$ whoami

Nur Azhar

Cloud IAM & DevSecOps Security Automation Specialist

ISO 27001 · Identity Governance — Deterministic CI/CD Security Gates for Regulated Enterprises

I help security & engineering leaders in Singapore regulated enterprises turn ISO 27001 and identity governance controls into deterministic, automated CI/CD security gates — Cloud IAM (Entra ID, Okta, Cloudflare Edge Security & WAF), CyberArk PAM, OPA/Rego least-privilege policies, and compliance-as-code pipelines.

SG-Based · For Regulated-Enterprise Security & Engineering LeadersCSA CyberTrust Mark (Promoter Tier) DeliveredCloud IAM · DevSecOps Automation · Regulated ISMS Execution

Singapore-based · Remote & APAC Cloud IAM, Identity Governance & DevSecOps Security Automation

Identity work that travels

01

Compliance-as-Code & Pipeline Automation

Deterministic static analysis engines (`pdpa-sg-clj`, `aur-audit`) built in Clojure/Babashka, enforcing automated security gates directly within CI/CD pipelines.

02

Enterprise IAM/PAM & Infrastructure Governance

Enterprise PAM & Identity Security (CyberArk PAM / Entra ID Governance, OPA/Rego least-privilege policies), Enterprise RBAC (Active Directory / Entra ID), and Database Activity Monitoring (IBM Guardium DAM).

03

Information Security Management Systems (ISMS)

Executed end-to-end ISMS deployment resulting in CSA CyberTrust Mark certification (Promoter Tier) across 7 Annex A domain baselines.

Technical Expertise & Engineering Focus Areas

Three engineering disciplines, one operating principle: controls that execute in the pipeline, with evidence to prove it.

01

Cloud IAM & Identity Governance

Entra ID · OPA/Rego least-privilege · SCIM/OAuth2 auditing

Least-privilege IAM enforced as code: Entra ID governance, OPA/Rego deny-sets over Terraform plans, and deterministic SCIM/OAuth2 access audits — orphaned privileges, dormant credentials, and MFA drift surfaced as evidence.

02

DevSecOps & Security Automation

CI/CD security gates · compliance-as-code · Clojure/Babashka tooling

ISO 27001 and identity governance controls compiled into deterministic, automated CI/CD gates — auditable CLI security engines that block risky change pre-deploy instead of documenting it post-incident.

03

Regulated ISMS & Framework Compliance

ISO 27001 · CSA CyberTrust Mark execution

End-to-end ISMS execution that produced CSA CyberTrust Mark certification (Promoter Tier) across 7 Annex A domain baselines — control implementation with evidence, not slideware.

Research & Architecture

Agentic AI Security

Determined control patterns and security architecture for systems where untrusted data can influence model context, tool selection, and runtime execution.

View the research ↗

Research & Engineering

Immutable Agent Evidence

daglog — an append-only DAG flight recorder for AI agent runs: SHA-256 chained, Ed25519-signed, PDPA-scrubbable. Zero-token replay and run diffs prove what an agent actually did.

Read the field report ↗

Production Security Controls & Tooling Frameworks

Auditable, deterministic CLI security engines built for CI/CD pipeline integration.

pam-audit-clj

Identity Security Audit CLI — SCIM/OAuth2 API auditing engine executing deterministic evaluations for orphaned privileges, dormant credentials, and MFA policy drift.

Outcome: evidence-ready access reviews that cut audit prep from weeks to hours.

github ↗
identity-policy-as-code

Policy-as-Code Security Gate — OPA/Rego deny-sets enforcing least-privilege IAM controls over normalized Terraform execution plans in CI/CD.

Outcome: least-privilege enforced pre-deploy; blocks risky IAM before it ships.

github ↗
security-tools

Deterministic CLI security engine — six auditable assistants for vulnerability prioritization, findings triage, access classification, policy tickets, and IAM job matching. 50 tests, 175 assertions, built for CI/CD pipeline integration.

Outcome: repeatable SecOps workflow with no vendor lock-in.

github ↗
pdpa-sg-clj

Singapore PDPA compliance-as-code toolkit — NRIC Mod-11 static scanning, PII redaction, 11-obligation checklist, and policy templates. Ripgrep-backed, built for AI agents.

Outcome: PDPA-safe pipelines and AI data flows that pass regulatory review.

github ↗
bridge-gate-clj

CyberArk + Tenable policy gate enforcing compliance-as-code, automated access controls, and vulnerability policy checks in CI/CD.

Outcome: privileged access and vulnerability policy enforced pre-deploy.

github ↗
tui

Passkey-gated identity proxy and personal production gateway enforcing strict OIDC passkey authentication and allow-list execution.

Outcome: phishing-resistant access with allow-list execution.

github ↗

Research & Writing

Selected deep-dives on security automation, compliance pipelines, and systems architecture. Full archive of 203 posts on the archive page.

Case Study: Implementing Deterministic Telemetry & Flight Recorders for Agentic Execution Pipelines

Case study on implementing deterministic telemetry and flight recorders for agentic execution pipelines: immutable DAG evidence, SHA-256-chained runs, and four failure modes caught by dogfooding before production.

Architectural Patterns: Multi-Tiered State Storage for Immutable Systems

Traditional agent frameworks serialize giant state dictionaries on every step. An immutable DAG engine splits storage into three layers — HAMT pointers in RAM, content-addressed blobs on disk, and a replay proxy store — and last night I built layer two for real.

Building pdpa-sg-clj — A Clojure/Babashka Scanner Library With NRIC Mod-11 and ripgrep NDJSON

Deep-dive into the architecture of pdpa-sg-clj — how it uses Babashka, ripgrep NDJSON, and the Singapore NRIC Mod-11 checksum algorithm to build a fast, correct PII scanner library.

Six Security Automation Tools in Babashka: A Modular Security Automation Monorepo

How I built six security automation assistants as a babashka monorepo with pure functions, a self-contained CSV parser, and 175 assertions of golden tests — zero external dependencies, zero linter warnings, zero bugs.

I Made My Blog Discoverable by AI Agents — llms.txt, Content-Type, and the Agent Discovery Flow

How I implemented the llmstxt.org standard on nurazhar.com — dynamic llms.txt generation, proper Content-Type headers, and an agent discovery flow that lets AI agents navigate 191 articles without scraping.

Open Source & Strategic Roles

Explore the open-source security automation repositories, or reach out about strategic Cloud IAM & security automation roles in Singapore and APAC. Direct contact: