Portfolio / 2026

CloudSecurityEngineer.

— 7.5 years / 3 clouds / enterprise IAM

I secure and operate multi-cloud environments across AWS, Azure and GCP — with a specialism in enterprise IAM & identity governance.

Currently running — Tech Intelligence: automated ingestion, scoring and summarisation across nine cloud and DevOps sources, every six hours. [ View → ]

Madan Aritakula, Cloud Security Engineer
AWS SA — Professional
AWS
Azure
GCP
Terraform
Kubernetes
Entra ID
IAM
Rapid7
Vanta
GitHub Enterprise
Lambda
Control Tower
SSO / SAML
SCIM
GuardDuty
SIEM
Ansible
CloudFormation
AWS
Azure
GCP
Terraform
Kubernetes
Entra ID
IAM
Rapid7
Vanta
GitHub Enterprise
Lambda
Control Tower
SSO / SAML
SCIM
GuardDuty
SIEM
Ansible
CloudFormation
AWS
Azure
GCP
Terraform
Kubernetes
Entra ID
IAM
Rapid7
Vanta
GitHub Enterprise
Lambda
Control Tower
SSO / SAML
SCIM
GuardDuty
SIEM
Ansible
CloudFormation
AWS
Azure
GCP
Terraform
Kubernetes
Entra ID
IAM
Rapid7
Vanta
GitHub Enterprise
Lambda
Control Tower
SSO / SAML
SCIM
GuardDuty
SIEM
Ansible
CloudFormation
01.
About

Who is
Madan.

I secure and operate enterprise cloud platforms end-to-end — across AWS, Microsoft Entra ID and Google Cloud — with a specialism in identity governance and posture management.

The differentiator is range: I move fluently between IAM design (SSO / SAML / SCIM, Conditional Access) and the infrastructure layer that IAM ultimately protects — landing zones, Terraform, incident automation, certificate lifecycle.

I replace manual review with scripted controls. Real examples: an access-governance audit across 30+ GitHub orgs, a multi-region SNS→Lambda→Jira incident pipeline, org-level GCP deny policies.

AWS Solutions Architect — Professional. Currently pursuing CKA, AWS DevOps Professional and Terraform Associate.

7.5+
Years
3
Clouds
30+
GitHub orgs audited
3
AWS regions automated
02.
Stack

The
Toolkit.

01 / 05

Cloud Platforms

AWSIAMEC2 / VPCLambdaECS / FargateACMOrganizationsControl TowerMicrosoft AzureEntra IDGoogle CloudGKEOrg PoliciesAudit Logs
02 / 05

IAM & Access

SSO / SAMLSCIM provisioningConditional AccessMFA enforcementLeast-privilege reviewsEnterprise IAM governanceCross-account roles
03 / 05

Security & Compliance

Rapid7 InsightCloudSecVantaDevo SIEMAWS Security HubGuardDutyAWS ConfigSSL / TLS lifecyclePKCS#7 / ACM DNSSOC 2 support
04 / 05

Automation & IaC

TerraformOpenTofuSpaceliftAnsibleCloudFormationGitHub ActionsJenkinsPowerShellBash
05 / 05

Containers & DevOps

DockerKubernetesGKEECS / FargateCI/CD pipelinesDrift detectionObserve OPAL
03.
Credentials

Certified
& proven.

AWS-SAP
Professional

AWS Certified Solutions Architect

Amazon Web Services
AWS-SAA
Associate

AWS Certified Solutions Architect

Amazon Web Services
In progress
CKACertified Kubernetes Administrator
DOP-PAWS DevOps Engineer — Professional
TF-AHashiCorp Terraform Associate
04.
Timeline

Where I’ve
shipped.

05 /May 2025 — Present

Jaggaer

Cloud Security Engineer — Cloud Security Architecture & Engineering (CSAE)
Hyderabad, India
  • Led an enterprise-wide GitHub access-governance audit across 30+ organizations using PowerShell and the GitHub CLI, removing dormant accounts and tightening least-privilege posture.
  • Owned enterprise SSO/SAML lifecycle with Microsoft Entra ID for multiple SaaS platforms; repaired expired SCIM provisioning for Atlassian Cloud and resolved Conditional Access conflicts.
  • Engineered an end-to-end production incident pipeline (SNS → Lambda → Jira webhooks) linking Aurora CloudWatch alarms to Jira across three AWS regions, cutting manual triage.
  • Designed and enforced GCP deny-org policies restricting service-quota increases, paired with a custom service-account audit script for ongoing governance.
  • Managed SSL/TLS certificate lifecycle end-to-end — CSR generation, ACM DNS validation, PKCS#7/P7B conversions, and customer-facing renewal coordination.
04 /Jul 2024 — May 2025

Insight Direct India

Cloud Engineer III
  • Implemented AWS Landing Zone and Control Tower for enterprise customers, including Service Control Policies across the Control Tower estate.
  • Delivered security baselines using AWS Security Hub, GuardDuty and Config across customer environments.
  • Automated provisioning and drift detection with Terraform, CloudFormation and Ansible — including reverse-engineering existing resources into IaC.
03 /Jan 2022 — Jul 2024

Minfy Technologies

Cloud Ops Engineer
  • Provided 24/7 L1/L2/L3 oversight for cloud incident response, owning support end-to-end from client through every escalation level.
  • Managed, configured and resolved AWS security alerts across production and non-production environments.
  • Drove modern DevOps practices through automation and infrastructure-as-code.
  • Built out Azure infrastructure for internal environments as part of operational acceptance.
Service operations
Core Service Management — change, incident, problem, monitoring & maintenance for 3 core applications/Platform, application and network monitoring/OS patching, backup monitoring/restoration and regular DR / application-recovery testing/Process documentation, monitoring and high-availability solutions
Recognition & Awards
Recognized by Minfy Co-Founder for outstanding contribution to customer success and exemplifying core cultural values — Jan 2024
Awarded for exceptional performance, enduring commitment, and consistently going the extra mile — by Minfy Co-Founder & Sr. Director
02 /Aug 2021 — Dec 2021

TechGrit

Software Engineer
  • Provided 24/7 production support across AWS and Linux environments.
  • Managed AWS EC2 — instances, EBS volumes, AMI backups, volume snapshots and resizing.
  • Configured Security Groups and ELBs for high availability and controlled inbound/outbound traffic.
  • Managed IAM users/policies and S3 bucket access controls.
  • Administered Linux — LVM partitioning, disk management and scheduled automation.
01 /Jul 2019 — Aug 2021

NTT Cloud

IOC Analyst
  • Provided 24/7 production support for Linux and virtualization environments.
  • Implemented online backup and restore using snapshot technology; scheduled daily / weekly / monthly backups.
  • Administered and monitored system performance, disk space and memory.
  • Managed users, groups and access levels.
  • Troubleshot issues across support teams for rapid resolution.
05.
Selected work

Signal
over noise.

REPEATGITHUB ENTERPRISE(30+ ORGS)POWERSHELL +GITHUB CLI COLLECTORDORMANT-ACCOUNTDETECTIONREMEDIATIONRECURRINGACCESS REVIEW
P.01
30+ organizations · PowerShell + GitHub CLI

GitHub Access-Governance Audit

Enterprise-wide audit of user access across 30+ GitHub organizations. Automated dormant-account detection and remediation; established a repeatable access-review process for ongoing governance.

Result: dormant accounts removed across 30+ organizations, with a repeatable access-review process now in place. [[METRIC: accounts removed / users reviewed]]

IAMPowerShellGitHub
AURORA CLOUDWATCHALARMS (3 REGIONS)SNS TOPICLAMBDA HANDLERJIRA WEBHOOKTRACKED INCIDENT
P.02
AWS · SNS → Lambda → Jira

Multi-Region Incident Automation

Designed and deployed an SNS → Lambda → Jira webhook pipeline across three AWS regions to convert Aurora production alarms into tracked incidents automatically — replacing manual triage.

Result: Aurora production alarms become tracked Jira incidents automatically across three AWS regions. [[METRIC: triage time saved / alarm volume]]

AWSLambdaObservability
GCP ORGANIZATIONDENY POLICIES(SERVICE-QUOTA)FOLDERS / PROJECTSSERVICE-ACCOUNTAUDIT SCRIPTPOSTURE FINDINGS
P.03
Google Cloud · Deny-Org policies

GCP Org-Level Governance

Rolled out organization-level deny policies restricting service-quota increases, backed by a custom audit script that continuously reviews service-account posture across the estate.

Result: organization-wide deny policies on service-quota increases, backed by continuous service-account posture auditing. [[METRIC: projects covered / findings raised]]

GCPGovernanceAudit
06.
Signal feed

Tech
Intelligence.

A production intelligence pipeline I built and run. It ingests official release and security feeds from nine cloud and DevOps sources, deduplicates and enriches each item with AI, scores it against my technology profile, and surfaces only what warrants action.

Open dashboard
Source adapters
Nine providers behind one adapter interface — RSS, Atom and JSON Feed
Ingestion
Scheduled every 6 hours, conditional GET (ETag / Last-Modified), deduplicated
Enrichment
AI summary, impact assessment and recommended action per item
Scoring
AI-scored relevance and severity, ranked by a fixed weighting tuned to my technology profile
Delivery
Cached read path — no external fetch at page render
07.
Let’s talk

Get in
touch.

01 /
02 /
03 /
04 /
Reply within 24h · IST
Madan.Aritakula
Cloud Security Engineer · Multi-Cloud
© 2026 — Designed & engineered by Madan.
Built with React · Tailwind · Framer Motion · Lenis