Skip to content
View nurazhardotcom's full-sized avatar

Block or report nurazhardotcom

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
nurazhardotcom/README.md

Nur Azhar

Systems & Security Operations Engineer · DevSecOps & Compliance Automation

Website LinkedIn GitLab Email


🛡️ About Me

Systems & Security Operations Engineer with 7+ years of enterprise infrastructure, identity governance, and security operations experience across government-adjacent, critical operations (HTX/ICA, DCS, NEC). Proven track record authoring full ISO 27001 / CSA CyberTrust Mark ISMS frameworks and operating enterprise CyberArk PAM vaults under active ICA Category-2 clearance lineage.

Passionate about compliance-as-code, zero-dependency security automation, and deterministic Clojure/Babashka tooling.


🔬 Featured Open-Source Security & Automation Repositories

Repository Focus & Description Stack / Architecture
🛡️ security-tools 6 Zero-Dependency Security Automation Tools
Vulnerability prioritizer, triage engine, PAM request classifier, policy-to-ticket generator, IAM matcher, and access review summarizer. Fully tested (50 tests, 175 assertions).
Clojure, Babashka, Pure Functions
🔒 pdpa-sg-clj Singapore PDPA Compliance CLI & CI/CD Scanner
Static-analysis CLI tool detecting NRIC leaks, secret exposures, and PII redactor for repository pipelines.
Clojure, Babashka, Static Analysis
🕵️ aur-audit Supply-Chain Security Audit CLI
Static analysis scanner detecting obfuscated payloads, backdoors, and suspicious network calls in build scripts.
Babashka, Linux Security
🇸🇬 mcpf-adapter MyCareersFuture Government API Adapter
Zero-dependency CLI bridging Singapore MCF v2 job portal APIs to scrape, SHA-256 cache, and emit JSONL job intelligence.
Clojure, Babashka, REST API
🚀 lithan-capstone-project TasteLocal DevSecOps Microservices Capstone
Production containerized microservices on Northflank featuring automated CI/CD, PostgreSQL/SQLite, secure API gateways, and RBAC.
Clojure, Docker, Northflank

⚙️ Core Technical Capabilities

  • Identity & Access Management (IAM/PAM): CyberArk PAM Vaulting, Session Recording, Active Directory & Entra ID, Least-Privilege RBAC.
  • Security Compliance & Frameworks: ISO 27001 Annex A ISMS Authoring, CSA CyberTrust Mark (Cert No. 797101), IBM Guardium DAM, Carbon Black EDR, Tenable Nessus.
  • Automation & DevSecOps: Clojure, Babashka, Python, Go, Bash, SQL, Docker, GitLab CI / GitHub Actions, REST/gRPC.
  • Clearance & Subsidy: ICA Category-2 (Official Secrets Act) Clearance Lineage ·

Built with determinism and security in Singapore 🇸🇬

Pinned Loading

  1. pdpa-sg-clj pdpa-sg-clj Public

    Singapore PDPA compliance-as-code toolkit with static analysis, PII redaction, and validation data for AI agents and applications.

    Clojure

  2. security-tools security-tools Public

    Deterministic Clojure/Babashka security automation toolkit with six zero-dependency assistants for vulnerability prioritization, findings triage, access classification, policy tickets, IAM job matc…

    Clojure