF and central bank expectations. I now lead cloud and AI security architecture at International Turnkey Systems in Bahrain.
The current question in every enterprise I work with is the same: how do we let AI touch real data without losing control of it? That is an architecture problem before it is a policy problem.
More about how I workFocus
AI Security & Governance
I build the control layer around enterprise AI: model access, data boundaries, prompt and retrieval risk, and approval gates before a workload reaches production. Governance is written into architecture standards, not into a policy document nobody reads.
Zero Trust & Identity Architecture
Identity is the primary control plane in every environment I design — Entra ID, Conditional Access, privileged access paths, and segmentation that limits lateral movement. Verification is continuous and enforced at the workload, not just at the edge.
Cloud Security for Regulated Industries
Multi-cloud architecture across Azure, AWS and GCP mapped to CIS Benchmarks, NIST CSF and GCC banking regulation. I run posture management programs that measure misconfiguration risk and reduce it on a schedule regulators can audit.
Selected work
Rebuilding cloud posture management for a GCC bank
A regulated multi-cloud estate with no shared definition of risk. We built one — automated assessment, an agreed severity model, and a remediation cadence the regulator could follow.
Read the case studyExperience
Cloud and AI Security Architect
Enterprise cloud and AI security architecture across hybrid environments — Microsoft Defender suite (MDE, MDI, MDO, Defender for Cloud) deployment, identity-first Zero Trust with Entra ID and Conditional Access, and centralized security operations.
Cloud and AI security governance for enterprise LLM/agentic AI risk controls — securing GenAI and RAG deployments, prompt injection and adversarial ML defenses, AI copilot governance, and security controls embedded in vendor onboarding and procurement. Enterprise security strategy, roadmap and architecture governance.
Cloud Security Architect | Consultant
Principal cloud security architect for a leading GCC financial institution. Multi-cloud security architecture across Azure, AWS and GCP aligned to CIS Benchmarks, NIST CSF and banking regulatory standards.
Led the CSPM program — automated configuration assessment, high-risk misconfiguration remediation, cloud security maturity uplift, and cloud security/AI/ML risk assessment including model governance as part of the bank's cloud security posture management (CSPM) and Microsoft Purview program — evaluating GenAI vendor solutions for data protection, access control, and compliance risk prior to enterprise adoption. Zero Trust across identity, data and workloads. Product Owner for HSM and Microsoft Purview/AIP. SABSA and TOGAF aligned reference architectures. DevSecOps integration into CI/CD.
Cloud Security & DevSecOps Engineer
Security embedded into cloud infrastructure and DevOps pipelines at enterprise scale across Azure and GCP. Zero Trust across cloud workloads — identity-based access control, micro-segmentation, continuous verification.
Cloud Security Engineer
Azure infrastructure and security configuration for enterprise clients — NSGs, firewall rules, resource isolation.
Cloud Security Analyst
Foundation role in AWS and Azure infrastructure, access management and security operations — IAM policy administration, least privilege enforcement, secure baseline configuration.
Speaking
Sovereignty Beyond Regions: Practical Azure/M365 Control Patterns
A working session on what data sovereignty actually requires once the region selector is no longer enough — tenant boundaries, key custody, Purview classification, and the Conditional Access patterns that keep regulated data inside a jurisdiction.
Speaking detailsWriting
The Future of AI Security in Enterprise Environments
How global enterprises are rearchitecting their cyber programs around AI workloads, model integrity, and secure data lifecycles.
Zero Trust in the Age of AI
Zero Trust principles applied to autonomous agents, copilots, and machine identities operating at machine speed.
Securing Microsoft 365 for Modern Enterprises
A reference architecture for hardening M365 with Entra ID, Defender XDR, Purview, and Conditional Access in regulated industries.