I'm Tarandeep (Taran) Singh, an AWS Certified Security Specialty engineer who secures cloud platforms from the first commit.
I set up least-privilege access, threat detection, encryption, and compliance controls, and I build security checks into CI/CD so problems are caught before they ship.
Open to full-time, contract, and freelance work. Based in Toronto and available anywhere in Canada: remote, hybrid, or on-site.
Least-privilege IAM roles and policies, Kubernetes and Azure RBAC, and IAM Access Analyzer to find anything shared outside the account.
Threat detection
GuardDuty, Security Hub with the AWS best practices and CIS benchmarks, AWS Config rules, and CloudTrail in every region, with alerts for serious findings.
Data and network protection
KMS encryption with key rotation, Secrets Manager and Key Vault, AWS WAF, and tightly scoped security groups.
Compliance
Access controls, audit trails, and security monitoring for SOC 2 and HIPAA environments, plus AWS Landing Zone Accelerator guardrails for new accounts.
DevSecOps
Snyk, SonarQube, and Checkov as pipeline gates, so a build fails on critical vulnerabilities, static analysis findings, or insecure infrastructure code.
The platform this website runs on: a k3s cluster in my home with GitOps delivery, zero-trust ingress, live observability, self-hosted analytics, and a cloud fallback.
Serves this site live; commit to production in minutes, full rebuild from git with one command
Zero open ports through Cloudflare Tunnel. Prometheus, Argo CD and analytics are private behind NetworkPolicies, RBAC is least-privilege, and secrets live in git only as SealedSecrets.