Skip to content
View Nisha318's full-sized avatar

Block or report Nisha318

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Nisha318/README.md

Hi, I'm Nisha πŸ‘‹

Cloud Security Engineer | GRC Engineering | Security Automation

I'm a cybersecurity professional specializing in bridging compliance frameworks with cloud security automation. I build security controls as code, automate vulnerability remediation, and implement policy-driven security architectures in AWS and Azure environments.

Currently: Senior Cyber Security Engineer supporting cloud-hosted systems | CISSP | AWS Solutions Architect Associate

πŸ”— LinkedIn | πŸ“ Technical Blog | πŸ“š Personal Page


🎯 What I'm Working On

  • πŸ” Building container security scanning pipelines with GitHub Actions & Trivy
  • ☁️ Implementing AWS Config auto-remediation for security group misconfigurations
  • πŸŽ“ Studying for AWS Security Specialty certification
  • 🌱 Exploring policy-as-code with OPA and compliance automation frameworks

πŸ’Ό Core Competencies

Cloud Security & Automation

  • AWS Security Architecture (VPC, IAM, Config, CloudTrail, GuardDuty)
  • Infrastructure as Code (Terraform, CloudFormation)
  • Container Security (Docker, Kubernetes, ECR scanning)
  • CI/CD Security Integration (GitHub Actions, security gates)

GRC & Compliance Engineering

  • RMF/ATO Process (NIST 800-53, FISMA, FedRAMP)
  • Vulnerability Management (Tenable Nessus, ACAS, automated remediation)
  • eMASS Authorization Workflows
  • Policy-to-Code Translation (compliance automation)

Security Operations

  • SIEM Analytics (Splunk, Azure Sentinel)
  • Network Security (Zero Trust, micro-segmentation, firewalls)
  • Threat Detection & Incident Response
  • Penetration Testing & Red Team Operations

πŸš€ Featured Projects

Cloud Security Automation

πŸ” Container Security Scanning Pipeline

  • Automated Trivy scanning in GitHub Actions
  • Vulnerability reporting & CVE tracking
  • Policy enforcement for production deployments
  • View Project β†’

βš™οΈ AWS Config Auto-Remediation

  • Lambda-based security group remediation
  • CloudWatch Events for real-time response
  • NIST 800-53 SC-7 control automation
  • View Project β†’

πŸ—οΈ 3-Tier AWS VPC with Terraform

  • Production-grade network architecture
  • Security group automation & least privilege
  • Multi-AZ resilient design
  • View Project β†’

🌐 Zero Trust Network Architecture

  • Azure Firewall policy automation
  • Micro-segmentation implementation
  • Site-to-Site VPN configurations
  • View Project β†’

Infrastructure as Code (IaC)

Project Technology Stack Description
Terraform AWS Configs Terraform, AWS, GitOps Automated dev environment provisioning with security controls
Terraform Azure Configs Terraform, Azure, ARM Azure infrastructure deployment with compliance baselines
AWS Security Projects AWS, Python, Lambda Security automation and serverless architectures
Azure Security Projects Azure, PowerShell, Sentinel Cloud security monitoring and SIEM integration

Vulnerability & Compliance Management

Threat Detection & Security Operations

Offensive Security & Red Team

Network Security (NIST 800-53 SC-7)


πŸ› οΈ Technology Stack

Cloud Platforms
AWS Azure

Infrastructure & Automation
Terraform Docker Kubernetes GitHub Actions

Security Tools
Splunk Tenable Nessus

Programming & Scripting
Python Bash PowerShell

DevSecOps
Git Linux Trivy


πŸ“œ Certifications

  • CISSP - Certified Information Systems Security Professional
  • AWS Solutions Architect Associate
  • GDSA - GIAC Defendable Security Architecture
  • CompTIA Security+ (Instructor)
  • 🎯 Currently studying: AWS Certified Security - Specialty

πŸŽ“ Community Involvement

  • πŸ‘©β€πŸ« CompTIA Security+ Study Group - Teaching exam prep courses
  • 🀝 WiCyS Professional Mentorship Program - Active mentor
  • πŸ’‘ GRC Engineering Club - Member & contributor
  • πŸ” DevSec Blueprint Community - Technical participant

πŸ“Š GitHub Stats

Nisha's GitHub stats


πŸ“« Let's Connect

I'm always interested in discussing cloud security automation, GRC engineering practices, and building security controls as code. Feel free to reach out!

LinkedIn Medium GitHub


"Building bridges between compliance frameworks and cloud security automation, one Terraform module at a time."

Popular repositories Loading

  1. config-auto-revoke-sg config-auto-revoke-sg Public

    Automated AWS security compliance project built with Infrastructure as Code (IaC) using CloudFormation, AWS Config, Lambda, and Systems Manager. Detects and remediates non-compliant security groups…

    Python 4 1

  2. Terraform-Azure-Configs Terraform-Azure-Configs Public

    Terraform Configuration Files for Azure

    HCL 1

  3. Terraform-Modules Terraform-Modules Public

    HCL 1 1

  4. Splunk-Projects Splunk-Projects Public

    1

  5. origin origin Public

  6. prep_basics prep_basics Public

    Forked from vikingeducation/prep_basics

    The repo students will push to as part of the final project in the Web Development Basics (http://vikingcodeschool.com/web-development-basics) unit of the prep curriculum