Production work · cloud · platform · security
Systems that had to work.Not just look good on paper.
A selection of production engineering work across large AWS estates, migration programs, delivery automation, secrets infrastructure, and vulnerability management. Several backend services, scripts, and other components were developed with AI assistance, while design, validation, and operational responsibility stayed human-led.
01 / Cloud governance
CloudCage
An AWS Organizations metadata system that turned fragmented account information into a usable cloud solution for ownership, visibility, and operational decision-making.
- API Gateway
- Flask
- FastAPI
- Kubernetes
- Helm
- AWS Lambda
- AWS Document DB
- AWS DynamoDB
- Python
- Docker
- Next.js
- GitLab
- AWS BOTO3
- pytest
- DataDog
- CloudWatch
- AWS Organizations
- Terraform
02 / Cloud cost governance
Cloud Cost Governance
Drove roughly $5M in annual cloud savings by identifying orphaned, underutilized, and oversized resources across a large AWS environment. The work increased owner accountability and drove remediation that improved cost discipline and platform hygiene.
- AWS Org
- AWS Glue
- AWS Cost Explorer
- AWS Compute
- Trusted Advisor
- Athena
- Python
- S3
- EC2
- AWS System Manager
- Lambda
- Cost Anomaly
03 / AI-assisted migration and scanning
AMI Migration
Migrated thousands of non-standard AMIs into a security-scanning workflow for SecOps. Several components were developed with AI assistance, then validated against SecOps security-scanning requirements and operational constraints. The work saved tens of thousands of dollars in scanner licensing and server costs.
- Python
- S3
- AWS Boto3
- CloudFormation
- pytest
- AWS AMIs
- AWS Inspector
- Gitlab
04 / Delivery automation
Proxy Server Automation
Modernized proxy-server delivery by combining reusable pipeline automation with runtime readiness checks. The lesson was simple: infrastructure being up does not mean the service is operational.
- HAProxy
- Docker
- AWS Inspector
- AWS AMI
- ALB
- ASG
- GitLab
05 / AI-assisted secrets reliability
HashiCorp Vault Repair and Improvement
Restored trust in a degraded secrets platform by addressing architecture, automation, TLS recovery, observability, failover behavior, and the handoff to SRE ownership. AI assisted the reference research and script development; the repair and operational decisions remained human-led.
- EC2
- HashiCorp Vault
- TLS certificate management
- BASH
- GitLab
- Datadog
- Grafana
06 / Security operations
Vulnerability Management Services
Built operational controls around a high-volume vulnerability workflow: identify findings, validate the affected AMI and service health, check closure, and report by account.
- CVE workflows
- AMI remediation
- AWS accounts
- Terraform
- Python
- BASH
- AWS Inspector
- AWS Systems Manager
- Docker
07 / High-traffic publishing
News and Sports Websites
Led the News and Sports site redesign with a 15-person developer and UX team, and led the Bright House Networks Residential, SMB, and Enterprise pre-sales web designs with the same team. Trained implementation engineers on the deployment process and liaised with DevOps to standardize News/Sports deployments and automation.
- Adobe Experience Manager
- Varnish
- High-traffic publishing
- BASH
- Linux
- HTML
- JavaScript
- Groovy
- Java
- Maven
08 / AWS security response
AWS Security Incident Response
Led a 12-person engineering team through the response to an AWS security incident, coordinating with SecOps and senior leadership to contain the incident, investigate affected access, and rebuild the organization’s security boundaries.
- AWS Organizations
- IAM
- SSO
- Keycloak
- Secrets Manager
- Logging
- Automation scripts
- WAF
- Firewalls
- Security scanning
09 / Project and asset inventory
Project and Asset Inventory and Documentation
As a Principal Engineer acting as product manager—and one of three Principal Engineers on the effort—coordinated a 12–15-person project to recover a decade of undocumented engineering work. Led a three-engineer team through a six-week scripted and manual repository inventory, then coordinated the wider team through an 11-week documentation effort.
- Scripted repository discovery
- Manual validation
- Archive workflow
- Documentation templates
- Git/GitLab
- Terraform
- Docker