Cloud, AI & Security Architect · Manama, Bahrain

Security engineering for regulated, high-consequence environments.

I am Shujat Azim — a hands-on security architect with 10+ years designing, building and operating controls across cloud, identity, detection and response. I turn requirements into deployable patterns, automation and secure defaults that engineers can actually adopt.

Portrait of Shujat Azim, Cloud, AI and Security Architect

Security is an engineering problem: build the secure path, automate it, and make it easier to use than the unsafe alternative.

That path — HCL ISD, Accenture, Adobe, then architect-level work from July 2022 — means every architecture is informed by implementation. At Ahli United Bank I owned security engineering and design assurance across critical banking systems. Today at International Turnkey Systems I build cloud, identity, API, data, detection and AI security controls for a regulated banking platform.

I also build with AI coding agents daily while establishing controls for the risks those systems introduce: unauthorized use, data leakage, prompt injection, auditability, human oversight and incident readiness.

More about how I work

Focus

AI & Agent Security

I establish the security layer for GenAI and agentic workloads: unauthorized use, data leakage, prompt injection, auditability, human oversight and incident readiness, grounded in OWASP LLM Top 10, MITRE ATLAS and NIST AI RMF.

Identity, Detection & Response

I engineer Entra ID, Conditional Access, PAM and least-privilege controls alongside Microsoft Sentinel KQL analytics, detection tuning and SOAR playbooks for automated triage and containment.

Cloud & Infrastructure Security

Hands-on architecture across Azure and AWS: segmentation, private connectivity, CSPM, workload protection, hardening, secure baselines and infrastructure as code that turns control intent into repeatable engineering.

Selected work

Making prompt-injection resistance measurable

An end-to-end evaluation framework for testing RAG and LLM applications against prompt injection, with a structured payload taxonomy and an auditable scoring model.

Independent project · AI security · Private repository

Read the case study

Experience

  1. Apr 2026 — Present

    Cloud and AI Security Architect

    International Turnkey Systems (ITS) · Manama, Bahrain · Regulated banking environment

    Design and implement core security controls across the cloud, identity, API and data layers of a regulated banking platform — translating requirements into deployable patterns, hardened baselines and reference implementations.

    Engineer detection and response on Microsoft Sentinel: author KQL analytics, tune detections against real telemetry, and automate triage and containment through SOAR playbooks integrated with Defender XDR, Defender for Cloud and Entra ID.

  2. Jul 2022 — Apr 2026

    Security Architect

    Unity Infotech — Client: Ahli United Bank (AUB) · Manama, Bahrain · Tier-1 regional bank

    Owned security engineering and design assurance for critical banking platforms spanning application, cloud, network, identity, endpoint, data protection and third-party integrations.

    Implemented and operated the Microsoft security stack in production: Entra ID, Conditional Access, Defender XDR, Sentinel, Purview DLP/AIP, Defender for Cloud, Key Vault, Azure Policy, WAF and secure logging baselines.

  3. Sep 2019 — Apr 2022

    Cloud Security & DevSecOps Engineer

    Adobe · India

    Designed and deployed secure multi-cloud architecture on Azure and AWS for Adobe Experience Manager environments, spanning identity, segmentation, private connectivity, encryption, secrets, logging, workload protection, resilience and monitoring.

  4. May 2018 — Aug 2019

    Cloud Security Engineer

    Accenture · India

    Deployed and hardened Azure infrastructure, including virtual machines, load balancers, VNets, NSGs and the associated network and access controls.

  5. Apr 2016 — Mar 2018

    Cloud Security Analyst

    HCL ISD · India

    Executed on-premises-to-Azure migrations with Azure Site Recovery, applying migration, hardening, access, network and operational controls throughout.

Full experience

ISO 27001 · NIST CSF · CIS Controls · PCI DSS · SAMA-CSF · NIST AI RMF

Speaking

Sovereignty Beyond Regions: Practical Azure/M365 Control Patterns

Cloud Security Alliance — UK Chapter AGM

A working session on what data sovereignty actually requires once the region selector is no longer enough — tenant boundaries, key custody, Purview classification, and the Conditional Access patterns that keep regulated data inside a jurisdiction.

Speaking details

If it is about cloud, identity or AI risk, I am happy to talk.