[donny@scyber ~]$ whoami

Donny SchreiberCloud & Product Security Engineer/Architect · DevSecOps · AI Security

secured 18+ enterprise AWS environments — healthcare, gov, defense, fintech, edtech

AWS published my multi-Region IPAM architecture as Prescriptive Guidance

open-sourced IPAM Terraform code on aws-samples — 67 pools, 874 resources

cut one customer's internal security review processes from two weeks to four hours

cleared a year-long AWS-internal security-review backlog in one week with a tool I wrote

threat-modeled and helped remediate 127 threats in a FINRA-approved GenAI platform

drummed 8 seasons for the Avalanche (NHL) and Nuggets (NBA) in-game entertainment team

played drums on stage with Kacey Musgraves to a sold-out crowd at Red Rocks

went with the Nuggets to the London NBA Global Games in 2017

I'm a cloud and product security engineer/architect at Amazon Web Services (AWS). I've secured $4B+ of cloud infrastructure across 18+ projects with some of AWS's largest customers — in healthcare, financial-services, government, education-tech, telecom, etc. — helping build the network security, data protection, Identity & Access Management, GenAI/ML guardrails, DevSecOps pipelines, and automation those environments run and rely on. Much of what I build starts with me noticing, being annoyed with, and speaking up about repeat workflows (or bureaucracy) in {$XYZ}, ultimately building a solution (PoC) to demo, and either having it implemented immediately, delegated to a team that can take over, or laughed at. ¯\_(ツ)_/¯ This is my website.

# Selected Work

Projects & Work

A few things I've built and shipped — public artifacts where possible: open-source infrastructure, security automation, and writing on cloud and AI security.

./multi-region-ipam

Multi-Region IPAM on AWS

Multi-account, hierarchical IP address management automated end-to-end in Terraform — 67 pools across regions, cross-account sharing via AWS RAM. I authored the public AWS Prescriptive Guidance pattern for this architecture and open-sourced the Terraform to aws-samples.

./cloud-governance

Cloud Governance & Compliance-as-Code

Policy-as-code guardrails and compliance automation for AWS: Service Control Policies, AWS Config custom rules, Security Hub and GuardDuty, and Control Tower / Landing Zone Accelerator baselines that keep regulated environments from drifting out of compliance.

  • Service Control Policies & AWS Config custom rules (Guard DSL)
  • Security Hub, GuardDuty, Control Tower, Landing Zone Accelerator
  • Detective & preventative controls across multi-account organizations
  • Frameworks: HIPAA, HITRUST, PCI DSS, SOC 2, NIST 800-53, FedRAMP
./devsecops-automation

Shift-Left DevSecOps Automation

A CI suite orchestrating 15+ SAST/DAST/IaC/secrets scanners that only scan what changed. Cut a financial-services platform's security validation from two weeks to four hours.

  • 15+ scanners (Bandit, Semgrep, Checkov, Trivy, tflint, GitLeaks…)
  • GitHub Actions with 40–60% CI cost reduction
  • SARIF findings surfaced in GitHub's Security tab
  • Read the write-up →
./genai-security

GenAI & Agentic-AI Security

Security for LLM and agentic systems: OWASP-LLM-Top-10 reviews, MCP / multi-agent architecture security, and internal tooling that generates least-privilege IAM policies from natural language.

  • OWASP LLM Top 10 review methodology
  • MCP / multi-agent (agentic) architecture security
  • IAMulator — internal tool: least-privilege IAM from natural language
  • Read the write-up →
./personal-builds

Personal Builds

Things I build and secure for fun and for people I care about — static and serverless apps on AWS, infrastructure-as-code, end to end.

  • ruthevelynpaints.com → — an art portfolio I built + secured on AWS
  • scyber.ai — this site (S3 + CloudFront + Terraform + WAF)
  • Infrastructure-as-Code; you own everything
# About

The Person Behind the Terminal

I've been doing security for over a decade — network and endpoint defense, SIEMs, incident response, then cloud, infrastructure, and application security. For the last four years I've been a cloud security consultant (security engineer/architect) at AWS, helping enterprises build, assess, and secure their cloud environments.

I have a degree and a number of active/historic credentials in Cybersecurity, but I am fundamentally self-taught. It started at twelve, reverse-engineering embedded drum videos from page source to learn proper drumming technique — and, accidentally, figure out how the web worked. That curiosity never left. I just pointed it at networking, security, and automation.

The security career and drumming/music ran side-by-side for many years. From 2015 to 2022 I played drums for Kroenke Sports & Entertainment (KSE) — in-game for the Avalanche (NHL), Nuggets (NBA), and occasionally the Rapids (MLS) and Mammoth (NLL) — at night, after my Cybersecurity day-job, in roles that were progressing from junior- to mid-level. Thanks to KSE, I got to entertain audiences attending: games during the Avalanche's 2022 Stanley Cup run, the London NBA Global Games with the Nuggets, and some concerts at Red Rocks (including one sold-out night with eight-time Grammy Award winner Kacey Musgraves).

Security was the day job through all of it: analyst/administrative work at KIOSK; then EDR, Email, SIEM, and MDM security engineering work at Zayo; then network security engineering at Zayo. The year I started at AWS, in 2022, I put the drums away and doubled-down on professional development.

Have a look at my writing to see how I think and work.

Enterprise Security Background
Network defense, EDR, SIEM, email security, MDM, and incident response — over a decade, from MSSP-style work for 10 client organizations to a global Tier 1 fiber provider.
Cloud Security & IaC
AWS architecture, Terraform, AWS CDK, DevSecOps. I build infrastructure as code because clicking around consoles doesn't scale.
AI & Automation
I build security automation and GenAI tooling daily. I've caught enough of their mistakes to know where they cut corners.
[donny@scyber ~]$

Get in touch

Open to conversations about cloud, product, and AI security work. No forms — just email or LinkedIn.

principles.list()

How I Build Things

01
Simple where it counts. Not everything is easy. But nothing should be needlessly complicated. If you don't understand it, I can help until you do.
02
Built to change. Modular. Structured. So when your needs evolve — and they will — you're not starting over.
03
Secure by design. Not bolted on at the end. Not "we'll get to that later." From the start.
04
Honest about trade-offs. Everything has a cost... time, money, complexity, security. The right balance isn't the same for everyone. I'll help you find yours.
05
Lean on purpose. I'm not going to recommend something just because it's shiny. Every tool has to earn its place.
# Latest from the Blog

Recent Writing

The blog is where I go deep. Technical posts, arguments with buzzwords, and the occasional hot take.

# Contact Interface

Get in touch

No forms, no funnels. If you want to talk about security work, a role, or something I've built — reach out directly. I read everything.

contact_methods.avail()

Direct Contact

Email
[Protected — click to reveal]
Location
Boulder, Colorado