Cloud Security / SecOps / Governance

Cloud Security & Continuous Governance

Preventive, detective and operational controls integrated with cloud engineering across a multi-account AWS environment with +20 accounts.

AWS IAMGuardDutyInspectorAWS ConfigCloudWatchOrganizations
01

Overview

Implementation and evolution of security and governance controls in an AWS environment with +20 accounts, integrating prevention, detection and response in a sustainable operational model.

02

Context

Cloud security required controls distributed across multiple layers — identity, configuration, workloads, networking, logging and organizational governance. The challenge was connecting prevention, detection and response in a model that was operationally sustainable and compatible with the platform's evolution velocity.

03

Challenge

Integrate preventive, detective and operational controls in a sustainable model, reducing noise, maintaining operational context and transforming technical findings into risk-proportionate actions.

04

My role

  • IAM, access policies, AWS Organizations and Service Control Policies
  • GuardDuty, Inspector, AWS Config and configuration monitoring
  • CrowdStrike, Orca Security and complementary security tooling
  • Cloudflare and Imperva for edge and application protection
  • Event analysis, incident investigation and troubleshooting
  • Security, cloud engineering and operations integration
05

Architecture

The approach grouped controls across three complementary capabilities: prevent (controls that blocked risky actions before they occurred), detect (monitoring and detection of anomalous configurations and behavior) and respond (investigation, remediation and continuous improvement). Each capability operated with specific tooling, but integration between them was essential for effectiveness.

Conceptual architecture — details intentionally generalized
Prevent→
Detect→
Respond
IAM / SCPGuardDuty / InspectorConfig / CloudWatch
CrowdStrike→
Orca Security→
Cloudflare / Imperva
06

Technical decisions

  • Security by Design from architecture — not as retrospective auditing
  • Preventive controls applied at appropriate hierarchy levels
  • Detective signals with operational context to reduce false positives
  • Response supported by logs, investigation and automated remediation when possible
07

Security & governance

Prevent: IAM with least privilege, SCPs as guardrails, network controls and organizational policies. Detect: GuardDuty for threats, Inspector for workload vulnerabilities, Config for configuration compliance, and complementary tooling for broader visibility. Respond: structured logs, data-driven investigation, troubleshooting and remediation with action tracking.

08

Engineering challenges

The operational challenge was reducing alert noise, maintaining context across different tools and transforming technical findings into risk-proportionate actions. Security could not be an isolated layer — it needed to be integrated with engineering, understanding workload context and platform operational constraints.

09

Results

  • More coherent security coverage across multiple accounts and layers
  • Closer SecOps and Cloud Engineering integration
  • Better investigation and continuous control evolution capacity
  • Preventive controls reducing exposure surface before detection