Summary
Overview
Work History
Education
Skills
Certification
Languages
Timeline
Generic

Gyrron Aweh

Ottawa,ON

Summary

Staff level Cloud Security Engineer with 10+ years of experience designing, building, and securing enterprise cloud platforms across AWS, Azure, and Kubernetes environments. Proven track record of partnering with Platform Engineering, Cloud Architecture, Site Reliability Engineering (SRE), and Security Operations teams to build secure-by-default cloud foundations through software engineering, automation, reusable IaC, and policy-driven security controls. Deep expertise in AWS multi-account architectures, Terraform module development, Kubernetes security, cloud governance, deployment guardrails, identity architecture, cloud telemetry, and security automation. Passionate about solving security challenges through engineering rather than manual processes by building scalable security platforms that enable developers to move faster while maintaining enterprise security standards. Recognized for leading cloud security initiatives, influencing enterprise architecture, mentoring engineering teams, and delivering reusable cloud security capabilities adopted across large organizations.

Overview

2
2
Languages
1
1
Certification
12
12
years of professional experience

Work History

Senior Cloud Security Engineer

Workday
Ottawa, Ontario
04.2022 - Current
  • Designed and implemented secure AWS landing zone patterns supporting multi-account cloud environments using AWS Organizations, centralized identity, shared services, and least-privilege access models.
  • Built reusable enterprise Terraform modules implementing secure-by-default infrastructure standards, enabling engineering teams to provision compliant AWS resources through standardized Infrastructure-as-Code.
  • Developed Python automation validating Terraform deployments, IAM configurations, Kubernetes resources, networking policies, and cloud infrastructure before production deployment, significantly reducing manual security review effort.
  • Implemented preventive cloud security controls using policy-as-code frameworks enforcing organizational guardrails, deployment validation, configuration compliance, and Infrastructure-as-Code security standards.
  • Improved enterprise CloudTrail architecture through centralized log aggregation, immutable logging, integrity validation, telemetry enrichment, and standardized cloud audit pipelines supporting Security Operations and Detection Engineering.
  • Partnered with Platform Engineering teams to strengthen Amazon EKS security by implementing workload identities, RBAC governance, admission controls, secrets management, runtime protection, and secure service-to-service authentication.
  • Designed reusable cloud reference architectures documenting secure networking patterns, identity architecture, Kubernetes deployment standards, Infrastructure-as-Code practices, and cloud security implementation guidance adopted across engineering organizations.
  • Collaborated with Security Operations to integrate cloud telemetry into Microsoft Sentinel, improving detection engineering capabilities through enriched CloudTrail events, infrastructure telemetry, IAM analytics, and automated alert generation.
  • Participated in pull request reviews, Terraform code reviews, architecture reviews, and platform design discussions, ensuring cloud security was integrated throughout the engineering lifecycle.
  • Built deployment validation workflows preventing high-risk infrastructure changes through automated policy enforcement, Infrastructure-as-Code testing, and continuous compliance validation.
  • Worked closely with engineering leadership to improve developer experience by building reusable security capabilities instead of relying on manual approval processes.
  • Mentored engineers on AWS architecture, Terraform module design, Kubernetes security, policy-as-code implementation, secure Infrastructure-as-Code development, and cloud engineering best practices.

Cloud Security Specialist

Canadian Tire
02.2019 - 03.2022
  • Built reusable Terraform modules implementing standardized cloud infrastructure across Azure and AWS while enforcing enterprise security baselines and deployment consistency.
  • Integrated Infrastructure-as-Code validation, policy enforcement, secrets detection, dependency analysis, and deployment verification into Azure DevOps CI/CD pipelines supporting secure software delivery.
  • Designed cloud identity architecture using Azure Active Directory, AWS IAM, OAuth2, OIDC, RBAC, workload identities, and least-privilege governance supporting hybrid cloud environments.
  • Automated cloud governance, IAM lifecycle management, compliance validation, and operational security using Python and PowerShell, reducing manual engineering effort while improving audit readiness.
  • Conducted cloud architecture reviews evaluating networking, IAM, Kubernetes, APIs, Infrastructure-as-Code, and deployment pipelines before production implementation.
  • Collaborated with platform engineering teams to improve deployment standards, cloud networking, Kubernetes security, monitoring architecture, and Infrastructure-as-Code quality across enterprise engineering teams.

Cloud Architect

Capital One
01.2015 - 12.2018
  • Designed enterprise cloud architectures implementing AWS multi-account strategies, Zero Trust networking, secure VPC segmentation, encryption standards, identity federation, and resilient infrastructure supporting mission-critical financial applications.
  • Built standardized Terraform and CloudFormation frameworks implementing secure-by-default infrastructure patterns that accelerated cloud adoption while improving governance and engineering consistency.
  • Designed secure cloud-native architectures supporting distributed microservices through workload identities, secure APIs, authentication, authorization, encryption, and resilient service-to-service communication.
  • Implemented centralized cloud telemetry pipelines integrating CloudTrail, infrastructure logs, IAM activity, Kubernetes events, and cloud security monitoring into enterprise security operations, improving detection engineering and incident response capabilities.
  • Partnered with cloud engineering teams to develop secure cloud reference architectures, deployment standards, Infrastructure-as-Code frameworks, and engineering best practices that enabled scalable cloud adoption across multiple business units.
  • Participated in cloud architecture reviews, infrastructure design discussions, code reviews, and cloud transformation initiatives while providing technical leadership on enterprise cloud security strategy.
  • Mentored engineers on AWS architecture, Terraform design patterns, cloud governance, Infrastructure-as-Code, Kubernetes security, DevSecOps, and cloud engineering best practices, strengthening technical capabilities across engineering organizations.

Education

Bachelor of Science - Computer And Information Sciences

Presbyterian University
Cameroon
07-2014

Skills

  • AWS Multi-Account Architecture
  • Cloud Security Engineering
  • Platform Security
  • Enterprise Cloud Foundations
  • Terraform Module Development
  • Infrastructure-as-Code
  • Policy as Code
  • Cloud Governance
  • Amazon EKS Security
  • Kubernetes Security
  • Serverless Security
  • CloudTrail Architecture
  • Cloud Telemetry & Logging
  • Detection Engineering
  • CI/CD Security
  • Python, Go, Bash, PowerShell, YAML,JSON
  • Identity & Access Management
  • Zero Trust Architecture
  • Security Automation
  • Cross-Functional Technical Leadership
  • Engineering Mentorship

Certification

• AWS Certified Security – Specialty
• Certified Cloud Security Professional (CCSP)
• CompTIA Security+
• Microsoft Certified: Azure Fundamentals

Languages

English
Native/ Bilingual
French
Native/ Bilingual

Timeline

Senior Cloud Security Engineer

Workday
04.2022 - Current

Cloud Security Specialist

Canadian Tire
02.2019 - 03.2022

Cloud Architect

Capital One
01.2015 - 12.2018

Bachelor of Science - Computer And Information Sciences

Presbyterian University
Gyrron Aweh