Cloud security depth applied to real, self-built production systems
Designing and building AWS security architecture, IAM policy structures, encryption strategy, and multi-tenant isolation for my own compliance automation platform, Clouma.
Published author of a two-volume AWS Security Specialty exam guide, decoding 305 exam scenarios based on the patterns that trip candidates up.
Founder building Clouma (cloud compliance automation) and IndXPro (an AI-assisted stock scanner for Indian markets) — architecting, shipping, and operating both solo.
A two-volume guide to the AWS Security Specialty exam, decoded trap by trap
Traps 1–152: The first half of a 305-trap forensic system, built around the exam-question patterns that mislead even experienced candidates.
Traps 153–305: The advanced half of the 305-trap system, covering the harder scenarios that come up later in the exam.
Most exam prep teaches you to memorize services. This system teaches you to recognize the reasoning traps AWS builds into its hardest questions — the ones that catch people who otherwise know the material cold.
🎯 Start with 5 free traps • No signup required
Real, self-built systems — most in active development
Compliance evidence collection and control mapping across SOC 2, HIPAA, PCI DSS, ISO 27001, NIST, FedRAMP, CMMC, and more — with Postgres Row-Level Security for tenant isolation.
Continuous cloud-native security findings and posture management across AWS, Azure, GCP, OCI, and Kubernetes — built as Clouma's real-time detection layer.
The root-operator backend for Clouma — unified user, org, and entitlement administration across Proof and Shield, with platform-wide admin tooling.
Live production SaaS scanning Indian equity markets (NSE) — momentum, mean reversion, volatility breakout, and smart-money strategies, plus an AI signal-synthesis layer.
A registry connecting Florida property owners to the early eVTOL infrastructure buildout (I-4 corridor, Miami-Dade), ahead of Joby, UrbanX, and Eve's pilot rollouts.
An interactive companion to the AWS SCS-C02 books — practice the 305 decoded exam traps directly in the browser, no signup required for the first five.
Smaller builds and portfolio demos — not production systems, but real code exploring real patterns.
Multi-account Google Drive manager exploring OAuth 2.0 flows, server-side session security, and real-time file operations.
Zero-open-port file sync across two continents via a Raspberry Pi 5 relay, using WireGuard/Tailscale mesh VPN.
Open to cloud security roles, consulting conversations, or just talking shop about AWS.