Open to senior & advisory engagements

Hi, I’m Ushna.
I secure the cloud.

>

CISO at Athena Security Group, with 5+ years building hardened AWS / Azure / GCP infrastructure, leading SOC 2 programs, and shipping DevSecOps automation across Terraform, Kubernetes, and Python.

SCROLL

A bit about me.

Ushna Akram
Lahore, PK
UTC+5 · available

I’m a Chief Information Security Officer and AWS Certified DevSecOps Engineer with a degree in Software Engineering from Lancaster University, UK. I currently lead the security program at Athena Security Group, owning SOC 2 governance, risk management, audit evidence, and security oversight across AWS, GitHub, M365, and Defender/Intune.

Before stepping into the CISO seat, I spent 5+ years in the trenches as a DevSecOps Engineer — designing scalable cloud architectures on EKS, ECS, Lambda, and CloudFront, building auto-remediation systems with EventBridge + Lambda, and shipping CI/CD pipelines across Jenkins, GitHub Actions, CircleCI, and CodePipeline.

My happy place: Infrastructure as Code, security automation, and Python. When I’m not deploying, I’m traveling, hunting local food, or losing arguments with my cat.

0+
Years experience
0+
Projects shipped
0
Certifications
0
Major clouds

Tools in my arsenal.

☁️ Cloud

AWS Azure GCP Cloudflare GovCloud Lambda API Gateway CloudFront Cognito S3 DynamoDB Aurora

📦 Containers & Orchestration

Docker Kubernetes EKS ECS Fargate Helm Istio ArgoCD

🏗️ Infrastructure as Code

Terraform Terragrunt AWS CDK CDK-TF CloudFormation SAM Serverless Framework Packer

🔁 CI/CD & DevOps

GitHub Actions Jenkins CircleCI CodePipeline CodeBuild CloudDeploy Ansible Chef Puppet

🛡️ Security & Compliance

SOC 2 IAM SCPs GuardDuty SSM PagerDuty Defender/Intune Tailscale Netbox (IPAM) Well-Architected

📊 Observability

Datadog Grafana Prometheus CloudWatch Splunk New Relic ElasticSearch Kibana

💻 Languages

Python Golang TypeScript Bash YAML SQL

🤝 Collaboration

GitHub GitLab BitBucket JIRA Confluence Trello

Where I’ve shipped.

JUL 2025 — PRESENT
Chief Information Security Officer
@ Athena Security Group, LLC
Leading the company-wide information security program with full ownership of SOC 2 governance, policy, and audit readiness.
  • Own SOC 2 governance, risk management, and control coordination
  • Security oversight across AWS, GitHub, Microsoft 365, Defender/Intune
  • Partner with executive leadership, engineering, and SecOps
  • Drive controls across access mgmt, vuln mgmt, endpoint, backups, vendor risk
SOC 2AWSDefenderIntuneGRC
JAN 2024 — PRESENT
Senior DevSecOps Engineer (Freelance)
@ Upwork — multiple clients
Full-time freelance work delivering secure, scalable cloud platforms.
  • Auto-remediation lambdas for S3 PAB, SG drift, IAM misconfigs
  • SCPs blocking non-compliant resource creation (missing tags, public access)
  • Tracked SSO logins & Tailscale IPs, alerts on brute-force attempts
  • Daily / weekly / monthly cost reports per user
  • EventBridge + Lambda for org-wide API tracking with MSTeams/Slack/PagerDuty
  • GovCloud account provisioning via Terraform
TerraformAWS CDKEventBridgeLambdaEKSPython
2023 — 2024
Senior DevOps Engineer
@ Kaleidoscope
Data analytics & risk measurement company. Drove the platform’s DevOps maturity end-to-end.
  • Migrated CI/CD from GitLab → GitHub Actions
  • Terragrunt-based infra across multiple client environments
  • Built org-wide API call tracking solution
  • Enhanced existing Golang applications
  • AWS Cloud9 setups improving developer deployment velocity
TerragruntGitHub ActionsGolangArgoCDHelm
NOV 2019 — JUN 2023
DevOps Engineer / Python Developer
@ Enquizit, Inc. — AWS Premier Partner
3.5 years at an AWS Premier consulting partner, shipping cloud migration & modernization for clients across healthcare, e-commerce, and federal.
  • Migrated infrastructure from on-prem & other clouds → AWS
  • Containerized microservices (Docker, EKS, ECS Fargate)
  • Serverless apps with AWS Lambda (Python) & GCP Cloud Functions
  • IaC across CloudFormation, Terraform, and AWS CDK
  • Optimized healthcare app performance & built microservices automation
EKSECS FargateCloudFormationCDKPythonLambdaBigQuery

Things I’ve built.

# 01SOC 2

Athena Security Program

Athena Security Group · 2025–Present

Built the SOC 2 governance program from ground up. Security oversight across AWS infrastructure, GitHub, M365, and Defender/Intune. Risk management, control coordination, and audit evidence.

SOC 2AWSDefenderIntuneM365GitHub
# 02Auto-remediation

Cloud Auto-Remediation Platform

Freelance · 2024–Present

EventBridge + Lambda system that detects and auto-fixes security drift across AWS Org — re-enables S3 PAB, removes SSH-open SGs, blocks non-compliant creates via SCPs, and auto-tags missing resources.

EventBridgeLambdaSCPsTerraformPython
# 03Forensics

SSO Login Threat Detection

Freelance · 2024–Present

Tracks IPs of all SSO logins, alerts on failed-login bursts & brute force attempts, supports Tailscale IP tracking. Integrates with MSTeams, Slack, Google Chat, PagerDuty, and Azure for analysis.

EventBridgeLambdaTailscalePagerDutySlack
# 04FinOps

Per-User Cost Reporting

Freelance · 2024–Present

Daily / weekly / monthly cost reports for active AWS resources broken down per SSO user. Surfaces orphaned resources after user deletion. Reduced cloud spend through targeted optimization plays.

Cost ExplorerLambdaPythonQuickSight
# 05Platform

Kaleidoscope DevOps Platform

Kaleidoscope · 2023–2024

Migrated CI/CD from GitLab to GitHub Actions across all repos. Stood up Terragrunt-based infrastructure for multiple client environments and Cloud9 dev envs that boosted deployment velocity.

TerragruntGitHub ActionsCloud9ArgoCDGolang
# 06EKS

SkyMap

Enquizit · DevOps + Python

Built the AMI pipeline (Packer), multi-env CloudFormation, and CircleCI flow that ships microservices to ECS & EKS. APIs via Serverless Framework + Python Lambdas; internal ElasticSearch for dev logs.

PackerCloudFormationCircleCIEKSLambdaElasticSearch
# 07ECS

SkyTracker

Enquizit · DevOps Engineer

CloudFormation-driven multi-env setup with ACM SSL, multibuild Docker images, and a CircleCI pipeline pushing to ECS. MSSQL RDS backing for stateful workloads.

CloudFormationECSDockerCircleCIMSSQL RDS
# 08Migration

NEMSIS

National Emergency Medical Services Info System

Migrated a WordPress site from on-prem to AWS ECS Fargate. Multi-origin CloudFront (S3 + EFS), CloudFormation + Jenkins automation, and AWS SAM APIs over RDS MSSQL.

ECS FargateCloudFrontLambda@EdgeJenkinsSAM
# 09Serverless

Rebuild Ukraine

Enquizit · DevOps + Python

Serverless application on Aurora Serverless (Postgres) with Cognito-authenticated APIs. Frontend on private S3 behind CloudFront. Full PyTest coverage on Lambda business logic.

Aurora ServerlessAPI GatewayLambdaCognitoPyTest
# 10Landing Zone

iModal

Enquizit · Migration + DevOps

Stood up Landing Zone + Control Tower, migrated infra cross-account via CloudFormation, moved domain from GoDaddy → Route53. SES + Workmail wiring, DynamoDB for signup/contact, QuickSight dashboards.

Control TowerDynamoDBSAMSESQuickSightAthena
# 11800 servers

American Chemical Society (ACS)

Enquizit · Migration & DevOps

Discovery and cost analysis of 800 on-prem servers, then full migration to AWS. Broke a monolith into microservices, wrote Dockerfiles from scratch, and shipped on EKS with Cognito-auth APIs.

EKSDockerAPI GatewayCognitoServerless
# 12Multi-account

NBME — National Board of Medical Examiners

Enquizit · DevOps + Python

Automated CodePipeline with multibranch strategy deploying cross-account via Lambdas. SAM + CDK stacks, org-wide alarm manager, and secure S3-from-QuickSight delivery.

CodePipelineCDKSAMLambdaRedshiftQuickSight

Receipts & credentials.

🏆
AWS Certified DevOps Engineer
Professional · Amazon Web Services
🛠️
AWS Solutions Architect
Associate · Amazon Web Services
⚙️
AWS Certified Developer
Associate · Amazon Web Services
🌐
Google Cloud Associate Engineer
Google Cloud
☸️
Certified Kubernetes Application Developer (CKAD)
Cloud Native Computing Foundation

Or just talk to my terminal.

guest@ushna.akram: ~
Tip: try help, whoami, projects, sudo hire-me, or matrix. Arrow keys for history, Tab to autocomplete.

Build something secure together.

Got a cloud security problem?

Whether you need a SOC 2 readiness sprint, hardened AWS infra, DevSecOps automation, or a Kubernetes platform that doesn’t page you at 3am — let’s talk.

 ushna.akram1@gmail.com