Yavuz Sönmez

Based in southern Germany

Cloud & Application Security Engineer

DevSecOps practices, Cloud and Application Security, Zero trust architecture and Defense-in-depth applied at scale to systems running in production.

What I work on

Cloud Security

I secure cloud environments end to end: least-privilege identity, segmented networks, and isolated accounts that contain blast radius. Detection and remediation run continuously, not at deployment.

Application Security

I secure applications at the code and CI/CD levels: inputs validated at the boundary, authorization enforced per object, secrets kept out of code. Static, dynamic and dependency analysis run before release.

Zero Trust Architecture

I design systems where no user, service or device is trusted by default, whatever its network location. Identity is the perimeter: every request authenticated and authorized on its own, on an assume-breach premise.

Defense-in-Depth

I layer independent controls so no single failure leads to compromise. Perimeter, network, host, application and data, each designed assuming the layer before it could fail, and tested adversarially.

Writing

Nothing published yet. The RSS feed will pick them up when they land.