Infrastructure and Application Security

IT Security Challenges in Modern IT

Infrastructure and application architectures are becoming increasingly complex. Modern environments consist of a mix of SaaS, PaaS, IaaS, and public and private cloud infrastructure. Software is a mix of closed and open-source components, developed by both external and internal parties.

The attack surface of modern applications often extends beyond direct organizational control. Despite advances in tooling and automation, human error remains the most significant security risk. Security relates to almost everything — from end-user behavior to database queries.

My Experience

I have worked with organizations where security is the highest priority, as well as with teams that focus primarily on time-to-market. Balancing these priorities is often challenging.

Automation, observability, and robust security tooling play a key role in achieving this balance. Equally important are clear documentation and effective knowledge sharing. The human factor can only be addressed through awareness, standardization, and by removing guesswork from day-to-day IT operations.

What I Can Do for You

  • Perform technical security audits of cloud and/or application environments
  • Improve team processes and operational practices to reduce risk
  • Implement cloud security best practices and least-privilege IAM
  • Review and help remediate penetration test findings
  • Strengthen web environments using WAF and/or security-enhanced CDN
  • Design and implement Kubernetes security tooling (Aqua Security, Red Hat ACS, Sysdig)
  • Enhance Kubernetes cluster security through service mesh encryption (Istio, Cilium)