Salman Tabrez
Cloud Security Architect
Designing secure, scalable, high-performance cloud systems in AWS, GCP, and Azure — specializing in CI/CD, Kubernetes, and Zero Trust architectures.
View ProjectsAbout Me
I’m a Cloud Security Engineer and Architect with a passion for building secure, scalable, and resilient cloud infrastructures. My approach blends deep technical expertise with a strategic mindset rooted in security-first architecture, aligning with principles like Defense-in-Depth, Zero Trust, Shift-Left, and Secure-by-Design.
I specialize in architecting enterprise solutions across AWS, Azure, and GCP, embedding security from design through deployment. My work reflects a strong command of granular IAM, network segmentation, policy-as-code, and least privilege access — enabling cloud-native environments that are secure by default and scalable by design.
I’ve led initiatives that reduced attack surfaces, automated compliance, and elevated observability through optimized EDR tuning and intelligent SIEM correlation. I advocate for separation of duties and believe in enabling engineering teams with secure CI/CD pipelines that don’t trade off agility for protection.
Beyond implementation, I take pride in mentoring and enabling others — transforming security from a gatekeeper into a business enabler. Whether it’s tuning a WAF, deploying IaC with Terraform, hardening containers with K8s policies, or educating teams on application threat modeling, I bring clarity, coordination, and leadership to every engagement.
Tools & Expertise
Featured Projects
AWS EKS Secure Deployment
Implemented Kubernetes RBAC, Network Policies, image scanning pipeline, EKS hardening.
GCP Infrastructure Hardening
Baseline guardrails for GCP using Terraform: logging, segmentation, secure factory.
GCP Secure CI/CD Pipeline
Automated DevSecOps pipeline: SAST, DAST, IaC scanning, artifact promotion.
Terraform GitOps Pipelines
Automated Terraform plan, OPA policy check, apply pipelines using GitHub Actions.
AppSec & API Threat Modeling
Threat modeling for microservices: SAST, DAST, API security tests.
Secure SDLC Program
Secure SDLC: developer training, secure code review, threat modeling.