Skip to content
View rivassec's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report rivassec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
rivassec/README.md

Staff Security Engineer - Cloud & Platform Security

I build and ship security controls in public: an AWS IAM blast-radius analyzer with a live tool, a Pulumi IAM library with safe defaults, and a threat-model addendum for the case where the operator is the adversary.

Current role (private org work under @oliveratprimer, low public signal): AWS and EKS hardening in production, EDR and cloud threat detection operations, and compliance requirements mapped into policy-as-code in CI/CD.


🛠 Projects


📄 Writing - rivassec.com

Start here: Testing an IAM Analyzer Against Its Own Claims. Latest:


Controls that fail closed.

Pinned Loading

  1. secure-iam-lint secure-iam-lint Public

    Client-side AWS IAM policy blast-radius analyzer (fail-closed). Web tool live; headless CLI + SARIF + GitHub Action in progress.

    JavaScript 2

  2. devsecops-notes devsecops-notes Public

    Source for rivassec.com — Pelican blog on infrastructure security, cloud hardening, Kubernetes, and IAM. CI: link checks, accessibility (pa11y), gitleaks.

    JavaScript

  3. iam-safe-defaults iam-safe-defaults Public

    Pulumi component library for AWS IAM roles and policies with safe defaults that fail loud

    Python

  4. weaponization-threat-model weaponization-threat-model Public

    A one-page addendum to standard threat-modeling frameworks (STRIDE, LINDDUN, PASTA) for modeling the case where the legitimate operator of the system becomes the adversary.

  5. efi-bruteforce efi-bruteforce Public

    Automates EFI password input using Teensy-based USB HID brute-force

    C++ 4 1