Cloud foundations
Designing landing zones, identity boundaries, logging, and policy guardrails that scale with the organization.
Open to Cloud Security opportunities in Germany
Cloud security engineering with a bias toward useful guardrails, measurable detection, and infrastructure that developers can trust.
profile: cloud_security_engineer
location: Germany / EU
default: secure_by_design
signal: ● systems_online
01 / What I focus on
Designing landing zones, identity boundaries, logging, and policy guardrails that scale with the organization.
Turning cloud telemetry into useful signals, triage playbooks, and response workflows that reduce uncertainty.
Embedding security checks into CI/CD so teams find issues early without slowing down delivery.
02 / Selected work
Sample case studies for the portfolio. Replace these with your own labs, assessments, and measurable outcomes.
Cloud governance · AWS
A reference landing zone that combines least-privilege access, centralized audit trails, and preventive controls with a clear developer path.
Discuss the approachDetection engineering · CloudTrail
A detection pack for suspicious identity activity, with tested hypotheses, severity context, and response notes for an on-call team.
Discuss the approachDevSecOps · GitHub Actions
A lightweight pipeline for secrets, dependencies, infrastructure, and container checks with actionable developer feedback.
Discuss the approach03 / My approach
Good security engineering is not a gate at the end of delivery. It is a set of well-designed decisions that help a team move with confidence.
I work from threat models and real operational constraints, then turn them into controls people can understand, automate, and improve. The goal is a safer system and a stronger engineering culture.
Start a conversationMap assets, identities, data flows, and the risks that matter to the business.
Prefer small, composable controls over brittle security theatre.
Build feedback loops and defaults that work with the team, not against it.