Skip to content
View vanhoangkha's full-sized avatar
πŸ’­
I may be slow to respond.
πŸ’­
I may be slow to respond.

Block or report vanhoangkha

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
VanHoangKha/README.md

Kha Van Hoang | Senior Cloud Security Engineer | AWS | Azure | GCP

Cloud Security Architect | Zero Trust | CNAPP | IAM | SIEM | Multi-Cloud Security

Architecting Zero Trust Security for Enterprise Multi-Cloud Environments

LinkedIn Email AWS Community Viet AWS

Profile Views GitHub followers GitHub Stars


πŸ‘¨β€πŸ’» About Me | Cloud Security Engineer | Cybersecurity Expert

Senior Cloud Security Engineer specializing in Zero Trust Architecture, Cloud-Native Application Protection (CNAPP), and identity-first security for enterprise multi-cloud environments. Expert in designing and implementing comprehensive cloud security solutions across AWS (Amazon Web Services), Microsoft Azure, Google Cloud Platform (GCP), Huawei Cloud, and Yandex Cloud.

10+ years of experience in cloud security architecture, cybersecurity, IAM (Identity and Access Management), SIEM (Security Information and Event Management), and incident response for enterprise organizations.

My approach integrates defense-in-depth security across all layersβ€”identity security, network security, workload protection, and threat detectionβ€”ensuring robust prevention, detection, response, and governance aligned with enterprise risk management and compliance frameworks (ISO 27001, SOC 2, NIST, CIS).

πŸ” Core Competencies | Cloud Security Skills | Technical Expertise

Cloud Security Architecture | CNAPP | Zero Trust

  • CNAPP (Cloud-Native Application Protection Platform) - Wiz, Prisma Cloud, Aqua Security
  • IAM (Identity and Access Management) - AWS IAM, Azure AD, Google Cloud IAM, Okta
  • ZTNA (Zero Trust Network Access) - Zscaler, Cloudflare Access, Palo Alto Prisma Access
  • PAM (Privileged Access Management) - CyberArk, BeyondTrust, HashiCorp Vault
  • CIEM (Cloud Infrastructure Entitlement Management) - Ermetic, Sonrai, CloudKnox

Security Operations | SOC | SIEM | Threat Detection

  • SIEM implementation and optimization - Splunk, Elastic Security, Microsoft Sentinel, Chronicle
  • Log correlation and analysis - CloudWatch, Azure Monitor, Google Cloud Logging
  • Threat hunting and intelligence - MITRE ATT&CK, threat modeling, IOC analysis
  • Incident response and forensics - IR playbooks, digital forensics, root cause analysis
  • Security automation and orchestration - SOAR, Lambda, Azure Functions, Cloud Functions

Multi-Cloud Security | AWS | Azure | GCP | Hybrid Cloud

  • Cross-cloud security posture management - CSPM, cloud security benchmarks
  • Network security and microsegmentation - VPC, NSG, firewall rules, service mesh
  • Data protection and encryption - KMS, encryption at rest/in transit, DLP
  • Workload security and runtime protection - container security, Kubernetes security, serverless security
  • Compliance and governance frameworks - ISO 27001, SOC 2, NIST CSF, CIS Benchmarks, GDPR, PCI DSS

🌟 Community Leadership | AWS Community | Cloud Training | Mentorship

Co-Founder, Viet AWS | AWS Community Leader | Cloud Security Advocate

Dedicated to advancing cloud computing and cybersecurity expertise in Vietnam through:

  • Technical training and workshops - AWS, Azure, GCP security best practices
  • Mentorship programs for emerging cloud security professionals and engineers
  • Community-driven knowledge sharing - meetups, webinars, technical talks
  • Advocacy for security best practices - DevSecOps, shift-left security, cloud security posture

Speaking & Training Topics:

  • Zero Trust Architecture Implementation
  • Cloud Security Posture Management (CSPM)
  • Multi-Cloud IAM Strategy
  • SIEM and Threat Detection in Cloud
  • Container and Kubernetes Security
  • Cloud Compliance and Governance

Technical Focus

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  Prevention  β†’  Detection  β†’  Response  β†’  Governance   β”‚
β”‚                                                          β”‚
β”‚  Identity Layer    ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━  β”‚
β”‚  Network Layer     ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━  β”‚
β”‚  Workload Layer    ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━  β”‚
β”‚  Detection Layer   ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ“Š GitHub Stats

GitHub Stats

Top Languages

GitHub Streak

πŸ› οΈ Technology Stack

Cloud Platforms

AWS Azure GCP

Security Tools

Splunk Wiz CrowdStrike Palo Alto

Infrastructure as Code

Terraform CloudFormation Ansible

Container & Orchestration

Docker Kubernetes ECS

Programming & Scripting

Python Bash PowerShell Go

πŸ’Ό Let's Connect | Collaboration | Speaking Opportunities

I'm always interested in discussing:

  • Cloud security architecture and design patterns
  • Zero Trust implementation strategies
  • Multi-cloud security challenges and solutions
  • DevSecOps and security automation
  • Community initiatives and knowledge sharing
  • Speaking opportunities at conferences and meetups
  • Technical consulting and advisory

Open to:

  • Technical collaboration on cloud security projects
  • Speaking engagements (conferences, webinars, podcasts)
  • Mentorship and career guidance
  • Open source security tool contributions

Building resilient cloud infrastructure | Empowering the next generation of security professionals

Keywords: Cloud Security Engineer, AWS Security, Azure Security, GCP Security, Zero Trust, CNAPP, IAM, SIEM, SOC, Cybersecurity, Multi-Cloud, DevSecOps, Cloud Architecture, Security Operations, Threat Detection, Incident Response, Compliance, Vietnam, AWS Community

Pinned Loading

  1. aws-samples/AWS-First-GenAI-Journey aws-samples/AWS-First-GenAI-Journey Public

    Welcome to the AWS First Generative AI Journey repository! This project serves as a comprehensive resource for individuals and organizations looking to explore the transformative capabilities of Ge…

    Jupyter Notebook 370 51