Cloud, AI & Security Architect · Bahrain

Security architecture for regulated enterprises moving into AI.

I am Shujat Azim — a cloud and AI security architect working with banks and enterprise technology providers across the Gulf. My work is the unglamorous part: identity boundaries, posture management, and governance that survives an audit.

Portrait of Shujat Azim, Cloud, AI and Security Architect

Ten years ago I was writing IAM policies and hardening baselines. Today I decide how a bank's cloud estate is allowed to work.

That path — HCL, Accenture, Adobe, then architect-level work from July 2022 — means the standards I write are shaped by having implemented them first. I spent four years as principal cloud security architect for a leading GCC financial institution, running posture management across Azure, AWS and GCP against CIS, NIST CSF and central bank expectations. I now lead cloud and AI security architecture at International Turnkey Systems in Bahrain.

The current question in every enterprise I work with is the same: how do we let AI touch real data without losing control of it? That is an architecture problem before it is a policy problem.

More about how I work

Focus

AI Security & Governance

I build the control layer around enterprise AI: model access, data boundaries, prompt and retrieval risk, and approval gates before a workload reaches production. Governance is written into architecture standards, not into a policy document nobody reads.

Zero Trust & Identity Architecture

Identity is the primary control plane in every environment I design — Entra ID, Conditional Access, privileged access paths, and segmentation that limits lateral movement. Verification is continuous and enforced at the workload, not just at the edge.

Cloud Security for Regulated Industries

Multi-cloud architecture across Azure, AWS and GCP mapped to CIS Benchmarks, NIST CSF and GCC banking regulation. I run posture management programs that measure misconfiguration risk and reduce it on a schedule regulators can audit.

Selected work

Rebuilding cloud posture management for a GCC bank

A regulated multi-cloud estate with no shared definition of risk. We built one — automated assessment, an agreed severity model, and a remediation cadence the regulator could follow.

Financial services · Azure, AWS, GCP · 2022—2026

Read the case study

Experience

  1. Apr 2026 — Present

    Cloud and AI Security Architect

    International Turnkey Systems (ITS) · Bahrain

    Enterprise cloud and AI security architecture across hybrid environments — Microsoft Defender suite (MDE, MDI, MDO, Defender for Cloud) deployment, identity-first Zero Trust with Entra ID and Conditional Access, and centralized security operations.

    Cloud and AI security governance for enterprise LLM/agentic AI risk controls — securing GenAI and RAG deployments, prompt injection and adversarial ML defenses, AI copilot governance, and security controls embedded in vendor onboarding and procurement. Enterprise security strategy, roadmap and architecture governance.

  2. Jul 2022 — Apr 2026

    Cloud Security Architect | Consultant

    Ahli United Bank · Bahrain

    Principal cloud security architect for a leading GCC financial institution. Multi-cloud security architecture across Azure, AWS and GCP aligned to CIS Benchmarks, NIST CSF and banking regulatory standards.

    Led the CSPM program — automated configuration assessment, high-risk misconfiguration remediation, cloud security maturity uplift, and cloud security/AI/ML risk assessment including model governance as part of the bank's cloud security posture management (CSPM) and Microsoft Purview program — evaluating GenAI vendor solutions for data protection, access control, and compliance risk prior to enterprise adoption. Zero Trust across identity, data and workloads. Product Owner for HSM and Microsoft Purview/AIP. SABSA and TOGAF aligned reference architectures. DevSecOps integration into CI/CD.

  3. Sep 2019 — Apr 2022

    Cloud Security & DevSecOps Engineer

    Adobe · Noida, India

    Security embedded into cloud infrastructure and DevOps pipelines at enterprise scale across Azure and GCP. Zero Trust across cloud workloads — identity-based access control, micro-segmentation, continuous verification.

  4. May 2018 — Sep 2019

    Cloud Security Engineer

    Accenture · Gurgaon, India

    Azure infrastructure and security configuration for enterprise clients — NSGs, firewall rules, resource isolation.

  5. Jun 2016 — Mar 2018

    Cloud Security Analyst

    HCL Technologies · Noida, India

    Foundation role in AWS and Azure infrastructure, access management and security operations — IAM policy administration, least privilege enforcement, secure baseline configuration.

Full experience

SABSA · TOGAF · NIST CSF · ISO/IEC 27001 · CIS Controls · Zero Trust

Speaking

Sovereignty Beyond Regions: Practical Azure/M365 Control Patterns

Cloud Security Alliance — UK Chapter AGM

A working session on what data sovereignty actually requires once the region selector is no longer enough — tenant boundaries, key custody, Purview classification, and the Conditional Access patterns that keep regulated data inside a jurisdiction.

Speaking details

If it is about cloud, identity or AI risk, I am happy to talk.