I build and ship security controls in public: an AWS IAM blast-radius analyzer with a live tool, a Pulumi IAM library with safe defaults, and a threat-model addendum for the case where the operator is the adversary.
Current role (private org work under @oliveratprimer, low public signal): AWS and EKS hardening in production, EDR and cloud threat detection operations, and compliance requirements mapped into policy-as-code in CI/CD.
secure-iam-lint- Client-side AWS IAM policy blast-radius analyzer (fail-closed, zero-backend); powers the live tool at rivassec.com/tools/iam-blast-radius. 📝 Testing an IAM Analyzer Against Its Own Claimsiam-safe-defaults- Pulumi component library for AWS IAM with safe defaults that fail loud: mandatory permissions boundary, no wildcard trust, every opt-out explicit. 📝 IAM Roles That Fail Loudweaponization-threat-model- One-page addendum to STRIDE/LINDDUN/PASTA for modeling the legitimate operator as the adversary. 📝 Applied in When Telemetry Turns Predatorydevsecops-notes- Source for rivassec.com: Pelican with link-check, accessibility (pa11y), and gitleaks CI.- Smaller and archival:
cf-token-links(token-scoped redirects),elasticsearch-tools(least-privilege snapshot verification),efi-bruteforce(2013 Teensy EFI research, featured on Hackaday).
📄 Writing - rivassec.com
Start here: Testing an IAM Analyzer Against Its Own Claims. Latest:
- When Telemetry Turns Predatory: A DevSecOps Look at Digital Repression in Venezuela
- Testing an IAM Analyzer Against Its Own Claims
- The DevSecOps Guide: Hardening, IAM, and Incident Response
Controls that fail closed.



