Skip to content
View nurazhardotcom's full-sized avatar

Block or report nurazhardotcom

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
nurazhardotcom/README.md

Nur Azhar

Senior SecOps & Identity Operations Specialist — PAM · CyberTrust ISMS (ISO 27001 Annex A) · Containerised CI/CD Compliance Automation

Website LinkedIn GitLab Email


🛡️ About Me

Senior SecOps & Identity Operations Specialist with 7+ years of enterprise infrastructure, identity governance (IAM/PAM), and security operations experience across government-adjacent, critical environments (HTX/ICA, DCS, NEC). Delivered CSA CyberTrust Mark certification (Promoter Tier) as sole ISMS Lead — executed the consultant-designed ISMS internally across 7 Annex A control domains — and operated enterprise CyberArk PAM vaults in government-adjacent environments.

Focus: containerised compliance automation (Shell/Python, Semgrep/Checkov ecosystem), IAM/PAM operations (CyberArk, Active Directory/Entra ID RBAC), and CI/CD pipeline security — with a security clearance (Cat 2, Government-Adjacent Environments).


🔬 Featured Open-Source Repositories

Repository Focus & Description
🛡️ security-tools Zero-Dependency Compliance & IAM Automation Toolkit — 6 assistants: vulnerability prioritiser, findings triage, IAM job matcher, access review summariser, policy-to-ticket generator, PAM request classifier. 50 tests, 175 assertions.
🔒 pdpa-sg-clj Singapore PDPA Compliance CLI & CI/CD Scanner — NRIC Mod-11 static scanning, PII redaction, 11-obligation checklist. Built for AI agents.
🇸🇬 mcpf-adapter MyCareersFuture API Adapter — zero-dependency CLI bridging Singapore MCF v2 APIs to structured job intelligence (JSONL/SQLite).

✍️ Research & Writing

Sustained technical publishing at nurazhar.com — 200+ posts on systems architecture, agent-era security, and compliance pipelines.

Essay Focus
🧠 Cognitive Asymmetry: The Epistemic Bandwidth Bottleneck Why abstraction capacity — not hardware access — defines the agent era divide
The Energy Wall Will Kill Von Neumann Computing Data-movement energy costs forcing hybrid compute architectures
🛡️ Agentic AI Security Trust boundaries, tool integrity, and contained execution for autonomous systems

The site is fully LLM-readable (llms.txt, llms-full.txt).


⚙️ Core Technical Capabilities

  • Identity & Access Management (IAM/PAM): CyberArk PAM Vaulting, Session Recording, Active Directory & Entra ID, Least-Privilege RBAC.
  • Security Compliance & Frameworks: ISO 27001 Annex A ISMS Delivery, CSA CyberTrust Mark Promoter Tier, IBM Guardium DAM, Carbon Black EDR, Tenable Nessus.
  • Developer Tooling: Containerised CLI utilities (Shell/Python, Semgrep, Checkov), Clojure/Babashka, GitLab CI / GitHub Actions, REST/gRPC.
  • Security Clearance: Cat 2 Cleared (Government-Adjacent Environments).

Built with determinism and security in Singapore 🇸🇬

Pinned Loading

  1. pdpa-sg-clj pdpa-sg-clj Public

    Singapore PDPA compliance-as-code toolkit with static analysis, PII redaction, and validation data for AI agents and applications.

    Clojure

  2. security-tools security-tools Public

    Deterministic Clojure/Babashka security automation toolkit with six zero-dependency assistants for vulnerability prioritization, findings triage, access classification, policy tickets, IAM job matc…

    Clojure