Available for select work · San Diego, CA

Shawheen
Azimi

>

Senior Security Architect, Engineer & Analyst defending high-assurance, regulated environments across cyber, multi-cloud, and AI. I design enterprise security programs, lead enterprise incident response, and engineer the automation & detection platforms that make a SOC scale.

shawheen@ai: ~/whoami
shawheen@ai:~$
tip: type help, experience, projects or resume
Large
Enterprise environments defended through senior incident response
7fig
Operational efficiency gains through security automation
Major
Cost reduction through security platform modernization
Top 0%
Global ranking on TryHackMe
01 / about

Security as engineering,
not paperwork.

I'm a senior security architect who treats defense as a software discipline — detections as code, automation over toil, and architecture that holds up under audit and attack alike.

Over four years at General Atomics & Affiliated Companies, I progressed from analyst to Senior Security Engineer & Tech Lead, owning enterprise Azure and AWS security programs across a NIST/CMMC-aligned multi-cloud estate and standing up the platforms that run a modern SOC.

I pair deep technical range — detection engineering, DFIR, adversary emulation, cloud & identity architecture — with a business-minded, entrepreneurial lens: protecting contract revenue, cutting spend, and building security that lets the business move faster.

~/whoami.json
nameShawheen Azimi
roleSenior Security Engineer
& Tech Lead
focusCyber · Cloud · AI
clearanceActive clearance
educationB.S. Information Systems
San Diego State · Dean's List
languagesEnglish, Farsi (fluent) · Spanish
status● open to select work
02 / experience

General Atomics & Affiliated Cos.

Building and leading enterprise security across cyber, cloud, and AI in a regulated defense environment.

Senior Security Engineer & Tech LeadCURRENTOct 2025 — Present
Security Engineer IIMar 2024 — Oct 2025
Security EngineerOct 2022 — Mar 2024
Cybersecurity AnalystNov 2021 — Oct 2022
selected operations · $ cat experience.json
01

Multi-Cloud Security Architecture & Governance

Owned design and build-out of enterprise Azure & AWS security programs across a NIST/CMMC-aligned estate, integrating cloud-native controls with on-prem to run regulated workloads at scale.

Azure · AWS · NIST · CMMC
02

Enterprise Threat Detection & Incident Command

Senior incident response lead for enterprise-scale security events — coordinating containment, eradication, and executive risk communication across large endpoint environments.

DFIR · Enterprise IR
03

Detection-as-Code Platform (CI/CD)

Architected a Detection-as-Code CI/CD platform — treating detections as software with Git version control, SIGMA conversion, automated efficacy testing, and adversary-driven validation.

Detection Eng · SIGMA · CI/CD
04

CMMC Program Leadership & Audit

Led enterprise-wide CMMC readiness across security control domains and supported third-party assessment activities, strengthening certification readiness and strategic business operations.

CMMC · Audit · Compliance
05

Adversary Emulation & Defensive Validation

Led adversary emulation and defensive validation exercises to improve detection coverage and control effectiveness across enterprise environments.

Red/Purple · Validation
06

Digital Forensics & Insider Threat

Directed sensitive digital forensic investigations while preserving evidentiary integrity, stakeholder coordination, and operational continuity.

Forensics · Investigations
07

AI-Powered Security Operations

Built and integrated AI infrastructure into SecOps tooling, enabling an AI-augmented SOC with accelerated triage, enrichment, and investigative decision-making at scale.

AI · LLM · SecOps
08

Global SaaS Security Architecture

Owned security architecture for a global SaaS platform — secure-by-design infrastructure, identity segmentation, and cross-region telemetry pipelines in a highly regulated environment.

SaaS · Secure-by-Design
09

Security Automation

Designed an enterprise automation platform for alert enrichment, investigation, and response — producing seven-figure efficiency gains and enabling continuous operations.

Automation · SecOps
10

Enterprise Threat Modeling Framework

Created the org's threat-modeling framework to systematically assess cloud workloads, applications, and emerging tech against real-world attack vectors and business impact.

Threat Modeling · Risk
11

Cloud-Native Observability Platform

Architected a cloud-native observability platform consolidating enterprise telemetry and replacing legacy tooling while improving correlation, retention, and investigative performance.

Observability · Cost Reduction
12

Security Correlation Platform

Led major enterprise security platform modernization across cloud, endpoint, network, and identity telemetry to improve automated correlation and reduce manual triage.

Correlation · Modernization
03 / projects

Selected builds

Public-safe examples of security engineering, AI-assisted operations, cloud labs, and detection-focused tooling.

research & tools · $ ls public-work/
04 / skills

Technical stack

The tools, platforms, and frameworks I build and defend with.

security platforms //

detection, response & network defense
DFIRSecurity AutomationTelemetry PlatformsEndpoint Defense Network DefenseWeb SecuritySecure Remote Access Detection RulesDefensive Validation

cloud & identity //

multi-cloud, containers & access
AWSAzureGCP Cloud IAMEnterprise IdentityAccess Governance KubernetesDockerPodmanVMware Enterprise Email Security

code · scripting · AI //

automation & AI engineering
PythonBashPowerShell SQLKQLXQL LangGraphLangChainAWS Bedrock Claude CodeOllamaOpenAI Codex

frameworks & OS //

standards, practices & systems
MITRE ATT&CKNIST 800CMMCFedRAMP IaCCI/CDSASTSBOM Linux / RHELWindowsKaliParrot OS
domains of expertise
Detection Engineering Threat Modeling & Attack Path Analysis Incident Response & Digital Forensics Security Architecture & Design Review Security Operations Strategy Threat Intel & Adversary Emulation Vulnerability & Exposure Management Cloud & Identity Security Architecture Security Automation Engineering Cyber Deception Infrastructure & Platform Security Identity & Access Governance Security Policy & Control Design Compliance Engineering Leadership & Cross-Team Execution
05 / certifications

Credentials & training

Industry certifications across architecture, cloud, and operations — plus active clearance and advanced training.

Architecture & Incident Response

CISSP PROJECTED Q4 '26
CompTIA SecurityX (CASP+)
GIAC Certified Forensic Analyst (GCFA)
CompTIA CySA+

Cloud & Platform Security

AWS Certified Security — Specialty
AWS Certified Solutions Architect
Microsoft Azure Security Engineer (AZ-500)

Security Operations

Security Automation Engineering
Security Analytics Platform Operations
Network Defense Technologies
Vulnerability Scanning & Analysis

Foundational & Advanced Training

CompTIA Security+
SANS FOR508 — Adv. IR & Threat Hunting
Mandiant Academy — Linux Enterprise IR
TryHackMe — Top 1% global · Challenge Coin
Security Clearance
Active clearance
Details available upon request
Citizenship
U.S. Citizen
Education
B.S. Information Systems
San Diego State · Dean's List
Recognition
Challenge Coin Winner
Top 1% · TryHackMe
06 / contact

Let's secure what's next.

Open to senior security engineering, architecture, and AI-security roles — plus select consulting and speaking. Reach out and I'll get back to you.

shawheen56@gmail.com Read the blog San Diego, CA Active clearance