Skip to content
View Nisha318's full-sized avatar

Block or report Nisha318

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Nisha318/README.md

Hi, I'm Nisha πŸ‘‹

Cloud Security Engineer | DevSecOps | GRC Automation

I build security controls as code. My work sits at the intersection of cloud engineering and compliance automation: translating NIST 800-53 controls into working infrastructure, designing DevSecOps pipelines that catch vulnerabilities before deployment, and architecting secure systems in AWS and Azure environments.

Currently a Cloud Engineer at ManTech, supporting cloud-hosted systems in complex compliance environments. CISSP | AWS Solutions Architect Associate | AWS Security Specialty (in progress)

πŸ”— LinkedIn | πŸ“ Blog | 🌐 Portfolio


🎯 What I'm Working On

  • 🐳 From Docker to EKS: A Security-First Progression β€” Container security portfolio project building from Docker through EKS, with Trivy scanning, OpenTofu IaC, and NIST 800-53 control mapping
  • πŸ”¬ Compliance-as-Code Builder Session β€” Developing a hands-on lab for the GRC Engineering Club covering Terraform and Checkov in an audit-ready CI/CD pipeline
  • πŸŽ“ AWS Certified Security – Specialty β€” Active exam prep

πŸ’Ό Core Competencies

Cloud Engineering & Security Architecture

  • AWS Security (VPC, IAM, Config, CloudTrail, GuardDuty, Security Hub)
  • Infrastructure as Code (OpenTofu, Terraform, CloudFormation)
  • Container Security (Docker, Kubernetes, ECR, Trivy scanning)
  • CI/CD Security Integration (GitHub Actions, OIDC, security gates)

GRC & Compliance Engineering

  • NIST 800-53 Control Implementation and Automation
  • RMF/ATO Process (FISMA, FedRAMP)
  • Vulnerability Management (Tenable/ACAS, automated remediation, POA&M)
  • eMASS Authorization Workflows
  • Compliance-as-Code (Checkov, policy-to-code translation)

DevSecOps

  • SAST/SCA pipeline integration (Semgrep, Gitleaks, NJSScan)
  • Secrets scanning and pre-commit enforcement
  • DefectDojo vulnerability tracking and triage
  • Python/boto3 automation and Lambda-based remediation

πŸš€ Featured Projects

Container Security

Project Stack Description
From Docker to EKS: A Security-First Progression Docker, EKS, Trivy, OpenTofu, GitHub Actions Stage-by-stage container security build from local Docker through managed Kubernetes, with NIST 800-53 mapping at each layer
Container Security Scanning Pipeline Trivy, GitHub Actions Automated image scanning with CVE reporting and policy enforcement gates

DevSecOps Pipelines

Project Stack Description
Application Vulnerability Scanning Pipeline Semgrep, Gitleaks, NJSScan, DefectDojo, GitHub Actions Multi-tool SAST and secrets scanning pipeline with pre-commit hooks and DefectDojo integration; maps to NIST 800-53
Terraform Flask Lab OpenTofu, Flask, GitHub Actions OIDC, S3 backend Flask on AWS EC2 via OpenTofu with OIDC-based CI/CD, remote state, and NIST 800-53 control mapping

Cloud Security Automation

βš™οΈ AWS Config Auto-Remediation

  • Lambda-based security group remediation
  • CloudWatch Events for real-time response
  • NIST 800-53 SC-7 control automation
  • View Project β†’

πŸ” Azure AD + AWS SAML SSO Federation

  • Cross-cloud identity federation
  • SAML trust policy configuration
  • Troubleshooting and debugging methodology
  • View Project β†’

πŸ—οΈ 3-Tier AWS VPC with Terraform

  • Production-grade network architecture
  • Security group automation and least privilege
  • Multi-AZ resilient design
  • View Project β†’

🌐 Zero Trust Network Architecture

  • Azure Firewall policy automation
  • Micro-segmentation implementation
  • Site-to-Site VPN configurations
  • View Project β†’

Vulnerability & Compliance Management

Threat Detection & Security Operations

Offensive Security & Red Team


πŸ› οΈ Technology Stack

Cloud Platforms AWS Azure

Infrastructure & Automation OpenTofu Terraform Docker Kubernetes GitHub Actions

Security & Scanning Tools Trivy Checkov Semgrep Splunk Tenable

Programming & Scripting Python Bash PowerShell

DevSecOps Git Linux DefectDojo


πŸ“œ Certifications

  • CISSP β€” Certified Information Systems Security Professional
  • AWS Solutions Architect Associate
  • Azure Administrator Associate (AZ-104)
  • Azure Network Engineer Associate (AZ-700)
  • GDSA β€” GIAC Defendable Security Architecture
  • CompTIA Security+
  • 🎯 In progress: AWS Certified Security – Specialty

πŸŽ“ Community

  • πŸ’‘ GRC Engineering Club β€” Member and active participant in builder sessions
  • 🀝 WiCyS β€” Active mentor in the Professional Mentorship Program
  • πŸ’¬ Black Tech Network Texas β€” Facebook group moderator
  • πŸ” Digital Defense Foundation β€” Cybersecurity group moderator

πŸ“Š GitHub Stats

Nisha's GitHub stats


πŸ“« Let's Connect

I'm always interested in talking through cloud security engineering, compliance automation, and DevSecOps pipeline design. Reach out any time.

LinkedIn Blog GitHub


"The goal is not just to pass the audit. The goal is to build systems that deserve to pass it."

Popular repositories Loading

  1. config-auto-revoke-sg config-auto-revoke-sg Public

    Automated AWS security compliance project built with Infrastructure as Code (IaC) using CloudFormation, AWS Config, Lambda, and Systems Manager. Detects and remediates non-compliant security groups…

    Python 5 1

  2. Splunk-Projects Splunk-Projects Public

    2

  3. Terraform-Azure-Configs Terraform-Azure-Configs Public

    Terraform Configuration Files for Azure

    HCL 1

  4. Terraform-Modules Terraform-Modules Public

    HCL 1 1

  5. origin origin Public

  6. prep_basics prep_basics Public

    Forked from vikingeducation/prep_basics

    The repo students will push to as part of the final project in the Web Development Basics (http://vikingcodeschool.com/web-development-basics) unit of the prep curriculum