About
Sonny Enchill
Cloud & DevOps Engineer | Cybersecurity & SOC
19 years of enterprise IT experience, the last decade as sole owner of cybersecurity posture and IT governance for a regulated financial services organisation — now specialising in security operations, cloud infrastructure, and DevOps delivery.

Background
Who I Am
A DevOps and cybersecurity professional with a foundation that most candidates in this space simply do not have: 19 years of hands-on enterprise IT experience, the last decade spent as the sole owner of cybersecurity posture, cloud transformation, and IT governance for a regulated financial services organisation reporting directly to the board.
That background — accountability for security in a regulated environment, not just exposure to it — is what I bring into my next role. Combined with an awarded MSc in Cybersecurity and current hands-on DevOps engineering, I now operate at the intersection of security operations, cloud infrastructure, and DevOps delivery.
The Journey
The Transition
Leaving a senior IT leadership role to pursue an MSc and rebuild as a hands-on technical practitioner was a deliberate decision, not a drift. I wanted to move from managing security policy to doing security work — from overseeing cloud adoption to architecting and deploying cloud infrastructure myself.
MSc Cybersecurity covering incident response, SIEM, digital forensics, penetration testing, threat modelling, and cloud security — awarded 2025. Alongside that, a series of production-grade DevOps assignments across AWS, Azure, and Terraform — building systems from scratch, breaking them deliberately, and fixing them under operational discipline.
Differentiators
What Makes Me Different
Security depth with operational context
Accountability for a regulated organisation's security posture for nearly a decade — not advisory oversight, not academic study.
Dual-cloud, hands-on engineering
AWS and Azure are not theoretical. Three-tier architectures, private networking, IAM, Terraform stacks — built and shipped on both platforms.
DevSecOps from the start
Every pipeline I build includes security by design: secrets handling, access governance, and validation gates — not bolted on after.
Agentic AI in infrastructure
Applied Claude Code and MCP subagents to infrastructure security reviews and automated deployment pipelines — a capability few practitioners currently hold.
Financial services regulatory literacy
GDPR, UK GDPR, business continuity, audit trails, and board-level reporting — not concepts I have read about, but disciplines I have practised for nearly a decade.
Job Search
Roles I'm Targeting
SOC / Cybersecurity Analyst
SIEM, incident response, threat detection, log analysis
Cloud Engineer (AWS / Azure)
Infrastructure design, IaC, multi-cloud deployment
DevOps / DevSecOps Engineer
CI/CD pipelines, automation, security-first delivery
Credentials
Certifications & Education
MSc Cybersecurity
Robert Gordon University, Aberdeen
Awarded 2025CompTIA Security+ (SY0-701)
CompTIA
Exam Scheduled August 2026MCSA: Windows Server 2012
Microsoft
CertifiedMicrosoft Certified Professional (MCP)
Microsoft
CertifiedUltimate Agentic AI DevOps with Claude Code
Udemy
Completed 2026Ready to see the work?
14 projects across DevOps, cloud, and cybersecurity.