About Me
About Arnav Sharma
Cloud security, cybersecurity, DevOps and AI — with a practical engineering lens.
I’m a Sydney-based cloud security architect, Microsoft MVP, author, and builder focused on Azure security, cloud security, cybersecurity strategy, DevOps, AI security, governance, and compliance.
I’ve been blogging for more than a decade, sharing practical field notes for engineers, architects, security teams, consultants, and technology leaders working across modern cloud and security environments.
Focus areas
What I work on
Cloud security architecture
Secure cloud design, security posture, governance, landing zones, identity, network security, workload protection, and operational security.
Azure security
Practical Azure security across identity, networking, Microsoft Defender for Cloud, Microsoft Sentinel, Key Vault, Azure Policy, monitoring, and Zero Trust patterns.
Cybersecurity strategy
Security operating models, program uplift, people/process/technology alignment, cyber resilience, risk management, and executive-friendly security planning.
DevOps and automation
Infrastructure as code, secure delivery pipelines, policy as code, cloud automation, Terraform, DevSecOps, and repeatable engineering practices.
AI security and governance
AI security risks, secure adoption, policy considerations, control mapping, and practical governance for teams using AI-enabled systems.
GRC and compliance
Mapping controls across cybersecurity frameworks, translating compliance requirements into practical implementation, and reducing policy and audit friction.
Books and tools
Practical resources I’ve created
Mastering Azure Security
A hands-on book about implementing Zero Trust, compliance, and threat protection with Azure security tools.
View bookThe 4 Corners of Cybersecurity
A practical cybersecurity book about building security programs across people, process, technology, and threats.
View bookSecFrame Explorer
A security framework explorer that helps decode controls, explanations, remediation steps, CLI checks, and cross-framework mappings.
Explore SecFrameSecPolicy
An AI security policy generator for creating tailored, audit-ready policies with cross-framework control mapping and editable document exports.
Explore SecPolicyRecognition
Awards and recognition
Microsoft MVP
Recognised as a Microsoft MVP across Cloud Security, Microsoft Azure, and Security, including recent recognition for 2024–25 and earlier MVP awards.
HashiCorp Ambassador
Recognised as a HashiCorp Ambassador for contributions around infrastructure, automation, Terraform, and cloud engineering communities.
Microsoft community recognition
Previous Microsoft community recognition includes Microsoft MVP, Microsoft Community Contributor, and Microsoft Influencer Hero recognition.
Microsoft Security recognition
Recognised across Microsoft Security areas including Defender for Cloud, Microsoft Sentinel, Cloud Security, and related product influence programs.
Certifications
Selected certifications
My certification background spans cloud architecture, cloud security, DevOps, identity, governance, infrastructure, and enterprise architecture.
Microsoft Azure and Security
- Azure Solutions Architect Expert
- Azure Security Engineer Associate
- Azure Network Engineer Associate
- Azure Administrator Associate
- Security Operations Analyst Associate
- Identity and Access Administrator Associate
- Information Protection Administrator Associate
- Azure AI Engineer and Azure AI Fundamentals
Cloud, DevOps and Architecture
- AWS Solutions Architect – Associate
- AWS Security – Specialty
- Google Cloud Professional Cloud Architect
- Google Cloud Associate Cloud Engineer
- HashiCorp Certified: Terraform Associate
- GitLab Certified Associate
- TOGAF Certified
- ITIL Foundation
View additional certification background
My broader certification history also includes Microsoft 365, Windows Server, System Center, Hyper-V, Azure Virtual Desktop, Azure for SAP Workloads, Power Platform, Cisco CCNA, and earlier Microsoft infrastructure certifications.
Work with me
Need help with cloud security, Azure security, cybersecurity strategy, or compliance?
I work with teams that need practical help turning security goals, cloud architecture, governance requirements, and compliance obligations into implementation plans that engineers and business stakeholders can actually use.