Cloud, AI & Security Architect · Manama, Bahrain
Security engineering for regulated, high-consequence environments.
I am Shujat Azim — a hands-on security architect with 10+ years designing, building and operating controls across cloud, identity, detection and response. I turn requirements into deployable patterns, automation and secure defaults that engineers can actually adopt.

Security is an engineering problem: build the secure path, automate it, and make it easier to use than the unsafe alternative.
That path — HCL ISD, Accenture, Adobe, then architect-level work from July 2022 — means every architecture is informed by implementation. At Ahli United Bank I owned security engineering and design assurance across critical banking systems. Today at International Turnkey Systems I build cloud, identity, API, data, detection and AI security controls for a regulated banking platform.
I also build with AI coding agents daily while establishing controls for the risks those systems introduce: unauthorized use, data leakage, prompt injection, auditability, human oversight and incident readiness.
More about how I workFocus
AI & Agent Security
I establish the security layer for GenAI and agentic workloads: unauthorized use, data leakage, prompt injection, auditability, human oversight and incident readiness, grounded in OWASP LLM Top 10, MITRE ATLAS and NIST AI RMF.
Identity, Detection & Response
I engineer Entra ID, Conditional Access, PAM and least-privilege controls alongside Microsoft Sentinel KQL analytics, detection tuning and SOAR playbooks for automated triage and containment.
Cloud & Infrastructure Security
Hands-on architecture across Azure and AWS: segmentation, private connectivity, CSPM, workload protection, hardening, secure baselines and infrastructure as code that turns control intent into repeatable engineering.
Selected work
Making prompt-injection resistance measurable
An end-to-end evaluation framework for testing RAG and LLM applications against prompt injection, with a structured payload taxonomy and an auditable scoring model.
Read the case studyExperience
Cloud and AI Security Architect
Design and implement core security controls across the cloud, identity, API and data layers of a regulated banking platform — translating requirements into deployable patterns, hardened baselines and reference implementations.
Engineer detection and response on Microsoft Sentinel: author KQL analytics, tune detections against real telemetry, and automate triage and containment through SOAR playbooks integrated with Defender XDR, Defender for Cloud and Entra ID.
Security Architect
Owned security engineering and design assurance for critical banking platforms spanning application, cloud, network, identity, endpoint, data protection and third-party integrations.
Implemented and operated the Microsoft security stack in production: Entra ID, Conditional Access, Defender XDR, Sentinel, Purview DLP/AIP, Defender for Cloud, Key Vault, Azure Policy, WAF and secure logging baselines.
Cloud Security & DevSecOps Engineer
Designed and deployed secure multi-cloud architecture on Azure and AWS for Adobe Experience Manager environments, spanning identity, segmentation, private connectivity, encryption, secrets, logging, workload protection, resilience and monitoring.
Cloud Security Engineer
Deployed and hardened Azure infrastructure, including virtual machines, load balancers, VNets, NSGs and the associated network and access controls.
Cloud Security Analyst
Executed on-premises-to-Azure migrations with Azure Site Recovery, applying migration, hardening, access, network and operational controls throughout.
Speaking
Sovereignty Beyond Regions: Practical Azure/M365 Control Patterns
A working session on what data sovereignty actually requires once the region selector is no longer enough — tenant boundaries, key custody, Purview classification, and the Conditional Access patterns that keep regulated data inside a jurisdiction.
Speaking detailsWriting
The Future of AI Security in Enterprise Environments
How global enterprises are rearchitecting their cyber programs around AI workloads, model integrity, and secure data lifecycles.
Zero Trust in the Age of AI
Zero Trust principles applied to autonomous agents, copilots, and machine identities operating at machine speed.
Securing Microsoft 365 for Modern Enterprises
A reference architecture for hardening M365 with Entra ID, Defender XDR, Purview, and Conditional Access in regulated industries.