Skip to main content
Cloud Security Engineer

Designing Secure AWS Architectures

Zero Trust | DevSecOps Automation | Terraform Governance | Cloud-Native Threat Detection

I architect and automate secure AWS environments with a focus on Zero Trust principles, infrastructure-as-code governance, and real-time threat detection. Specializing in DevSecOps automation, IAM guardrails, SOAR workflows, and compliance-driven cloud security.

Surya Sesank — Senior Cloud Security Architect
AWS
TF

About

Senior Cloud Security Architect with 8+ years of expertise in designing and automating secure AWS environments. Specialized in implementing Zero Trust architectures, DevSecOps automation, and cloud-native threat detection systems.

My focus is on building security-first infrastructure through Terraform governance, IAM guardrails, SOAR automation, and comprehensive compliance frameworks. I've designed and deployed security solutions for healthcare, financial services, and enterprise organizations.

Cloud security demands a proactive approach — from securing the software supply chain and hardening CI/CD pipelines to enforcing least-privilege access at scale. I architect layered defenses that combine preventive controls, detective capabilities, and automated response workflows to reduce risk across the entire AWS environment.

I specialize in threat modeling for cloud-native workloads, designing AWS Security Hub and GuardDuty integrations that turn raw findings into actionable alerts. By correlating signals across CloudTrail, VPC Flow Logs, and application telemetry, I build detection pipelines that catch lateral movement, credential abuse, and data exfiltration in real time.

Passionate about cloud security automation, infrastructure-as-code, and translating complex security requirements into scalable, maintainable systems that stand up to modern adversaries.

AWS Security Architecture & Automation
Zero Trust & IAM Governance
DevSecOps Pipeline Integration
Infrastructure-as-Code (Terraform, CloudFormation)
Cloud-Native Threat Detection
SOAR Automation & Incident Response
Healthcare & Compliance (HIPAA, PCI-DSS)

Core Expertise

Cloud Security

AWS security architecture, network isolation, encryption, and defense-in-depth strategies

AWS Security Network Security Encryption

IAM Governance

Identity & access management, policy automation, least privilege enforcement, and access reviews

IAM Design Policy Automation Access Control

DevSecOps

Security-first CI/CD pipelines, container security, SAST/DAST integration, and automated remediation

CI/CD Security Container Security Automation

Terraform & IaC

Infrastructure-as-code governance, policy enforcement with OPA/Sentinel, and secure automation

Terraform OPA/Sentinel CloudFormation

Threat Detection

Cloud-native detection engineering, GuardDuty integration, SecurityHub automation, and threat response

Detection Rules GuardDuty Threat Hunting

SOAR Automation

Security orchestration, automated incident response, threat enrichment, and response workflows

SOAR Platforms Automation Response

Compliance & GRC

Healthcare (HIPAA), payment processing (PCI-DSS), audit automation, and compliance frameworks

HIPAA PCI-DSS Compliance

Application Security

OWASP principles, secure coding practices, vulnerability management, and security testing

AppSec OWASP Vuln Management

Tools & Tech Stack

The technologies and platforms I work with daily

AWS Security Services

Security HubGuardDutyIAM CloudTrailAWS ConfigMacie InspectorWAF & ShieldFirewall Manager Organizations & SCPs

IaC & Automation

TerraformAWS CDKCloudFormation PythonBashAnsible

DevSecOps & Pipeline Security

GitHub ActionsOPA / ConftestCheckov tfsecTrivySAST / DASTSonarQube

CSPM, SIEM & Detection

WizCrowdStrikeSplunk CloudWatchSOAR PlatformsVPC Flow Logs

Compliance Frameworks

SOC 2PCI DSSHIPAA NIST CSFCIS BenchmarksISO 27001

Containers & Platforms

DockerKubernetesEKS ECRFargateGit

Featured Projects

AWS Security Architecture Portfolio

Featured

Comprehensive AWS security architecture implementation covering multi-account setup, network isolation, encryption, and centralized logging with GuardDuty and SecurityHub integration.

AWS Services 12+
Security Controls 35+
Compliance Aligned HIPAA
AWS Terraform IAM GuardDuty
View on GitHub

Cloud SOAR Pipeline

Automation

Automated threat detection and response pipeline using GuardDuty findings, Lambda orchestration, and automated remediation workflows with 90% auto-remediation rate.

MTTD Reduction 35%
Auto-Remediation 90%
Response Time <5min
Lambda EventBridge GuardDuty Python
View on GitHub

Terraform + OPA Policy Gates

IaC Governance

Infrastructure-as-code governance with OPA/Conftest policy enforcement, automated security validation, and compliance-driven Terraform automation.

Policies Automated 50+
Security Gates 15+
Drift Prevention 100%
Terraform OPA/Conftest CI/CD Policy-as-Code
View on GitHub

ITDR Detection Engineering

Detection

Identity and infrastructure threat detection rules, anomaly detection, and real-time monitoring for AWS environments with automated alert orchestration.

Detection Rules 75+
Anomalies Caught Realtime
False Positive Rate <3%
GuardDuty CloudWatch Detection Rules CloudTrail
View on GitHub

Multi-Account Zero Trust Architecture

Architecture

Zero Trust architecture implementation across multiple AWS accounts with centralized policy enforcement, comprehensive logging, and automated compliance validation.

AWS Accounts 8+
Workloads Protected 200+
Trust Assumed None
AWS Organizations SCP IAM NetworkACLs
View on GitHub

Terraform + Ansible Automation

DevOps

End-to-end infrastructure automation combining Terraform for infrastructure provisioning and Ansible for security hardening and compliance enforcement.

Deployment Time -75%
Manual Effort -90%
Consistency 100%
Terraform Ansible CI/CD Python
View on GitHub

Impact & Metrics

0
+

Years Cloud Security Experience

0
+

Critical Vulnerabilities Remediated

0
%

MTTD Reduction Achieved

0
%

Automated Remediation Rate

0
+

AWS Security Projects

0
+

Workloads Secured

Articles & Blog

Latest Most recent articles
Medium Latest

Designing a Zero Trust AWS Governance Architecture using AWS Organisations, SCPs and CloudTrail

A practical walkthrough of designing a Zero Trust governance model across AWS Organizations — leveraging Service Control Policies, CloudTrail audit trails, and layered IAM controls to enforce least-privilege at scale.

⏱ 12 min read
Zero Trust AWS Orgs SCPs
Read Article
Dev.to Latest

Event-Driven EC2 Isolation in AWS: Building a Minimal Cloud SOAR Without Buying One

How to build a lightweight, event-driven EC2 isolation workflow on AWS — achieving automated threat containment using native services without the cost of a commercial SOAR platform.

⏱ 9 min read
EC2 SOAR Automation
Read Article
Hashnode Latest

Building a Multi-Account Zero Trust Governance Architecture in AWS using Terraform, SCPs and CloudTrail

A comprehensive guide to designing and deploying Zero Trust governance across AWS Organizations — combining Terraform automation, Service Control Policies, and CloudTrail for end-to-end visibility and enforcement.

⏱ 12 min read
Zero Trust Terraform SCPs
Read Article
LinkedIn Latest

Most People Study Cloud Wrong: Lessons from a Google Architect

A perspective-shifting take on how most engineers approach cloud certifications and learning — and the mindset shifts that separate architects who truly understand the cloud from those who just pass exams.

⏱ 5 min read
Cloud Career Architecture
Read Article
Medium Jan 2025

Cloud-Native Threat Detection: Building Detection Rules for AWS

A framework for writing high-fidelity detection rules using CloudTrail, VPC Flow Logs, and CloudWatch — reducing false positives below 3% in production environments.

⏱ 10 min read
Detection CloudTrail Threat Hunting
Read Article
Dev.to Dec 2024

HIPAA-Compliant AWS Architecture: What You Actually Need

Cutting through the compliance noise — a practical checklist of AWS controls needed for HIPAA, backed by real architecture patterns from healthcare deployments.

⏱ 11 min read
HIPAA Compliance AWS
Read Article

Speaking & Community

Sharing knowledge through talks, webinars, and community contributions

Conference 2025

Zero Trust at Scale: AWS Multi-Account Governance

Cloud Security Summit

Deep-dive into designing and enforcing Zero Trust governance across large AWS Organization structures using SCPs, Terraform, and CloudTrail.

Zero TrustAWSTerraform
Webinar 2025

Building a SOAR Without Buying One: Event-Driven Security on AWS

DevSecOps Community Webinar

Live walkthrough of building automated EC2 isolation and incident response workflows using native AWS services — no commercial SOAR required.

SOARAutomationDevSecOps
Community 2024

Policy-as-Code: Enforcing Security Gates in CI/CD with OPA

AWS User Group Meetup

Practical session on using Open Policy Agent and Conftest to block insecure Terraform plans before they reach production environments.

OPACI/CDIaC Security

Open Source & GitHub

Public tools, templates, and contributions to the security community

aws-zero-trust-terraform

Terraform modules for deploying a Zero Trust governance architecture across AWS Organizations — including SCPs, IAM guardrails, and CloudTrail configuration.

HCL ★ Add on GitHub
View Repository →

aws-soar-ec2-isolation

Serverless event-driven pipeline for automatic EC2 isolation on suspicious activity — Lambda, EventBridge, and Security Hub integration with full audit trail.

Python ★ Add on GitHub
View Repository →

More on GitHub

Browse all public repositories, security tools, and Terraform modules.

View GitHub Profile

What People Say

Feedback from colleagues, managers, and collaborators

Surya brings a rare combination of deep technical knowledge and practical implementation skills. His Zero Trust architecture work fundamentally improved our cloud security posture.

SS
— Add Colleague Name Senior Manager, Cloud Security · [Company]

Working with Surya on our DevSecOps pipeline was transformative. He automated threat detection workflows that reduced our manual triage effort by over 70%.

TK
— Add Colleague Name Principal Engineer, DevSecOps · [Company]

Surya's Terraform governance framework saved us months of compliance work. His attention to detail and ability to translate security requirements into code is exceptional.

AR
— Add Colleague Name Cloud Architect · [Company]

Get In Touch

Open to conversations about AWS security, cloud architecture, DevSecOps, and new opportunities

Location India · Open to Remote