# Nur Azhar — Systems & Security Automation Engineer > Senior Systems & Security Automation Engineer specializing in SG enterprise and government-adjacent infrastructure: compliance-as-code, identity governance (CyberArk PAM), and ISO 27001 / CSA CyberTrust Mark ISMS delivery. 186 research posts on nurazhar.com. Systems & Security Automation Engineer with a focus on zero-dependency security tooling, Clojure/Babashka CLI development, enterprise privileged access management, and complete ISMS framework implementation. Publishes deep-dive research and open-source tools for engineers who build, audit, and harden systems. ## Identity - **Role:** Systems & Security Automation Engineer - **Domain:** Systems Architecture, Compliance-as-Code, Identity Governance & PAM, ISMS / Security Frameworks - **Locale:** Singapore — SG enterprise and government-sector infrastructure ## Verified Proof Points - **security-tools** — deterministic security automation toolkit (Clojure/Babashka): 50 tests, 175 assertions; six zero-dependency assistants for vuln prioritization, findings triage, access classification, policy tickets, IAM job matching - **pdpa-sg-clj** — Singapore PDPA compliance-as-code toolkit: NRIC Mod-11 static scanning, PII redaction, 11-obligation checklist, six policy templates; used to audit all 186 posts on this site - **aur-audit** — AUR supply-chain static-analysis scanner: 9 IoC rules plus BPF/systemd host-state checks, 17 tests / 42 assertions; built for the June 2026 AUR malware campaign - **mcpf-adapter** — Babashka CLI for Singapore MyCareersFuture listings: scrape, filter, keywordise, cache, JSONL/SQLite export - **CyberTrust Mark delivered** — drove a government-sector organisation to CSA CyberTrust Mark (Promoter Tier) certification; executed the consultant-designed ISMS across 7 Annex A control domains - **ISO 27001** — Annex A control implementation across 7 control domains ## Open-Source Repositories - [security-tools](https://github.com/nurazhardotcom/security-tools): Clojure/Babashka security automation toolkit - [pdpa-sg-clj](https://github.com/nurazhardotcom/pdpa-sg-clj): Singapore PDPA compliance-as-code toolkit - [aur-audit](https://github.com/nurazhardotcom/aur-audit): AUR supply-chain static-analysis scanner - [mcpf-adapter](https://github.com/nurazhardotcom/mcpf-adapter): MyCareersFuture job data CLI ## Technical Stack Clojure, Babashka, GraalVM, Hiccup, Linux (Arch/CachyOS), bash/fish scripting, CyberArk PAM, Active Directory / Entra ID, IBM Guardium, ISO 27001, CSA CyberTrust Mark, Cloudflare Pages, GitLab CI ## Skills (Installable) - [pdpa-sg-clj](https://nurazhar.com/skills/pdpa-sg-clj/SKILL.md): agent skill for running PDPA/secret scans — `npx skills add nurazhardotcom/homepage --skill pdpa-sg-clj` - [aur-audit](https://nurazhar.com/skills/aur-audit/SKILL.md): agent skill for supply-chain build-script auditing — `npx skills add nurazhardotcom/homepage --skill aur-audit` ## Getting Started - [Homepage](https://nurazhar.com/): portfolio, focus areas, and featured tools. - [Archive](https://nurazhar.com/archive.html): complete post list (186 articles). - [Agentic AI Security](https://nurazhar.com/agentic-ai-security.html): active research and architecture covering prompt injection, RAG trust boundaries, MCP tool integrity, and contained execution. - [Full Index](https://nurazhar.com/llms-full.txt): every article with descriptions. - [RSS Feed](https://nurazhar.com/feed.xml): subscribe for updates. ## Recent Posts - [I Built an Evergreen Job-Ad Detector for MyCareersFuture](https://nurazhar.com/mcf-evergreen-job-ad-detector.html): A deterministic detector for reposted "evergreen" job ads on MyCareersFuture — timestamps and hashes as evidence, no accusations needed. - [What Stripe Radar Teaches About Money-as-Code — A Security Engineer's Translation](https://nurazhar.com/stripe-solved-money-as-code-fintech-transition.html): What Stripe Radar rules can teach security engineers about explicit payment controls, and where the analogy to OPA/Rego stops. - [3X Productivity, Not 10X — Measuring AI-Augmented Work Honestly](https://nurazhar.com/productivity-measurement-honest-3x-not-10x.html): A session-level accounting of AI-assisted work that separates generation, review, waiting, and context switching instead of treating model time as total productivity. - [Why I Replaced 200 Lines of Babashka with 35 Lines of Rego](https://nurazhar.com/rego-replaces-clojure-iam.html): How declarative IAM validation using OPA/Rego replaced imperative Clojure security checks — and why functional programmers already understand policy engines. - [Money is More Than a Database Row — Security Lessons from Financial Systems](https://nurazhar.com/money-is-code-security-finance-translation.html): A security-focused explanation of why financial systems need authorization, auditability, and controlled state transitions in addition to database storage. - [Your Idea Already Exists — It's Called "Logic Programming for Security"](https://nurazhar.com/logic-programming-for-security.html): Why functional programmers are naturally drawn to security policy engines — and how declarative policy ideas are used in modern infrastructure. - [The Missing Link: Why Clojure Developers Should Care About Policy Engines](https://nurazhar.com/clojure-policy-engines.html): How functional programming meets infrastructure security — and how Clojure skills can transfer to policy-as-code work. - [Cognitive Asymmetry: The Epistemic Bandwidth Bottleneck](https://nurazhar.com/cognitive-asymmetry-epistemic-bandwidth.html): The divide in the agent era is no longer hardware access but epistemic bandwidth — the capacity to build abstractions and query reasoning engines. ## Topics - [clojure (34 posts)](https://nurazhar.com/tag-clojure.html) - [security (30 posts)](https://nurazhar.com/tag-security.html) - [ai (30 posts)](https://nurazhar.com/tag-ai.html) - [architecture (29 posts)](https://nurazhar.com/tag-architecture.html) - [infrastructure (27 posts)](https://nurazhar.com/tag-infrastructure.html) - [devops (25 posts)](https://nurazhar.com/tag-devops.html) - [babashka (25 posts)](https://nurazhar.com/tag-babashka.html) - [automation (22 posts)](https://nurazhar.com/tag-automation.html) - [llm (18 posts)](https://nurazhar.com/tag-llm.html) - [networking (18 posts)](https://nurazhar.com/tag-networking.html) - [cachyos (17 posts)](https://nurazhar.com/tag-cachyos.html) - [agile (16 posts)](https://nurazhar.com/tag-agile.html) ## For AI Agents - This file is at `/llms.txt` per the [llmstxt.org](https://llmstxt.org) standard. - All links are absolute URLs — agents can follow them without reconstructing paths. - Content-Type: `text/plain; charset=utf-8` - `/llms-full.txt` contains every post with descriptions for deeper context. - `/sitemap.xml` lists all URLs for crawling. - `/feed.xml` provides RSS for feed readers. ## Optional - [PDPA Compliance](https://github.com/nurazhardotcom/pdpa-sg-clj): Singapore PDPA toolkit used to scan posts.