Mathesh M E
I'm a security engineer working across AWS and Kubernetes. Mostly I review cloud infrastructure for security gaps and write policy as code so those checks run automatically, and I also build tools along the way.
Experience
- One of the primary reviewers for org-wide security group requests, checking each team's network access against the architecture and least privilege, prioritized by risk.
- Contributed security configurations to shared Terraform modules, mainly for EKS.
- Built policy-as-code auto-remediation with Cloud Custodian, running organization-wide.
- Manage the infrastructure hosting Wiz Outpost, the scanning component of our Wiz CSPM: maintain its IaC across CRDs and Helm charts, and automate EKS patching across regions.
- Handled the org-wide review and remediation of stale IAM users, both unused access keys and inactive accounts.
- Work directly with application teams on cloud security issues in their accounts, through to remediation.
- Built detect-and-notify policy-as-code checks, later expanded into the organization-wide auto-remediation.
- Containerized an internal application from source using Docker multi-stage builds.
- Evaluated secrets-detection tools for Terraform code.
Selected work
-
WharfEyeGo
Container metrics, security auditing, and performance recommendations across Docker, Podman, and containerd.
-
SCP ValidatorPython
Tests AWS CLI commands against service control policies and shows the full evaluation trace.
-
Terraform architectures, AWS cost tooling, and public study guides for CKA and CKS.
Skills
Writing
I write about cloud, Kubernetes, and security, usually something I just worked through, mostly on Medium.
Contact
If you work on security or infrastructure, or you found something of mine worth picking apart, reach out at hello@mathesh.dev.