Experience · Manama, Bahrain

10+ years, five organisations, one direction.

From cloud operations and infrastructure hardening to enterprise security architecture for regulated banking — every architecture below is informed by implementation.
Cloud infrastructure security architecture
  1. Apr 2026 — Present

    Cloud and AI Security Architect

    International Turnkey Systems (ITS) · Manama, Bahrain · Regulated banking environment

    Design and implement core security controls across the cloud, identity, API and data layers of a regulated banking platform — translating requirements into deployable patterns, hardened baselines and reference implementations.

    Engineer detection and response on Microsoft Sentinel: author KQL analytics, tune detections against real telemetry, and automate triage and containment through SOAR playbooks integrated with Defender XDR, Defender for Cloud and Entra ID.

    Build identity and access controls with Entra ID and Conditional Access, including phased policy rollout, privileged access and least-privilege models that reduce blast radius.

    Threat model systems end to end across data flows, trust boundaries and failure modes, and assess HLDs, LLDs, products and third-party integrations before production.

    Establish the security layer for agentic AI, covering unauthorized AI use, data leakage, prompt injection, auditability, human oversight and incident readiness for GenAI and agent workloads.

    Build paved roads for delivery teams through secure defaults, control baselines and implementation guidance, while leading vendor evaluations, architecture reviews and engineering workshops.

  2. Jul 2022 — Apr 2026

    Security Architect

    Unity Infotech — Client: Ahli United Bank (AUB) · Manama, Bahrain · Tier-1 regional bank

    Owned security engineering and design assurance for critical banking platforms spanning application, cloud, network, identity, endpoint, data protection and third-party integrations.

    Implemented and operated the Microsoft security stack in production: Entra ID, Conditional Access, Defender XDR, Sentinel, Purview DLP/AIP, Defender for Cloud, Key Vault, Azure Policy, WAF and secure logging baselines.

    Led incident response end to end — containment, root-cause analysis and post-mortems that converted incidents into durable control or detection changes.

    Built reference architectures and control patterns for API security, Microsoft security and cloud controls, and ran threat modelling and technical risk assessment across HLDs, LLDs, data flows and vendor solutions.

    Served as product owner for HSM and Purview/AIP, covering key lifecycle governance, classification, DLP policy engineering, troubleshooting and control-effectiveness validation.

    Led third-party and SOC/MSSP assurance, translating technical risk into decisions for engineering, risk, compliance and vendor teams.

  3. Sep 2019 — Apr 2022

    Cloud Security & DevSecOps Engineer

    Adobe · India

    Designed and deployed secure multi-cloud architecture on Azure and AWS for Adobe Experience Manager environments, spanning identity, segmentation, private connectivity, encryption, secrets, logging, workload protection, resilience and monitoring.

    Automated secure delivery with Ansible, Python, Bash and CI/CD practices, replacing manual and drift-prone steps with repeatable hardened deployments.

    Led Azure ASM-to-ARM modernization and security assessments across live customer environments, partnering with enterprise architects and operations teams through production deployment.

  4. May 2018 — Aug 2019

    Cloud Security Engineer

    Accenture · India

    Deployed and hardened Azure infrastructure, including virtual machines, load balancers, VNets, NSGs and the associated network and access controls.

    Codified infrastructure with PowerShell and Terraform, and performed Azure security assessments with prioritized remediation alongside cloud and operations teams.

  5. Apr 2016 — Mar 2018

    Cloud Security Analyst

    HCL ISD · India

    Executed on-premises-to-Azure migrations with Azure Site Recovery, applying migration, hardening, access, network and operational controls throughout.

    Implemented VNets, NSGs, ExpressRoute, Azure Application Gateway and WAF, and automated cloud operations with PowerShell and JSON templates.