← Back to About Me

Production work · cloud · platform · security

Systems that had to work.Not just look good on paper.

A selection of production engineering work across large AWS estates, migration programs, delivery automation, secrets infrastructure, and vulnerability management. Several backend services, scripts, and other components were developed with AI assistance, while design, validation, and operational responsibility stayed human-led.

~$5Mannual cloud savings through cost governance
Thousandsof non-standard AMIs migrated for security scanning
9 storiesacross cloud, security, automation, and publishing

01 / Cloud governance

CloudCage

An AWS Organizations metadata system that turned fragmented account information into a usable cloud solution for ownership, visibility, and operational decision-making.

Led the engineering teamDirected a team of engineers building the internal cloud solution.
Large AWS estateDelivery evidence covers 170+ accounts, with the broader environment spanning 500+ accounts.
Shared operational viewCreated a system of record for account metadata and ownership across cloud operations, finance, and security.
Technology
  • API Gateway
  • Flask
  • FastAPI
  • Kubernetes
  • Helm
  • AWS Lambda
  • AWS Document DB
  • AWS DynamoDB
  • Python
  • Docker
  • Next.js
  • GitLab
  • AWS BOTO3
  • pytest
  • DataDog
  • CloudWatch
  • AWS Organizations
  • Terraform

02 / Cloud cost governance

Cloud Cost Governance

Drove roughly $5M in annual cloud savings by identifying orphaned, underutilized, and oversized resources across a large AWS environment. The work increased owner accountability and drove remediation that improved cost discipline and platform hygiene.

Roughly $5M saved annuallyReduced annual cloud spending through targeted remediation across the AWS environment.
Accountability through visibilityConnected resource ownership to the spend that required action.
Cost and platform hygieneAddressed orphaned, underutilized, and oversized resources rather than treating spend as an isolated finance problem.
Technology
  • AWS Org
  • AWS Glue
  • AWS Cost Explorer
  • AWS Compute
  • Trusted Advisor
  • Athena
  • Python
  • S3
  • EC2
  • AWS System Manager
  • Lambda
  • Cost Anomaly

03 / AI-assisted migration and scanning

AMI Migration

Migrated thousands of non-standard AMIs into a security-scanning workflow for SecOps. Several components were developed with AI assistance, then validated against SecOps security-scanning requirements and operational constraints. The work saved tens of thousands of dollars in scanner licensing and server costs.

Thousands of non-standard AMIsMoved non-standard images into a repeatable security-scanning workflow for SecOps.
Tens of thousands savedReduced scanner licensing and server costs for the security operation.
Scanning at scaleUsed AMI provenance, cross-account S3 transfer, isolated rehydration, and aggregator services to support scanning, with AI-assisted components reviewed and validated as part of the implementation.
Technology
  • Python
  • S3
  • AWS Boto3
  • CloudFormation
  • pytest
  • AWS AMIs
  • AWS Inspector
  • Gitlab

04 / Delivery automation

Proxy Server Automation

Modernized proxy-server delivery by combining reusable pipeline automation with runtime readiness checks. The lesson was simple: infrastructure being up does not mean the service is operational.

Reusable delivery frameworkGitLab workflow templates, staged validation, fail-fast gates, and release automation.
140+ serversDeployment modernization across a large server estate, reducing cycles from weeks to hours.
Readiness before trafficCorrected missing container startup configuration and added Datadog synthetic validation before shifting traffic.
Technology
  • HAProxy
  • Docker
  • AWS Inspector
  • AWS AMI
  • ALB
  • ASG
  • GitLab

05 / AI-assisted secrets reliability

HashiCorp Vault Repair and Improvement

Restored trust in a degraded secrets platform by addressing architecture, automation, TLS recovery, observability, failover behavior, and the handoff to SRE ownership. AI assisted the reference research and script development; the repair and operational decisions remained human-led.

250+ production systemsSupported a platform serving more than 250 production applications or systems.
Degraded clusterWorked through a two-node healthy state in a five-node cluster instead of treating symptoms as normal.
Operational handoffAdded Datadog observability, failover testing, recovery automation, and documentation for sustainable support.
Technology
  • EC2
  • HashiCorp Vault
  • TLS certificate management
  • BASH
  • GitLab
  • Datadog
  • Grafana

06 / Security operations

Vulnerability Management Services

Built operational controls around a high-volume vulnerability workflow: identify findings, validate the affected AMI and service health, check closure, and report by account.

100k+ monthly findingsCollective incoming CVE findings across the AWS estate, with scope kept explicit.
AMI remediationUsed scripted health validation and account-specific reporting to support remediation work.
Critical and High closureFocused closure checks and audit-conscious reporting without claiming every finding was remediated by one team.
Technology
  • CVE workflows
  • AMI remediation
  • AWS accounts
  • Terraform
  • Python
  • BASH
  • AWS Inspector
  • AWS Systems Manager
  • Docker

07 / High-traffic publishing

News and Sports Websites

Led the News and Sports site redesign with a 15-person developer and UX team, and led the Bright House Networks Residential, SMB, and Enterprise pre-sales web designs with the same team. Trained implementation engineers on the deployment process and liaised with DevOps to standardize News/Sports deployments and automation.

15-person design and engineering teamLed the News/Sports redesign and Bright House Networks Residential, SMB, and Enterprise pre-sales web designs.
31 sites · 12-node AEM CMSManaged the local and regional publishing platform through Adobe Experience Manager and Varnish.
5M visits per hourSupported extreme traffic during weather and election events through Varnish web caching and platform readiness work.
Technology
  • Adobe Experience Manager
  • Varnish
  • High-traffic publishing
  • BASH
  • Linux
  • HTML
  • JavaScript
  • Groovy
  • Java
  • Maven

08 / AWS security response

AWS Security Incident Response

Led a 12-person engineering team through the response to an AWS security incident, coordinating with SecOps and senior leadership to contain the incident, investigate affected access, and rebuild the organization’s security boundaries.

Triage in about one weekCoordinated the initial response, identified the access path, closed immediate holes, and determined what systems and services required investigation.
Identity and access lockdownRemoved interactive IAM accounts, moved users to SSO, made 2FA mandatory, and rotated service credentials through Secrets Manager.
6–9 month hardening effortSegmented AWS management responsibilities, moved the master payer account, expanded logging and automation, and restricted admin access to approved temporary use.
Technology
  • AWS Organizations
  • IAM
  • SSO
  • Keycloak
  • Secrets Manager
  • Logging
  • Automation scripts
  • WAF
  • Firewalls
  • Security scanning

09 / Project and asset inventory

Project and Asset Inventory and Documentation

As a Principal Engineer acting as product manager—and one of three Principal Engineers on the effort—coordinated a 12–15-person project to recover a decade of undocumented engineering work. Led a three-engineer team through a six-week scripted and manual repository inventory, then coordinated the wider team through an 11-week documentation effort.

~500 repositories reviewedUsed scripted discovery and keyword lookups to identify repositories, then manually validated whether each project was still in use.
~150 active projects retainedMoved inactive work to an archive group and focused the documentation effort on projects that remained operationally relevant.
Less rework, stronger knowledge baseEstablished common documentation expectations, improved code-storage policies, and made existing tools easier to understand and maintain.
Technology
  • Scripted repository discovery
  • Manual validation
  • Archive workflow
  • Documentation templates
  • Git/GitLab
  • Terraform
  • Docker
Return to the full portfolio