Software Engineering Student - Interested in Cloud Security Engineering and GRC

Making risk legible.

I build tools that map controls across frameworks like NIST CSF, ISO 27001 and Essential Eight, and I write about what I learn along the way. Currently completing a software engineering degree at Monash, with a professional background in regulated manufacturing.

Move to declassify

[ REDACTED ]

Most compliance work is invisible until something breaks.

I'm interested in the systems behind the systems. The frameworks, controls and processes that let cloud infrastructure be trusted. This site is a record of what I've built, what I've learned, and where that's heading.

2Websites deployed to cloud
2Certifications in progress
2Certifications completed
Who is Nathan Nunes

I'm a penultimate-year Bachelor of Software Engineering (Honours) student at Monash University, graduating in 2027.

My background isn't typical for software engineering. I spent four years as a GMP Processor in a regulated manufacturing environment at Ensign Laboratories. Working under strict Standard Operating Procedures taught me that good systems are ones where evidence, process, and accountability are built in, not an afterthought.

That experience drives my interest in GRC and Cloud Security Engineering. I'm focused on how major frameworks like NIST CSF, ISO 27001, Essential Eight, and APRA CPS 234, get operationalised in code rather than just existing as static documents.

Systems

Projects and tools.

GRC Report Automation Agent

01GRC Report Automation Agent

Automates control mapping and reporting across major security and compliance frameworks. Generates client-ready risk registers natively mapped to standard frameworks with zero ongoing API costs using local LLMs.

PythonOllamaNIST CSFISO 27001Essential Eight
Secure AWS Serverless Messaging Framework

02Secure AWS Serverless Messaging Framework

A secure, infrastructure-as-code messaging framework built with least-privilege IAM and encryption at rest/in transit as first-class concerns. Compliant with NIST SP 800-53 and CIS AWS Foundations.

TerraformIAMKMSLambdaDynamoDB
nfx // Personal Trading Journal

03nfx // Personal Trading Journal

A journal for tracking and reviewing discretionary trades and strategy adherence. Features strict multi-user data isolation and secure authentication via an automated CI/CD pipeline.

ReactTypeScriptFirebaseVercel
Roam.io

04Roam.io

A fog-of-war style location exploration app built with a student team. Co-led as project manager and contributed roughly half of the development work.

FlutterDartFirebase
Record

Roles, certifications, and timeline.

Bachelor of Software Engineering (Honours)

Expected 2027
Monash UniversityPending

AWS Solutions Architect Associate (SAA-C03)

In Progress
Amazon Web ServicesPending

CompTIA Security+

In Progress
CompTIAPending

Google Cybersecurity Professional

Completed
GoogleVerified

Coursera CompTIA A+

Completed
CourseraVerified

GMP Processor

2022 — 2026
Ensign LaboratoriesVerified

Managed risk-minimisation and quality control under strict regulatory compliance frameworks and Standard Operating Procedures (SOPs).

Writing

Notes on cybersecurity and markets.

I write regularly about cloud security patterns, engineering for compliance, and how systems can be designed to make risk legible.

Read the full archive
In Progress

What's next.

[ Certifications ]

  • Completing CompTIA Security+
  • Completing AWS Solutions Architect Associate (SAA-C03)

[ Engineering ]

  • Building more agents to automate tasks
  • Expanding my IaC and Cloud Architecture knowledge

[ Career ]

  • Seeking graduate and internship opportunities in cloud security and GRC
  • Exploring opportunities across the broader cloud landscape
Status: Open

Let's talk.

Open to graduate roles, internships, and conversations about cloud security, GRC, or the tools in between.

nfx@nunesfx.com