Work

Selected engagements

Enterprise AWS architecture delivered as the accountable principal architect. Current clients are described, not named.

Mar 2026 — Present

AWS platform engineering & edge migration for live game titles

Global mobile & web gaming publisher — via a consulting partner

Own the Terraform platform behind three live titles across multiple accounts, six EKS clusters and eleven Aurora clusters. Migrated seven production zones from Cloudflare to CloudFront, WAFv2 and Shield Advanced on budget. Designed multi-region DR for EKS, Aurora, Valkey and CI/CD as one parameter-driven workflow and validated it in a live failover drill. RabbitMQ 3.13→4.2 on Amazon MQ, AWS Backup PITR, EKS 1.35 with Karpenter, Security Hub FSBP. Ran a CloudFront/WAF workshop for 12 engineers.

TerraformEKSAuroraCloudFrontWAFv2Shield AdvancedAmazon MQValkeyAWS BackupSecurity Hub
Jul 2025 — Present

AI-native internal developer platform

Global IoT positioning & wireless semiconductor company

Principal architect of an agentic developer platform on Amazon Bedrock AgentCore, Lambda, EventBridge and DynamoDB: repo-discovery, architecture-compliance and RAG agents that gate GitLab merge requests and answer with cited sources. Cross-account GitLab OIDC deploy roles (CDK) across eleven AWS accounts; all AWS Security Agent findings remediated. HA self-managed GitLab for 500+ users, GitHub and SVN migration with full history, serverless company wiki.

Bedrock AgentCoreLambdaEventBridgeDynamoDBAWS CDKGitLab OIDCCognitoEntra IDReact
Aug 2023 — Present

Cloud platform, compliance archive & security operations

FCA-regulated fintech group

Control Tower landing zone with Security Hub, Google Workspace SSO into IAM Identity Center, GitLab OIDC CI/CD, ECS microservices streaming real-time market data, AppSync GraphQL and Managed Grafana. Immutable 7-year email archive on S3 Object Lock that also cut licensing ≈51%. Led the response to a P1 brand-impersonation attack, hardened SPF/DKIM/DMARC on ten domains, migrated Microsoft 365 to Google Workspace, designed US multi-region HA.

Control TowerIAM Identity CenterECSAppSyncS3 Object LockKMSManaged GrafanaTerraformGoogle Workspace
Jan 2024 — Dec 2025

Landing zone & multi-tenant Kubernetes for public-sector gas distribution

ReeVo Cloud & Cyber Security — public-sector end client

Control Tower, Security Hub and IAM Identity Center federated with Entra ID; hub-and-spoke Transit Gateway with Direct Connect and VPN failover; Network Firewall with Suricata. Multi-tenant EKS with namespace isolation, ArgoCD GitOps, Karpenter and NGINX ingress; Terraform observability modules; private NLB → API Gateway → CloudFront with WAF, Cognito and KMS.

EKSArgoCDKarpenterTransit GatewayDirect ConnectNetwork FirewallSuricataTerraformCodeCatalyst
Jan 2025 — Feb 2025

Connected-vehicle platform modernization

AWAKE Mobility — automotive IoT

Prod/Dev/QA multi-account architecture aligned to the Well-Architected Framework; Entra ID SSO with least-privilege permission sets; VPC segmentation and Network Firewall; credential-free Bitbucket CI/CD via IAM Identity Center; AWS Backup with cross-region replication; CloudFormation and Terraform.

Network FirewallEntra IDAWS BackupCloudFormationTerraformBitbucket