About me
I’m a Security & Cloud Engineer focused on building secure, resilient systems in the cloud. I help teams ship fast and safely with secure-by-default architectures, automated guardrails, and clear governance aligned to SOC 2 and ISO/IEC 27001.
Core Focus Areas
- Cloud Security: architecture reviews, IAM hardening, encryption, network segmentation
- DevSecOps: CI/CD security, SAST/DAST, SCA, secrets management, IaC security (Terraform)
- Compliance & Governance: SOC 2, ISO/IEC 27001 control design, evidence automation, audit readiness
- Detection & Response: centralized logging, SIEM pipelines, alert tuning, response playbooks
- Application Security: threat modeling, secure coding guidance, dependency risk management
Selected Highlights
- Led SOC 2 and ISO/IEC 27001 readiness across engineering and operations, from policy development to technical controls and external assessments
- Implemented automated security checks in CI/CD (SAST, SCA, IaC scanning) with actionable feedback loops for developers
- Built secure cloud landing zones and standardized guardrails across AWS/GCP/Azure
- Drove vendor risk management improvements with standardized assessments and remediation tracking
Tools & Platforms
Go, Bash • Docker, Kubernetes • Terraform • AWS, GCP, Azure • Cloudflare • SIEM • SAST/DAST • SCA • Prisma Cloud/Twistlock • Checkmarx • Black Duck
Connect
- LinkedIn: https://www.linkedin.com/in/yentam/
- Email: (available upon request)
If you’re building in the cloud and want to raise your security baseline without slowing down delivery, let’s connect.