Joseph-Israel Wong
Cloud Security Engineer
Attributes
-
Infrastructure9Terraform modules generating SCP and RCP based guardrails across 50+ AWS accounts; the remediation system codified as modules and migrated onto a Bazel-managed IaC setup; a service's production bring-up provisioned end to end.
-
Cloud8AWS Certified Security Specialty (SCS-C03, Jan 2026). Access control standardized across 50+ accounts through IAM, CloudTrail and Datadog integrations.
-
Security8Primary subject matter expert for Security and Log products, specializing in Cloud SIEM and Cloud Security Posture Management. Risk classification scoring public exposure, encryption, versioning, IAM policy, blast radius and data sensitivity.
-
Code7Designed and shipped a Go risk-classification service scoring 2,000 production storage buckets. Python, Bash, PowerShell and SQL alongside it.
-
Operations6A self-hosted Linux server running containerized services since Sept 2023 — web apps, network-level DNS filtering, network-attached storage. Earlier: server performance degradation and log anomalies across a SaaS fleet via Grafana and Kibana.
-
Communication7An auditable remediation workflow routing findings to owning teams across 100+ teams. Mentor for Security and Log products, trusted technical advisor to enterprise customers, translating feedback into product improvements.
Proficiencies
Languages
Cloud & IaC
Security
Platforms
Inventory
- Containers Docker. Everything the lab runs, and this page.
- Fifty Accounts The AWS estate under SCP and RCP guardrails.
- The Home Lab Self-hosted since Sept 2023. Testbed before production.
- Modules Terraform. Guardrails, pipelines, bring-up.
- Two Hats Security engineering and support, concurrently.
- The SME Tome Subject matter expert, Security and Log products.
Achievements
-
Certified
AWS Certified Security Specialty, SCS-C03. Jan 2026. -
Two Thousand Buckets
Scored every one on public exposure, encryption, versioning, IAM policy, blast radius and data sensitivity. -
Hundred Teams
Replaced manual triage with an auditable workflow across 100+ teams. -
Warded
SCP and RCP guardrails generated across 50+ AWS accounts. -
Ninety-Five Percent
Complex customer issues replicated and resolved in sandboxed environments. -
Change Of Orbit
B.S. Aerospace Engineering, Embry-Riddle, Dec 2021. Now doing cloud security. -
Locked
Roll the die.
A twenty-sided die. It is not weighted, exactly. It simply has a very strong opinion, and the opinion is twenty.
Quest Log
-
Cloud Security Engineer Feb 2026 — PresentDatadog Active
Ship Go services and Terraform-managed infrastructure that classify risk and remediate security findings at fleet scale.
-
Technical Support Engineer May 2024 — PresentDatadog Active
Log Management, Cloud Security and Cloud Integrations. Subject matter expert for Cloud SIEM and Cloud Security Posture Management.
-
Cloud Support Specialist II Sept 2022 — April 2024Yardi Systems Complete
Cloud Services. Server performance and log anomalies across the SaaS fleet; cross-team incident resolution for enterprise deployments.
Backstory
Went to school for aerospace engineering and ended up in cloud security. It sounds like a bigger jump than it was. Both come down to the same question: what happens when one piece of this fails at 3am, and what catches it when it does.
There's a Linux box at home doing a lot more than it strictly needs to. Container orchestration, network segmentation, backups, infrastructure as code, it all gets tried there first, where breaking something costs a weekend instead of a fleet. This website runs on it. So does the village you walked through to get here.
The best part of the job is still the troubleshooting. Something is broken, nobody knows why, and between you and the answer there's a pile of logs, a few metrics that disagree with each other, and three assumptions everyone has stopped questioning. Pulling on that until one thing explains all of it never really gets old.