Salman Tabrez

Cloud Security Architect

Designing secure, scalable, high-performance cloud systems in AWS, GCP, and Azure — specializing in CI/CD, Kubernetes, and Zero Trust architectures.

View Projects

About Me

I’m a Cloud Security Engineer and Architect with a passion for building secure, scalable, and resilient cloud infrastructures. My approach blends deep technical expertise with a strategic mindset rooted in security-first architecture, aligning with principles like Defense-in-Depth, Zero Trust, Shift-Left, and Secure-by-Design.

I specialize in architecting enterprise solutions across AWS, Azure, and GCP, embedding security from design through deployment. My work reflects a strong command of granular IAM, network segmentation, policy-as-code, and least privilege access — enabling cloud-native environments that are secure by default and scalable by design.

I’ve led initiatives that reduced attack surfaces, automated compliance, and elevated observability through optimized EDR tuning and intelligent SIEM correlation. I advocate for separation of duties and believe in enabling engineering teams with secure CI/CD pipelines that don’t trade off agility for protection.

Beyond implementation, I take pride in mentoring and enabling others — transforming security from a gatekeeper into a business enabler. Whether it’s tuning a WAF, deploying IaC with Terraform, hardening containers with K8s policies, or educating teams on application threat modeling, I bring clarity, coordination, and leadership to every engagement.

Featured Projects

AWS EKS Secure Deployment

Implemented Kubernetes RBAC, Network Policies, image scanning pipeline, EKS hardening.

GCP Infrastructure Hardening

Baseline guardrails for GCP using Terraform: logging, segmentation, secure factory.

GCP Secure CI/CD Pipeline

Automated DevSecOps pipeline: SAST, DAST, IaC scanning, artifact promotion.

Terraform GitOps Pipelines

Automated Terraform plan, OPA policy check, apply pipelines using GitHub Actions.

AppSec & API Threat Modeling

Threat modeling for microservices: SAST, DAST, API security tests.

Secure SDLC Program

Secure SDLC: developer training, secure code review, threat modeling.

Contact Me