Application & Cloud Security Engineer
Capital One
Aug 2025 - Current (1 year 1 month)
• Reduced misconfigurations 50% by embedding Terraform and CloudFormation checks into CI/CD pipelines, preventing insecure AWS and Azure deployments from reaching production. • Lowered privileged access exposure 40% by restructuring IAM and RBAC policies, enforcing least-privilege access across sensitive workloads. • Improved fraud detection and incident response 30% by correlating Splunk, CloudTrail, and KMS logs for real-time analysis. • Automated vulnerability scans in CI/CD pipelines, cutting manual review effort 25% and accelerating secure release cycles. • Strengthened encryption by enforcing AWS KMS and Azure Key Vault across critical data assets, ensuring PCI DSS compliance. • Reduced configuration drift 20% by securing infrastructu