Overview
Implementation and evolution of security and governance controls in an AWS environment with +20 accounts, integrating prevention, detection and response in a sustainable operational model.
Context
Cloud security required controls distributed across multiple layers — identity, configuration, workloads, networking, logging and organizational governance. The challenge was connecting prevention, detection and response in a model that was operationally sustainable and compatible with the platform's evolution velocity.
Challenge
Integrate preventive, detective and operational controls in a sustainable model, reducing noise, maintaining operational context and transforming technical findings into risk-proportionate actions.
My role
- IAM, access policies, AWS Organizations and Service Control Policies
- GuardDuty, Inspector, AWS Config and configuration monitoring
- CrowdStrike, Orca Security and complementary security tooling
- Cloudflare and Imperva for edge and application protection
- Event analysis, incident investigation and troubleshooting
- Security, cloud engineering and operations integration
Architecture
The approach grouped controls across three complementary capabilities: prevent (controls that blocked risky actions before they occurred), detect (monitoring and detection of anomalous configurations and behavior) and respond (investigation, remediation and continuous improvement). Each capability operated with specific tooling, but integration between them was essential for effectiveness.
Technical decisions
- Security by Design from architecture — not as retrospective auditing
- Preventive controls applied at appropriate hierarchy levels
- Detective signals with operational context to reduce false positives
- Response supported by logs, investigation and automated remediation when possible
Security & governance
Prevent: IAM with least privilege, SCPs as guardrails, network controls and organizational policies. Detect: GuardDuty for threats, Inspector for workload vulnerabilities, Config for configuration compliance, and complementary tooling for broader visibility. Respond: structured logs, data-driven investigation, troubleshooting and remediation with action tracking.
Engineering challenges
The operational challenge was reducing alert noise, maintaining context across different tools and transforming technical findings into risk-proportionate actions. Security could not be an isolated layer — it needed to be integrated with engineering, understanding workload context and platform operational constraints.
Results
- More coherent security coverage across multiple accounts and layers
- Closer SecOps and Cloud Engineering integration
- Better investigation and continuous control evolution capacity
- Preventive controls reducing exposure surface before detection