Services
I work with teams running Kubernetes and cloud infrastructure who need security controls that hold up under scrutiny — from auditors, from clients, or from attackers.
Kubernetes Security Hardening
CIS Benchmark assessment, Pod Security Admission rollout, RBAC least-privilege remediation, default-deny network policy, Kyverno admission control, and runtime detection.
Deliverables: Before/after benchmark reports, a policy repository you keep, and documented remediation.
Zero-Trust Service Mesh Implementation
STRICT mTLS enforcement, identity-based L7 authorization, JWT validation at the edge, and egress control via allowlist.
Deliverables: Working policy set, traffic architecture documentation, and verification tests proving each control blocks what it claims to.
Software Supply Chain Security
SBOM generation, image signing in CI, and signature verification at admission — the complete loop, not half of it.
Deliverables: Hardened pipeline, admission policies, and a demonstrated rejection of unsigned artifacts.
Cloud Security Posture Review — AWS / Azure
Automated assessment against CIS benchmarks plus manual review of IAM, logging, network exposure and encryption.
Deliverables: Findings mapped to CIS controls, prioritised by exploitability rather than raw CVSS, with a remediation plan.
CI/CD Pipeline Security
Secret scanning, SAST, dependency and image scanning, and migration from long-lived cloud credentials to OIDC federation.
Deliverables: Integrated pipeline with severity gates tuned so they do not get bypassed, plus a documented exception process.
Linux Fleet Hardening
CIS Benchmark remediation delivered as reusable Ansible automation, with OpenSCAP evidence before and after.
Deliverables: An Ansible role you own, scan reports, and a drift-detection mechanism.
How I work
Fixed scope, fixed price. You know what you are getting and what it costs before we start.
You keep the automation. Every engagement leaves behind code — policies, roles, pipelines — not just a document.
Controls are verified, not asserted. If I say something is blocked, I show you it being blocked.