- 🔭 Currently: Cloud Security Engineer @ Equifax
- 🧩 Mission: To build automated, AI-driven security systems that scale across multi-cloud environments.
- 🌱 Learning Focus (2025): IaC Security, DevSecOps, Kubernetes Security, Threat Detection & Response.
- 🚀 Projects: Terraform Secure IAM Modules · Secure CI/CD Pipelines · AI-SOC Assistants · Kubernetes Policy Enforcement.
- 💬 Ask me about: Cloud Security, IaC, DevSecOps, or building real-world automation in GCP/AWS.
- 📄 Portfolio: github.com/jibin006
- 📫 Reach me: LinkedIn · 📧 jibin.benny@example.com
| Project | Description | Tech Stack |
|---|---|---|
| Secure Cloud Foundation | Multi-account AWS security architecture — SCPs, hub-spoke VPC, KMS encryption, secrets rotation, centralized logging, and EventBridge-driven detection pipeline with auto-remediation | Terraform · Python · AWS |
| IAM Drift Detector | Cross-account IAM drift detection with baseline snapshots, differential analysis, and blast-radius-based severity scoring — deployed as Lambda + EventBridge pipeline | Python · boto3 · Lambda |
| Terraform Secure Modules + OPA Policies | 4 hardened Terraform modules with security defaults enforced + 14 OPA/Conftest policies blocking misconfigurations at PR-time with testing framework and CI enforcement | Terraform · OPA/Rego · Conftest |
| Secure CI/CD Pipeline | Keyless OIDC federation + Cosign image signing + SBOM generation + Kubernetes admission verification — with STRIDE threat model covering 4 attack scenarios | GitHub Actions · Cosign · Sigstore |
| K8s Security Enforcement | 18 Gatekeeper constraint templates + Falco runtime detection + RBAC + Pod Security Standards + network policies with default-deny + investigation runbooks | Kubernetes · Gatekeeper · Falco |
| Cloud IR Toolkit | Automated evidence collection + Lambda containment (isolation, IAM revocation, S3 quarantine) + incident response playbooks with rollback capability | Python · Lambda · Terraform |
| GCP Workload Identity | Keyless GCP auth from GitHub Actions + AWS, GCP Org Policies, VPC security, Cloud Audit Logs to BigQuery | Terraform · GCP · GitHub Actions |
| LLM Prompt Injection Detector | Multi-layer prompt injection detection (pattern + heuristic + embedding) as FastAPI proxy for LLM API security | Python · FastAPI · LLM Security |
🔐 “Automate Security. Scale Trust.”
