Cloud & AI Governance Engineer

Kenneth
Zendera

AWS infrastructure · ISO 42001 · AI governance

📍 Cape Town, South Africa 🕐 UTC+2 🌍 Open to remote · EMEA & US East

Certifications

What I do

🏢

AWS multi-account architecture

Landing zones, Control Tower, IAM Identity Center, and Security Hub across multiple AWS Organizations. Multi-region, multi-client infrastructure designed for MSP scale.

📦

Infrastructure as Code

Production Terraform — modular, remote-state backed, CI/CD deployed with TFSec, Checkov, and manual approval gates. Idempotent and audit-compliant.

🔐

Cloud security & compliance

GuardDuty, Config, Security Hub, KMS, WAF — implemented as code and monitored continuously. ISO 27001 controls mapped to AWS services.

🤖

AI governance

EU AI Act risk classification, NIST AI RMF implementation, ISO 42001 AIMS design and audit. Practitioner-built templates and frameworks ready for real engagements.

⚙️

Ops automation

Cross-account Bash and Python tooling for CloudWatch alarm management, cost auditing, SSM State Manager deployments, quota monitoring, and account provisioning.

🚀

Migrations & cutovers

GCP → AWS workload migrations, RDS major-version upgrades via Blue/Green deployment, S3 + CloudFront OAC cutovers, IAM → IAM Identity Center transitions.

Projects

terraform-aws-security-baseline

Terraform

Reusable module enabling Security Hub (CIS + FSBP), GuardDuty, Config with managed rules, multi-region CloudTrail with KMS, and IAM Access Analyzer — all in one apply.

Terraform Security Hub ISO 27001
View on GitHub →

ai-governance-toolkit

Governance

Practitioner templates for EU AI Act risk classification, ISO 42001 clause-by-clause audit, NIST AI RMF implementation, incident response playbook, and vendor assessment questionnaire.

EU AI Act ISO 42001 NIST AI RMF
View on GitHub →

aws-cwagent-deployer

Bash · SSM

Self-healing CloudWatch Agent deployment via SSM State Manager. ASG-dimensioned alarms that survive instance replacement — fixes the two most common ways this is done wrong in production.

Bash SSM CloudWatch
View on GitHub →

aws-cost-auditor

Bash · FinOps

Read-only cross-account cost reporting using Cost Explorer. Month-over-month variance flagging, top-N services per account, EC2 rightsizing summary. CloudShell-native, no profile required.

Bash AWS CLI FinOps
View on GitHub →

terraform-aws-bedrock-governance

Terraform · AI

Private, VPC-endpointed Amazon Bedrock with Guardrails, Knowledge Base, and CloudWatch monitoring. Every resource annotated to the ISO 42001 control it satisfies.

Terraform Bedrock ISO 42001
View on GitHub →

terraform-aws-landing-zone

Terraform

Reusable landing zone module with Control Tower customisations, OU structure, account vending, and security baselines. In progress.

Terraform Control Tower Organizations
⚙ In progress

Tech stack

Cloud
AWS Control Tower IAM Identity Center ECS · EKS RDS Lambda CloudFront Bedrock Azure
Security
Security Hub GuardDuty Config IAM KMS WAF CloudTrail
IaC & CI/CD
Terraform CloudFormation GitLab CI GitHub Actions TFSec Checkov
Automation
Bash Python AWS CLI SSM Docker Kubernetes
Observability
CloudWatch CWAgent Prometheus Grafana Kibana
Governance
EU AI Act NIST AI RMF ISO 42001 ISO 27001 CIS Benchmarks

Get in touch

Open to remote infrastructure, cloud security, and AI governance roles or consulting engagements across EMEA and US East timezones.