Compliance-as-Code & Pipeline Automation
Deterministic static analysis engines (`pdpa-sg-clj`, `aur-audit`) built in Clojure/Babashka, enforcing automated security gates directly within CI/CD pipelines.
$ whoami
Principal Security Infrastructure & DevSecOps Consultant
MAS TRM · ISO 27001 · CSA CyberTrust — Evidence as Code for Regulated Enterprises
I help security & engineering leaders in Singapore regulated enterprises turn MAS TRM / ISO 27001 obligations into deterministic CI/CD gates — CyberArk/Entra ID governance, OPA/Rego checks, PDPA-safe pipelines. Entry point: fixed-scope 2–4 week readiness sprint (scoped proposal first). Also open to fractional and select full-time strategic roles.
Singapore-based · Open to remote/APAC work subject to written employer and legal approval
Deterministic static analysis engines (`pdpa-sg-clj`, `aur-audit`) built in Clojure/Babashka, enforcing automated security gates directly within CI/CD pipelines.
Privileged Access Management (CyberArk v10.x PSM proxying, CPM rotation, Safe policies), Enterprise RBAC (Active Directory / Entra ID), and Database Activity Monitoring (IBM Guardium DAM).
Executed end-to-end ISMS deployment resulting in CSA CyberTrust Mark certification (Promoter Tier) across 7 Annex A domain baselines.
For regulated-enterprise Sec/Eng leaders — advisory, fixed-scope readiness sprint, or full-time strategic hire. Every sprint starts with a written scoped proposal.
Continuous guidance on MAS TRM, CyberArk/Entra ID governance, and pipeline security gates. Outcome: audit-ready evidence, not slideware.
Entry point for regulated teams: TRM/ISO 27001 readiness check → OPA/Rego gates + compliance-as-code engine. Scope agreed in writing before kickoff.
AI agentic security architecture reviews, PII pipeline guardrails, and zero-dependency tooling design.
Research & Architecture
Determined control patterns and security architecture for systems where untrusted data can influence model context, tool selection, and runtime execution.
Research & Engineering
daglog — an append-only DAG flight recorder for AI agent runs: SHA-256 chained, Ed25519-signed, PDPA-scrubbable. Zero-token replay and run diffs prove what an agent actually did.
Auditable, scriptable tools that turn identity and compliance controls into inspectable evidence.
Zero-Dependency Identity Security Audit CLI — SCIM/OAuth2 API auditing engine executing deterministic evaluations for orphaned privileges, dormant credentials, and MFA policy drift.
Outcome: evidence-ready access reviews that cut audit prep from weeks to hours.
github ↗identity-policy-as-codePolicy-as-Code Security Gate — OPA/Rego deny-sets enforcing least-privilege IAM controls over normalized Terraform execution plans in CI/CD.
Outcome: least-privilege enforced pre-deploy; blocks risky IAM before it ships.
github ↗security-toolsDeterministic Clojure/Babashka security automation toolkit — six zero-dependency assistants for vulnerability prioritization, findings triage, access classification, policy tickets, and IAM job matching. 50 tests, 175 assertions.
Outcome: repeatable SecOps workflow with no vendor lock-in.
github ↗pdpa-sg-cljSingapore PDPA compliance-as-code toolkit — NRIC Mod-11 static scanning, PII redaction, 11-obligation checklist, and policy templates. Ripgrep-backed, built for AI agents.
Outcome: PDPA-safe pipelines and AI data flows that pass regulatory review.
github ↗aur-auditAUR supply-chain static-analysis scanner — 9 IoC rules (obfuscation, outbound calls, persistence) plus BPF/systemd host-state checks. 17 tests, 42 assertions.
Outcome: catches malicious packages pre-install.
github ↗mcpf-adapterBabashka CLI for Singapore MyCareersFuture listings — scrape, filter, keywordise, cache, and export structured JSONL or SQLite data.
Outcome: structured labour-market data for hiring and career analytics.
github ↗Selected deep-dives on security automation, compliance pipelines, and systems architecture. Full archive of 196 posts on the archive page.
I shipped a flight recorder for AI agent runs yesterday and preached immutable DAGs on this blog. Today my job bot attached it for its first real flight — and the recorder itself crashed four times. Every crash taught something a unit test would have missed.
Traditional agent frameworks serialize giant state dictionaries on every step. An immutable DAG engine splits storage into three layers — HAMT pointers in RAM, content-addressed blobs on disk, and a replay proxy store — and last night I built layer two for real.
Deep-dive into the architecture of pdpa-sg-clj — how it uses Babashka, ripgrep NDJSON, and the Singapore NRIC Mod-11 checksum algorithm to build a fast, correct PII scanner library.
How I built six security automation assistants as a babashka monorepo with pure functions, a self-contained CSV parser, and 175 assertions of golden tests — zero external dependencies, zero linter warnings, zero bugs.
How I implemented the llmstxt.org standard on nurazhar.com — dynamic llms.txt generation, proper Content-Type headers, and an agent discovery flow that lets AI agents navigate 191 articles without scraping.
For SG regulated-enterprise security & engineering leaders: start with a fixed-scope 2–4 week TRM/ISO readiness sprint (scoped proposal first). Also open to fractional advisory and select full-time leadership roles in Singapore and APAC. Direct contact: