Microsoft MVP (Cloud & Code Security)
Cloud Security
Multi-cloud security and technical advisory expertise from discovery and technical sales to solution design, PoCs and delivery.
AI Security
Hands-on security for generative AI and agentic systems.
DevSecOps
Leading DevSecOps programmes that change how software is built and released.
80% of high and critical findings remediated within two weeks before go-live.
Focus: Azure, AKS, Azure DevOps and CI/CD security
Sector: Retail
100% of critical attack paths remediated across development and production environments in a multi-cloud organisation.
Focus: CNAPP, Cloud posture, DevSecOps
Sector: Public Sector
684 High-severity cloud misconfigurations remediated in three months.
Focus: CNAPP adoption, remediation workflows and DevSecOps ownership
Sector: Public Sector
Supported multi-cloud CNAPP selection for a healthcare organisation through a Defender for Cloud workshop.
Focus: Technical pre-sales, PoV design and technical validation
Sector: Healthcare
About: Jakub Fras
I’m a Senior Cloud Security Consultant at Bridewell and a Microsoft Security MVP, with a deep passion for cloud security, AI security and DevSecOps.
I lead multi-cloud security engagements across Azure and AWS. I partner with CISOs and CTOs to translate technical findings into business risks and investment priorities, supporting informed security decisions. I champion shared security ownership by working directly with developers, security teams and platform engineers to remediate findings, implement controls and build security into how cloud services are developed and operated.
My work spans the full customer engagement lifecycle from discovery and solution design through technical and commercial proposals, demonstrations, PoCs and PoVs, to implementation. I turn business requirements into security designs and roadmaps clients can execute.
My experience spans Microsoft Defender XDR design and implementation, in addition to deep expertise across CNAPP platforms including Microsoft Defender for Cloud, Wiz and Orca Security, with working familiarity in Cortex Cloud. My expertise also spans DevSecOps strategy and roadmap development, application security, Kubernetes and container security, AI security, and technical pre-sales. My DevSecOps work draws on SME-level knowledge of developer workflows and CI/CD across GitHub and Azure DevOps, integrating Infrastructure as Code security, SAST, DAST, SCA and SBOM capabilities to identify code, dependency and configuration risks earlier in the development lifecycle.