Skip to content
View tltaylor1's full-sized avatar

Sponsoring

@ankidroid
@pydantic
@pytest-dev

Highlights

  • Pro

Organizations

@manifest-identity

Block or report tltaylor1

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
tltaylor1/README.md
Terry Taylor, security engineer and architect: cloud security, identity, governance

Hi, I'm Terry 👋

Stylized portrait of Terry

I'm a security engineer and architect based in Seattle.

My background spans infrastructure, cloud platforms, identity, application security, automation, observability, and federal compliance. I've worked from Linux and network engineering through Azure and AWS architecture, spent time handling Severity-A cloud escalations at Microsoft, and have taken two organizations from Cybersecurity Maturity Model Certification (CMMC) gap assessment through successful certification.

A lot of my work sits where security architecture meets engineering: turning ambiguous requirements into systems, controls, automation, diagrams, and operating models that people can actually use.

This is also a relatively new GitHub for me. I recently retired an older account I'd had since 2016 that had accumulated a pretty random mix of projects over the years. This one is intentionally more focused on enterprise security, application security, cloud, identity, and security engineering.

The projects here explore things like:

  • Governed coding agents
  • Non-human identity
  • Infrastructure as code
  • Secure application design
  • Policy enforcement
  • Evidence and the engineering practices behind security controls

Across these projects are implementation plans, architecture decisions, rejected alternatives, automated tests, security controls, failure records, and the checks added afterward.

I build primarily with Python, Terraform, Bicep, PowerShell, cloud-native services, and whatever else is useful for making security repeatable.

Please take a look at the work and if you like any of it please consider awarding a ⭐ and let me know!


Start Here

Flagship: manifest-identity

An application for reviewing who has access to what across an organization's cloud accounts and directories.

  • It holds a record of what access each identity is allowed to have, written by a named person, with an owner and an expiry.
  • It imports what AWS, Entra, Okta, Active Directory, and other providers already export, and builds an inventory of every identity and the access it holds.
  • It shows every difference between the two and runs review campaigns that put each one in front of the person responsible for it.
  • It never changes anything in the systems it reads, and it holds no provider credential.

How it is checked. Every change reaches main through a pull request that cannot merge until its checks pass. The checks sweep the full history for secrets, run every test under a coverage floor, remove security controls one at a time and confirm a named test fails for each, audit the dependencies, and scan the container image.

OpenSSF Scorecard OpenSSF Best Practices Coverage

After it, read these in order. The first is the rules both applications are built under, the second is a smaller application, and the third is the platform they will run on.

Project What it is
build-doctrine The rules and checks used to govern AI-assisted development across the repositories.
secure-expense-mvp A small application used to exercise application-security controls end to end.
control-plane The AWS estate the applications will run on, defined as code. The design is written and implementation has not started.

Looking for Something Specific?

Identity and access governance. Start with manifest-identity, then read its architecture, security model, decisions, and build gates.

Application security. Start with secure-expense-mvp, then read its architecture, design decisions, testing, and security in the development lifecycle sections.

AI-assisted software development. Start with build-doctrine, then read its standards, enforcement, coverage, and decisions.

Cloud security reference material. Start with aws-azure-security-mapping.

Platform engineering. Start with control-plane.


More Projects

Project What it is
sample-diagrams Architecture and process diagrams covering systems, trust boundaries, data flows, security controls, operational workflows, and cross-team handoffs.
aws-azure-security-mapping Ninety-nine AWS security concepts mapped to their closest Azure counterparts, including the cases where the two platforms have no clean equivalent.
anki-decks Seven maintained study decks, 1,262 cards across PowerShell, Python, Kusto Query Language (KQL), Bicep, cybersecurity, the AWS Security Specialty, and compliance frameworks. Each deck has a plain CSV source so changes can be reviewed in Git, and an automated parity check keeps the source and the Anki package in step.

Certifications and Skills

CISSP badge
CISSP
Microsoft Certified Expert badge
Cybersecurity Architect Expert
Microsoft Certified Expert badge
Azure Solutions Architect Expert
Microsoft Certified Expert badge
Microsoft 365 Administrator Expert
Terraform Associate badge
Terraform Associate
CCNA badge
CCNA

Azure Microsoft Entra ID AWS Terraform Bicep Salt Kubernetes Docker

Python PowerShell Bash FastAPI PostgreSQL Linux GitHub Actions


Areas of Focus

My work centers on a handful of areas.

  • I secure cloud platforms and identity across Azure, Entra ID, and AWS, including non-human identities.
  • I design application security in from the start, and test it by removing controls to confirm a test fails.
  • I define infrastructure as code, so an environment can be reviewed, rebuilt, and compared with what is running.
  • I secure delivery pipelines with pinned dependencies, full-history secret scanning, and merges gated on checks.
  • I build detections and the observability they depend on.
  • I automate security work so it runs the same way every time.
  • I work in regulated environments, including federal compliance and CMMC certification.
  • I govern AI-assisted development with written rules and the checks that enforce them.

Pinned Loading

  1. manifest-identity/manifest-identity manifest-identity/manifest-identity Public

    manifest-identity is an application for reviewing who has access to what across cloud accounts and directories. It keeps a record, written by a named person, of what access each identity may have, …

    Python 3 1

  2. build-doctrine build-doctrine Public

    A rulebook for letting an AI coding agent write code in a repository you are responsible for, with commands that measure a repository against the rules.

    Python 3

  3. sample-diagrams sample-diagrams Public

    Hand-drawn architecture and process diagrams, kept as point-in-time illustrations.

    3

  4. secure-expense-mvp secure-expense-mvp Public archive

    A small expense submission and approval application, built security-first with each control recorded against the threat it addresses.

    Python 3

  5. control-plane control-plane Public

    A security engineering program, built in public: the map of its parts, the method they share, and the documents that span them.

    Python 3

  6. aws-azure-security-mapping aws-azure-security-mapping Public

    99 AWS security concepts mapped to their closest Azure comparable, including the seven with no clean equivalent

    Python 3