Results-driven Cloud Security Expert with a risk-aware mindset and strong advocacy for shift-left practices. Demonstrated success in driving a multi-year reduction in engineering-controlled security incidents through proactive controls, secure defaults, early-stage enforcement, training and awareness. Expert in securing AWS environments using Infrastructure as Code, with a focus on automation, compliance, and zero-trust design. Maintains a personal cloud infrastructure portfolio at custoscloud.com, fully automated and managed through Terraform, showcasing practical implementation of cloud security and infrastructure-as-code best practices.
Professional Experience
Senior SecOps Engineer
May 2020 - Present
Sentiance, Belgium
Hardened the CI/CD pipeline to defend against software supply chain threats by integrating static analysis, SBOM generation, and container image scanning into the build process. Enforced mandatory checks for all projects and blocked vulnerable images from reaching Amazon ECR, resulting in nearly 650% growth in security coverage and eliminating known critical vulnerabilities to reach production.
Implemented infrastructure-as-code security checks in the CI pipeline to detect misconfigurations early in the development phase. This shift-left control helped reduce cloud security risks by preventing insecure infrastructure definitions from progressing to deployment.
Architected and deployed secure cloud infrastructure using Infrastructure as Code (Terraform, Ansible)
Reduced engineering-controlled security incidents by ~79% over four years
Maintained a robust RBAC and ABAC-based access control strategy, significantly reducing the risk of unauthorized access across environments by enforcing least privilege and dynamic, attribute-driven permissions.
Enhanced active threat monitoring capabilities by leveraging observability tools and custom Python scripting to detect anomalies, automate alerting, and reduce incident response time.
Conducted regular disaster recovery exercises to validate recovery procedures, ensure business continuity, and maintain compliance with organizational policies and resilience objectives.
Conducted frequent security assessments covering user access, threat monitoring, and endpoint protection to ensure continuous alignment with security policies, minimize risk exposure, and proactively identify control gaps.
Professional Services Engineer / InfoSec Consultant
Mar 2019 - Mar 2020
Bulwarx, Israel
Installed and integrated Forcepoint security solutions, ensuring seamless operation and alignment with customer infrastructure.
Tailored and customized security policies for email, web and data protection based on customer needs and compliance.
Provided on-site technical support, troubleshooting, and IT staff training on managing and maintaining solutions.
Assisted with updates, patch management, and security incidents, offering root cause analysis and remediation.
Prepared detailed documentation for implementation, ensuring clear post-deployment management and performance optimization.
Technical Support Engineer
Mar 2017 - Feb 2019
Check Point Software Technologies, Israel
Recommended architectural improvements, design, and integration solutions.
Diagnosed and resolved complex networking issues related to firewalls, including IPsec VPNs, NAT, and routing.
Monitored firewall performance, conducted health checks, and recommended upgrades to optimize system resources.
Acted as a point of escalation for critical OS and network issues, collaborating with teams for timely resolutions.
Guided customers through OS patching, firmware updates, and upgrades while creating and maintaining documentation and best practices.
IT Support Technician
Aug 2016 - Mar 2017
Migdal Insurance Company, Israel
Provided technical support to end-users, troubleshooting hardware and software issues, and resolving network connectivity problems.
Installed, configured, and maintained desktops, laptops, printers, and other peripherals.
Installed and configured software applications, performed updates, and ensured compatibility with existing systems.
Diagnosed and resolved network connectivity issues, including LAN, WAN, and VPN problems.
Created and updated documentation for IT procedures, user guides, and troubleshooting steps.
Certifications
AWS Certified Security Specialty
Certified Cloud Security Professional (CCSP)
Check Point Certified Security Expert (CCSE)
Check Point Certified Security Administrator (CCSA)
Certified Forcepoint DLP Administrator
Certified Forcepoint Web Security Administrator
Education
Sela College - Diploma - Cyber Operations and Warfare