Compliance-as-Code & Pipeline Automation
Deterministic static analysis engines (`pdpa-sg-clj`, `aur-audit`) built in Clojure/Babashka, enforcing automated security gates directly within CI/CD pipelines.
$ whoami
Cloud IAM & DevSecOps Security Automation Specialist
ISO 27001 · Identity Governance — Deterministic CI/CD Security Gates for Regulated Enterprises
I help security & engineering leaders in Singapore regulated enterprises turn ISO 27001 and identity governance controls into deterministic, automated CI/CD security gates — Cloud IAM (Entra ID, Okta, Cloudflare Edge Security & WAF), CyberArk PAM, OPA/Rego least-privilege policies, and compliance-as-code pipelines.
Singapore-based · Remote & APAC Cloud IAM, Identity Governance & DevSecOps Security Automation
Deterministic static analysis engines (`pdpa-sg-clj`, `aur-audit`) built in Clojure/Babashka, enforcing automated security gates directly within CI/CD pipelines.
Enterprise PAM & Identity Security (CyberArk PAM / Entra ID Governance, OPA/Rego least-privilege policies), Enterprise RBAC (Active Directory / Entra ID), and Database Activity Monitoring (IBM Guardium DAM).
Executed end-to-end ISMS deployment resulting in CSA CyberTrust Mark certification (Promoter Tier) across 7 Annex A domain baselines.
Three engineering disciplines, one operating principle: controls that execute in the pipeline, with evidence to prove it.
Least-privilege IAM enforced as code: Entra ID governance, OPA/Rego deny-sets over Terraform plans, and deterministic SCIM/OAuth2 access audits — orphaned privileges, dormant credentials, and MFA drift surfaced as evidence.
ISO 27001 and identity governance controls compiled into deterministic, automated CI/CD gates — auditable CLI security engines that block risky change pre-deploy instead of documenting it post-incident.
End-to-end ISMS execution that produced CSA CyberTrust Mark certification (Promoter Tier) across 7 Annex A domain baselines — control implementation with evidence, not slideware.
Research & Architecture
Determined control patterns and security architecture for systems where untrusted data can influence model context, tool selection, and runtime execution.
Research & Engineering
daglog — an append-only DAG flight recorder for AI agent runs: SHA-256 chained, Ed25519-signed, PDPA-scrubbable. Zero-token replay and run diffs prove what an agent actually did.
Auditable, deterministic CLI security engines built for CI/CD pipeline integration.
Identity Security Audit CLI — SCIM/OAuth2 API auditing engine executing deterministic evaluations for orphaned privileges, dormant credentials, and MFA policy drift.
Outcome: evidence-ready access reviews that cut audit prep from weeks to hours.
github ↗identity-policy-as-codePolicy-as-Code Security Gate — OPA/Rego deny-sets enforcing least-privilege IAM controls over normalized Terraform execution plans in CI/CD.
Outcome: least-privilege enforced pre-deploy; blocks risky IAM before it ships.
github ↗security-toolsDeterministic CLI security engine — six auditable assistants for vulnerability prioritization, findings triage, access classification, policy tickets, and IAM job matching. 50 tests, 175 assertions, built for CI/CD pipeline integration.
Outcome: repeatable SecOps workflow with no vendor lock-in.
github ↗pdpa-sg-cljSingapore PDPA compliance-as-code toolkit — NRIC Mod-11 static scanning, PII redaction, 11-obligation checklist, and policy templates. Ripgrep-backed, built for AI agents.
Outcome: PDPA-safe pipelines and AI data flows that pass regulatory review.
github ↗bridge-gate-cljCyberArk + Tenable policy gate enforcing compliance-as-code, automated access controls, and vulnerability policy checks in CI/CD.
Outcome: privileged access and vulnerability policy enforced pre-deploy.
github ↗tuiPasskey-gated identity proxy and personal production gateway enforcing strict OIDC passkey authentication and allow-list execution.
Outcome: phishing-resistant access with allow-list execution.
github ↗Selected deep-dives on security automation, compliance pipelines, and systems architecture. Full archive of 203 posts on the archive page.
Case study on implementing deterministic telemetry and flight recorders for agentic execution pipelines: immutable DAG evidence, SHA-256-chained runs, and four failure modes caught by dogfooding before production.
Traditional agent frameworks serialize giant state dictionaries on every step. An immutable DAG engine splits storage into three layers — HAMT pointers in RAM, content-addressed blobs on disk, and a replay proxy store — and last night I built layer two for real.
Deep-dive into the architecture of pdpa-sg-clj — how it uses Babashka, ripgrep NDJSON, and the Singapore NRIC Mod-11 checksum algorithm to build a fast, correct PII scanner library.
How I built six security automation assistants as a babashka monorepo with pure functions, a self-contained CSV parser, and 175 assertions of golden tests — zero external dependencies, zero linter warnings, zero bugs.
How I implemented the llmstxt.org standard on nurazhar.com — dynamic llms.txt generation, proper Content-Type headers, and an agent discovery flow that lets AI agents navigate 191 articles without scraping.
Explore the open-source security automation repositories, or reach out about strategic Cloud IAM & security automation roles in Singapore and APAC. Direct contact: