Skip to content
View FideleDonadje's full-sized avatar

Block or report FideleDonadje

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
FideleDonadje/README.md

πŸ‘‹ About Me

I'm a cloud security engineer building production-grade tooling on AWS. My focus is the intersection of cloud security, AI automation, and compliance engineering β€” turning noisy security findings into structured, actionable outputs including full RMF compliance packages.

  • πŸš€ Shipped a 3-feature AWS security platform: AI SOC Triage, ATO Assist Mode, and a full NIST RMF Workspace with live artifact generation
  • πŸ“‹ The RMF Workspace walks through all 7 NIST RMF steps and auto-generates the SSP, SAR, Risk Assessment, POA&M, and FIPS 199 categorization from live Security Hub findings
  • ⚑ Everything I build is infrastructure-as-code first (AWS CDK), no manual console changes
  • 🧠 Design-first workflow: architecture is thought through before a line of code is written, and I own every decision

πŸ› οΈ Tech Stack

Cloud & Security

AWS AWS CDK AWS Lambda Security Hub Bedrock DynamoDB Cognito IAM S3

Languages & Frameworks

TypeScript Python React Node.js PowerShell

DevSecOps

GitHub Actions Terraform Docker Checkov Jenkins

Compliance

NIST 800-53 NIST RMF ATO SSP FIPS 199


πŸ” Portfolio Projects

AI-powered AWS security platform β€” Triage, ATO Assist, and NIST RMF Workspace

A fully deployed, 3-feature security platform built on AWS:

SOC Triage Agent β€” ingests Security Hub findings, routes them through an AI triage workflow using Bedrock AgentCore, and executes approved Tier 1 remediation actions with human-in-the-loop approval via a React/Cognito frontend.

ATO Assist Mode β€” pulls NIST 800-53 findings from Security Hub grouped by control family, uses Bedrock to draft control implementation statements, and auto-generates POA&M entries from failed findings.

NIST RMF Workspace β€” a full 7-step RMF workflow dashboard. Covers system categorization (FIPS 199), control selection, implementation tracking, security assessment, authorization package generation, and continuous monitoring. Auto-generates the SSP, Security Assessment Report, and Risk Assessment from live Security Hub data. Every artifact has a Regenerate button so documents always reflect current environment state.

AWS Bedrock AgentCore CDK Lambda DynamoDB Streams Security Hub React/Vite TypeScript Cognito S3


Account-level AWS security control coverage auditing

Produces auditable JSON and Markdown reports showing exactly which AWS security controls are active vs. missing. Designed for compliance engineers who need clean evidence artifacts with no dashboard noise.

Python AWS Security Hub NIST 800-53 Markdown Reports


πŸ“Š GitHub Stats


πŸ—ΊοΈ What's Next

Status Project Description
πŸ”¨ In Progress CI/CD Security Gate Pre-deploy IaC scanning with Checkov/tfsec in GitHub Actions
πŸ“‹ Planned Greenfield AWS Setup Guide Blog post on secure account bootstrapping from scratch
πŸ“‹ Planned IAM Policy Analyzer Detect overpermissioned policies before they reach production
πŸ“‹ Planned Infrastructure Drift Detector Alert on live AWS config deviating from CDK-defined state

Popular repositories Loading

  1. security-triage-agent security-triage-agent Public

    Repo for An AI-powered AWS security operations platform offering a security triage agent, ATO assist and NIST RMF documentation generation

    TypeScript 5 1

  2. Github Github Public

    This repository contains some of my school work as well as projects

    Java

  3. security-control-coverage-analyzer security-control-coverage-analyzer Public

    Account-level AWS security control coverage analyzer that produces auditable JSON/Markdown reports (no dashboards, no remediation)

    Python

  4. grc-engineering-club.github.io grc-engineering-club.github.io Public

    Forked from GRCEngClub/directory

    GRC Engineer Directory

    JavaScript

  5. FideleDonadje FideleDonadje Public

    Introduction and projects

  6. shared-workflows shared-workflows Public