Identity & Security Systems Practitioner · IAM/PAM · Security Automation
I am an identity and security systems practitioner with 7+ years of enterprise infrastructure, IAM/PAM, and security operations experience across regulated, high-availability environments in Singapore. My operational foundation includes CyberArk PAM, Active Directory, Entra ID, regulated infrastructure, and CyberTrust Mark / ISO 27001 ISMS delivery.
My current work turns the durable identity problems—authentication, authorization, privilege, delegation, and auditability—into deterministic, inspectable automation using Clojure, Babashka, EDN, OPA/Rego, and CI/CD controls.
I am extending this foundation into workload identity and controlled automation: making access explicit, time-bounded, revocable, and auditable as systems become more distributed.
Open to remote roles across APAC/EMEA overlap — based in Singapore (SGT, UTC+8), flexible hours for CET-morning overlap, async-first (written RFCs/ADRs, 1–2 sync touches per week).
| Repository | What it demonstrates |
|---|---|
| 🚦 identity-policy-as-code | OPA/Rego IAM gates over Terraform plans, denying wildcard permissions and unsafe inline policies. |
| 🔍 idira-audit-clj | Babashka/Clojure PAM audit CLI: orphaned privilege, dormant accounts, missing MFA, and stale tokens via SCIM/OAuth2 APIs. |
| 🛡️ security-tools | Babashka/Clojure security automation for findings, access reviews, PAM requests, and IAM workflows. |
| 🔒 pdpa-sg-clj | Singapore PDPA and secret-exposure scanning for repositories and pipelines. |
| 🧪 aur-audit | Linux supply-chain inspection for obfuscated payloads and suspicious build behavior. |
| ⌨️ tui | Personal prod gateway in Clojure: passkey-gated proxy in front of opencode web, Zen Responses API (muse-spark-1.3-contributor-free), dogfooded daily. MIT. |
- IAM/PAM: CyberArk vaulting and session recording; Active Directory and Entra ID; least-privilege access control.
- Security operations: IBM Guardium DAM, Carbon Black EDR, Tenable Nessus, high-availability infrastructure support.
- Compliance: CSA CyberTrust Mark Promoter Tier delivery; ISO 27001 Annex A ISMS execution.
- Automation: Clojure/Babashka, EDN, OPA/Rego, Python/Bash, GitHub Actions, GitLab CI, Linux, containers.
Technical writing and architecture notes are published at nurazhar.com, including secure automation and agentic systems, Replacing Imperative Scan Code with Rego, I Built a PAM Audit CLI to Learn Identity the Hard Way, and the full archive.
I am available for IAM/PAM, identity operations, security automation, and infrastructure-security roles.
- Website: nurazhar.com
- Email: [email protected]
- LinkedIn: linkedin.com/in/nur-azhar



