$ whoami

Nur Azhar

Principal Security Infrastructure & DevSecOps Consultant

MAS TRM · ISO 27001 · CSA CyberTrust — Evidence as Code for Regulated Enterprises

I help security & engineering leaders in Singapore regulated enterprises turn MAS TRM / ISO 27001 obligations into deterministic CI/CD gates — CyberArk/Entra ID governance, OPA/Rego checks, PDPA-safe pipelines. Entry point: fixed-scope 2–4 week readiness sprint (scoped proposal first). Also open to fractional and select full-time strategic roles.

SG-Based · For Regulated-Enterprise Security & Engineering LeadersCSA CyberTrust Mark (Promoter Tier) DeliveredFixed-Scope Entry: 2–4 Week TRM/ISO Readiness Sprint — Scoped Proposal First

Singapore-based · Open to remote/APAC work subject to written employer and legal approval

Identity work that travels

01

Compliance-as-Code & Pipeline Automation

Deterministic static analysis engines (`pdpa-sg-clj`, `aur-audit`) built in Clojure/Babashka, enforcing automated security gates directly within CI/CD pipelines.

02

Enterprise IAM/PAM & Infrastructure Governance

Privileged Access Management (CyberArk v10.x PSM proxying, CPM rotation, Safe policies), Enterprise RBAC (Active Directory / Entra ID), and Database Activity Monitoring (IBM Guardium DAM).

03

Information Security Management Systems (ISMS)

Executed end-to-end ISMS deployment resulting in CSA CyberTrust Mark certification (Promoter Tier) across 7 Annex A domain baselines.

Engagement Models

For regulated-enterprise Sec/Eng leaders — advisory, fixed-scope readiness sprint, or full-time strategic hire. Every sprint starts with a written scoped proposal.

01

Fractional DevSecOps & Identity Architect

Continuous guidance on MAS TRM, CyberArk/Entra ID governance, and pipeline security gates. Outcome: audit-ready evidence, not slideware.

02

Project-Based Audit & Automation

Entry point for regulated teams: TRM/ISO 27001 readiness check → OPA/Rego gates + compliance-as-code engine. Scope agreed in writing before kickoff.

03

Specialist Technical Advisory

AI agentic security architecture reviews, PII pipeline guardrails, and zero-dependency tooling design.

Research & Architecture

Agentic AI Security

Determined control patterns and security architecture for systems where untrusted data can influence model context, tool selection, and runtime execution.

View the research ↗

Research & Engineering

Immutable Agent Evidence

daglog — an append-only DAG flight recorder for AI agent runs: SHA-256 chained, Ed25519-signed, PDPA-scrubbable. Zero-token replay and run diffs prove what an agent actually did.

Read the field report ↗

Production Security Controls & Tooling Frameworks

Auditable, scriptable tools that turn identity and compliance controls into inspectable evidence.

idira-audit-clj

Zero-Dependency Identity Security Audit CLI — SCIM/OAuth2 API auditing engine executing deterministic evaluations for orphaned privileges, dormant credentials, and MFA policy drift.

Outcome: evidence-ready access reviews that cut audit prep from weeks to hours.

github ↗
identity-policy-as-code

Policy-as-Code Security Gate — OPA/Rego deny-sets enforcing least-privilege IAM controls over normalized Terraform execution plans in CI/CD.

Outcome: least-privilege enforced pre-deploy; blocks risky IAM before it ships.

github ↗
security-tools

Deterministic Clojure/Babashka security automation toolkit — six zero-dependency assistants for vulnerability prioritization, findings triage, access classification, policy tickets, and IAM job matching. 50 tests, 175 assertions.

Outcome: repeatable SecOps workflow with no vendor lock-in.

github ↗
pdpa-sg-clj

Singapore PDPA compliance-as-code toolkit — NRIC Mod-11 static scanning, PII redaction, 11-obligation checklist, and policy templates. Ripgrep-backed, built for AI agents.

Outcome: PDPA-safe pipelines and AI data flows that pass regulatory review.

github ↗
aur-audit

AUR supply-chain static-analysis scanner — 9 IoC rules (obfuscation, outbound calls, persistence) plus BPF/systemd host-state checks. 17 tests, 42 assertions.

Outcome: catches malicious packages pre-install.

github ↗
mcpf-adapter

Babashka CLI for Singapore MyCareersFuture listings — scrape, filter, keywordise, cache, and export structured JSONL or SQLite data.

Outcome: structured labour-market data for hiring and career analytics.

github ↗

Research & Writing

Selected deep-dives on security automation, compliance pipelines, and systems architecture. Full archive of 196 posts on the archive page.

Engineering Case Study: Fault-Tolerant Telemetry in Agentic Execution Pipelines

I shipped a flight recorder for AI agent runs yesterday and preached immutable DAGs on this blog. Today my job bot attached it for its first real flight — and the recorder itself crashed four times. Every crash taught something a unit test would have missed.

Architectural Patterns: Multi-Tiered State Storage for Immutable Systems

Traditional agent frameworks serialize giant state dictionaries on every step. An immutable DAG engine splits storage into three layers — HAMT pointers in RAM, content-addressed blobs on disk, and a replay proxy store — and last night I built layer two for real.

Building pdpa-sg-clj — A Clojure/Babashka Scanner Library With NRIC Mod-11 and ripgrep NDJSON

Deep-dive into the architecture of pdpa-sg-clj — how it uses Babashka, ripgrep NDJSON, and the Singapore NRIC Mod-11 checksum algorithm to build a fast, correct PII scanner library.

Six Security Automation Tools in Babashka: A Zero-Dependency Monorepo

How I built six security automation assistants as a babashka monorepo with pure functions, a self-contained CSV parser, and 175 assertions of golden tests — zero external dependencies, zero linter warnings, zero bugs.

I Made My Blog Discoverable by AI Agents — llms.txt, Content-Type, and the Agent Discovery Flow

How I implemented the llmstxt.org standard on nurazhar.com — dynamic llms.txt generation, proper Content-Type headers, and an agent discovery flow that lets AI agents navigate 191 articles without scraping.

Inquiries, Consulting Scopes & Strategic Roles

For SG regulated-enterprise security & engineering leaders: start with a fixed-scope 2–4 week TRM/ISO readiness sprint (scoped proposal first). Also open to fractional advisory and select full-time leadership roles in Singapore and APAC. Direct contact: