Experience
Ten years, five organisations, one direction.
Cloud and AI Security Architect
Enterprise cloud and AI security architecture across hybrid environments — Microsoft Defender suite (MDE, MDI, MDO, Defender for Cloud) deployment, identity-first Zero Trust with Entra ID and Conditional Access, and centralized security operations.
Cloud and AI security governance for enterprise LLM/agentic AI risk controls — securing GenAI and RAG deployments, prompt injection and adversarial ML defenses, AI copilot governance, and security controls embedded in vendor onboarding and procurement. Enterprise security strategy, roadmap and architecture governance.
Authored and implemented the bank's Emerging Technology and AI Security Standard, aligned to NIST AI RMF and ISO/IEC 42001 — a governance framework covering GenAI, RAG architectures, agentic AI, prompt safety, and AI adoption controls, establishing the security baseline for the client's enterprise AI rollout.
Cloud Security Architect | Consultant
Principal cloud security architect for a leading GCC financial institution. Multi-cloud security architecture across Azure, AWS and GCP aligned to CIS Benchmarks, NIST CSF and banking regulatory standards.
Led the CSPM program — automated configuration assessment, high-risk misconfiguration remediation, cloud security maturity uplift, and cloud security/AI/ML risk assessment including model governance as part of the bank's cloud security posture management (CSPM) and Microsoft Purview program — evaluating GenAI vendor solutions for data protection, access control, and compliance risk prior to enterprise adoption. Zero Trust across identity, data and workloads. Product Owner for HSM and Microsoft Purview/AIP. SABSA and TOGAF aligned reference architectures. DevSecOps integration into CI/CD.
Cloud Security & DevSecOps Engineer
Security embedded into cloud infrastructure and DevOps pipelines at enterprise scale across Azure and GCP. Zero Trust across cloud workloads — identity-based access control, micro-segmentation, continuous verification.
Application threat modeling in the design phase, hub-and-spoke network architecture controlling lateral movement, and automation with Ansible, Python and Bash.
Cloud Security Engineer
Azure infrastructure and security configuration for enterprise clients — NSGs, firewall rules, resource isolation.
Identity and access governance: RBAC, service principal security, privileged access for production systems. Terraform and PowerShell automation, plus Azure security audits.
Cloud Security Analyst
Foundation role in AWS and Azure infrastructure, access management and security operations — IAM policy administration, least privilege enforcement, secure baseline configuration.
Azure Site Recovery, WAF and Application Gateway, with PowerShell, Python and JSON automation.