Static site on S3, CloudFront & OAC
The page you're reading. Private S3 origin behind CloudFront with Origin Access Control, ACM certificate with DNS validation, Route 53 alias records, HTTP/3. The bucket itself returns Access Denied — by design.
Warsaw · Network Security → Cloud Security
Network security analyst with a firewall-review background — Palo Alto, Check Point, Tufin — now building toward cloud security engineering on AWS. I learn by building: everything below runs, or ran, on hardware and accounts I administer myself.
I work in network security at a global payments company, reviewing and analysing firewall estates day to day — rule hygiene, policy violations, and change review across Palo Alto Panorama and Tufin. Before that: SOC analysis in the same organisation, and network engineering at Cisco.
The through-line is that I like knowing how things actually work, which is why my spare time goes into a home lab rather than more slideware: virtual firewalls on Proxmox, a segmented Meraki network, offensive practice on Hack The Box, and — currently front and centre — hands-on AWS, working toward Solutions Architect Associate with Security Specialty as the longer-term target.
The direction of travel is cloud security engineering: identity, guardrails, detection, and the parts of AWS where a firewall background turns out to be a surprisingly good map.
The page you're reading. Private S3 origin behind CloudFront with Origin Access Control, ACM certificate with DNS validation, Route 53 alias records, HTTP/3. The bucket itself returns Access Denied — by design.
A lab writeup on how over-broad iam:PassRole grants let a low-privileged principal hand a high-privileged role to a service it controls — and the policy patterns that prevent it.
Palo Alto VM deployed on a Proxmox node inside a segmented Meraki network (separate lab, AD, and management VLANs). Used for policy testing, packet-level debugging, and mirroring what I review professionally, at home, with root.
Ongoing
A staged build from first principles: packet capture and Bash tooling first, Suricata next, custom C utilities later. The point is to earn each layer of the detection stack rather than install it.
In progress