AI-Assisted IAM Provisioning
IAM Identity Center permission-set provisioning on Amazon Bedrock. Multi-layer human approval, Access Analyzer validation, and a complete audit trail.
Amazon BedrockIAM Identity CenterAccess AnalyzerPython
Designing and governing multi-cloud estates across AWS, Azure, and GCP — building AI-assisted automation that keeps things secure at scale.
I'm a cloud architect who cares about doing things at scale — the right way. Over 13 years, I've moved from hands-on systems engineering to designing governance frameworks that let hundreds of teams ship safely across AWS, Azure, and GCP.
At Epsilon, I set the standards for how 1,000+ AWS accounts operate: landing zones, identity, guardrails, networking. I also build AI-powered tools — like an IAM chatbot on Amazon Bedrock that turns plain English into governed IAM policies, and automation that cut security remediation from 30 minutes to under a minute.
I believe the best cloud architecture is invisible — teams should move fast without thinking about compliance, because the platform handles it. That's what I build.
Epsilon · Bangalore
Epsilon · Bangalore
Epsilon · Bangalore
Jeeves Info Systems
Brillio Technologies
IBM India Pvt Ltd
IAM Identity Center permission-set provisioning on Amazon Bedrock. Multi-layer human approval, Access Analyzer validation, and a complete audit trail.
Amazon BedrockIAM Identity CenterAccess AnalyzerPython
FastAPI + Bedrock chatbot generating governed IAM policies from plain language or JSON. Knowledge Base lookups for estate-specific queries.
FastAPIBedrockKnowledge BasesGenAI
Wiz CSPM integration with IAM remediation workflows. Cut per-account remediation from 15–30 minutes to under a minute.
WizIAMAutomationPython
One governance model across 1,000+ AWS accounts, Azure Management Groups, and GCP org/deny policies. Migrated 600+ accounts into Control Tower.
Control TowerAzureGCPGovernance
Vault on Amazon EKS and EC2/ASG with Terraform. Proved production resilience through node-loss, patching, and backup/restore DR tests.
HashiCorp VaultEKSTerraformDR
VPC Lattice + Route 53 Profiles with shared private hosted zones. Isolated VPC access to observability without Transit Gateway.
VPC LatticeRoute 53Networking
AWS
Azure
GCP
Landing Zone Design
AWS Organizations
Control Tower
Multi-Account Strategy
Cloud Migration
Reference Architectures
ADRs
SCPs
Permissions Boundaries
IAM Identity Center
IAM Access Analyzer
GuardDuty
Wiz (CSPM)
KMS
PCI-DSS
Least Privilege
Amazon Bedrock
Knowledge Bases
Guardrails
Amazon Q
IAM Policy Chatbot
GenAI Access Controls
Terraform
CloudFormation
StackSets
Python
FastAPI
Ansible
Lambda
SQS
EventBridge
VPC Design
Hub-and-Spoke
VPC Lattice
Route 53
ALB / NLB
DNS
Amazon EKS
HashiCorp Vault
Elasticsearch
Kibana
Elastic Fleet
GitHub
Bitbucket
Jenkins
GoCD
CloudWatch
CloudTrail
Athena
FinOps
Whether it's about cloud architecture, a project collaboration, or just a conversation — I'd love to hear from you.