// cloud security engineer · aws · london, uk
jaydeep — profilewhoamiProfile
Jaydeep Hasmukhlal
Cloud Security Engineer
Five years securing a large multi-account AWS estate in regulated UK financial services, specialising in security posture, vulnerability management, identity governance and the automation that turns findings into control.
London, UK · Remote-first · AWS
terminal$ jaydeep --interactiveTerminal
tty1jay@workstation:~$ helpjay@studio:~$ helpjay@studio:~$ help
available commands:
whoami · cases · skills · career · projects · contact · clear
click the window and type a command, or tap a chip below.click the panel and type a command, or tap a chip below.click the panel and type a command, or tap a chip below.
findings — caseworkfindings/Findings
Four case studies in security engineering: identity governance, threat hunting, AI-assisted investigation and service automation.
CASE-001orphaned-access✓ RESOLVED
Privileged access reporting became an orphaned-access detective control.
I built a Python control consolidating privileged-role data across RedHat IdM, AWS Identity Center, AWS IAM, GitHub, GitLab and Datadog, migrated it to GitHub Actions so the team could run it without local permissions or dependencies, then integrated leavers data to flag retained privilege.
- 1 day
- Before
- ~10 min
- After
- Monthly → bi-weekly
- Reporting cadence
- 20+
- Privileged roles
Production proof Still running after five years and finds real access issues on every run.
CASE-002weak-credentials✓ RESOLVED
One weak test credential became an estate-wide threat hunt.
After spotting a single weak password in a test environment, I generalised the observation into a Python scanner that evaluated credential strength across the AWS estate. The hunt surfaced weak production credentials, which were escalated and remediated through Route-to-Live.
- Estate-wide
- Credential sweep
- On-demand
- Repeatable hunt
CASE-003ai-triage-loop✓ RESOLVED
Created a structured GuardDuty investigation loop with Amazon Q.
I designed a Python workflow that retrieves a finding and directs Amazon Q through service-specific investigation across CloudTrail, EC2 and S3. It produces a true/false-positive assessment, remediation guidance and further checks where the evidence is incomplete — a repeatable investigation loop where none existed before.
CASE-004serviceops-automation✓ RESOLVED
Automated Service Operations until the manual workload disappeared.
I converted password resets, account creation, credential distribution and RBAC grants into parameterised Jenkins pipelines and Python automation — removing roughly 80% of the team's manual workload and clearing my own path into BAU DevOps engineering.
4 findings · 4 resolved · 0 open
~/skillsskills/Skills
$ ls current/
- aws-security/ IAM · Identity Center · Security Hub · GuardDuty · Inspector · Macie · Config · CloudTrail · Secrets Manager · Organizations
- vuln-mgmt/ Qualys VMDR · AWS Inspector · weekly account scans · new-AMI scans · CVE/QID investigation · product-group reporting
- sec-ops/ Cloud escalation authority · GuardDuty investigation · CloudTrail analysis · proactive threat hunting · compliance remediation
- identity/ RedHat IdM · RBAC · privileged access reviews · joiner/mover/leaver lifecycle · orphaned privilege detection
- automation/ Python · Bash · PowerShell · GitHub Actions · API integration · QuickSight dashboards · ServiceNow
- ai-assisted/ Amazon Q · agentic security workflow design · prompt engineering · failure-mode analysis · manual fallback design
$ ls archive/
- jenkins
- java
- csharp
- javascript
- sql
- xamarin
career.logcareer.logCareer
- [2021-08 → now] Cognizant — Cloud Security Engineer Security posture, vulnerability management, identity governance, cloud escalation and security automation across a large multi-account AWS estate.
- [2019-09 → 2020-09] Cognizant — DevOps Engineer / Programmer Analyst Maintained Jenkins CI/CD pipelines and supporting release scripts.
- [2019-05 → 2019-08] QA Consulting — DevOps Bootcamp Training across cloud platforms, Terraform, Jenkins, Docker, Java, web technologies and databases.
- [2018-09 → 2019-04] ICTS UK & Ireland (Heathrow) — Security Agent TSA-compliant passenger screening, document verification, behavioural observation and structured risk interviews in aviation security.
- [2017-07 → 2018-01] Tripleplay — Mobile App Developer Sole Android developer on a Xamarin IPTV application; learned the stack from zero and shipped a live-programming feature.
- [2013 → 2016] BEng (Hons) Software Engineering, University of Westminster Top 2% of cohort · Dean's List Award
- # off-duty: skydiving · trekking · travelling · food · photography · gaming
~/projectsprojects/Projects
- MakeMeMoney/ Python / Web Reddit and Finviz scraping for ticker sentiment analysis. ↗
- BlankBot/ JavaScript / Node.js A multi-command Discord bot and a long-running favourite build. ↗
- HTTP Cats/ Flutter / Dart Built specifically to learn Android, Dart and Flutter from zero. ↗
- Entertainment Planner/ Python / PyQt5 A desktop movie search and watchlist tool using REST APIs. ↗
- Minecraft Server Launcher/ Terraform / Bash / GCP Terraform and Bash that provision and initialise a game server on GCP. ↗
- Resource Guardian/ C# / .NET Windows process and service management with critical-component exclusions. ↗
contactcontactContact
open to roles · remote-first uk
Looking for the next cloud security problem worth solving.
Targeting remote-first Cloud Security, DevSecOps, Platform Security, Infrastructure Security and Security Automation roles in the UK.
- Location
- London, UK
- Work preference
- Remote strongly preferred · hybrid acceptable
- Right to work
- United Kingdom