about
Clyde
I'm Clyde, a senior platform security engineer based in Lisbon. I've spent more than 10 years in security, most of them on cloud, DevSecOps and Kubernetes security across AWS, GCP and Azure, with a focus on the technology sector. This blog is where I explore how to secure agentic AI systems, build small proofs of concept and write down what I learn.
Experience
Over the past decade I've worked in security engineering for technology companies, including several years at Amazon Web Services helping customers secure their cloud platforms.
- Cloud and Kubernetes security: hardening, admission control, runtime policy and zero-trust networking.
- Identity and access: least privilege, just-in-time access and identity across AWS, GCP and Azure.
- DevSecOps: security built into delivery pipelines, infrastructure as code and policy as code.
- Detection and response: centralised logging, SIEM integration and threat modelling.
What I work on
Cloud and containers
- AWS
- GCP
- Azure
- Kubernetes (EKS, GKE, AKS)
AI security
- agent gateways
- MCP
- guardrails
- threat modelling
Identity
- OIDC
- OAuth2
- SAML
- least privilege
- just-in-time access
Platform and delivery
- Terraform
- GitOps (Flux CD, Argo CD)
- CI/CD
- policy as code (OPA, Kyverno)
Detection and response
- SIEM
- runtime protection
- cloud security posture management
Standards
- NIST CSF
- NIST 800-53
- CIS benchmarks
- ISO 27002
- PCI DSS
Background
- AWS Certified Security – Specialty
- Certified Kubernetes Administrator (CKA)
- Certified Kubernetes Security Specialist (CKS)
- HashiCorp Terraform Associate
About this site
This is a personal project built in my own time. Everything here reflects my own views and is not affiliated with or endorsed by any employer. The code is open source and comes with no warranty.
Get in touch
Find me on GitHub or LinkedIn, or use the contact page.