Graduate Education
Master of Professional Science (MPS), Information Science
Concentration in Geographic Information Science
Unity Environmental University
Graduated: 2021
GPA: 3.97AWS Cloud Engineering • Platform Automation • Governance • Security
I design, automate, secure, and support enterprise cloud environments, with deep AWS experience and additional Azure, GCP, and hybrid infrastructure experience across cloud engineering, cloud administration, platform automation, and production operations.
About
I design, automate, secure, and support enterprise cloud environments, with deep AWS experience and additional Azure, GCP, and hybrid infrastructure experience across cloud engineering, cloud administration, platform automation, and production operations.
My background includes cloud platform engineering, cloud architecture, DevOps automation, infrastructure design, cloud migrations, CI/CD delivery, identity and access management, governance, monitoring, security operations, cost optimization, production support, and application delivery support.
My strongest hands-on work is in AWS, including multi-account environments, secure infrastructure operations, Terraform and CloudFormation automation, compliance-aligned support, and production workload reliability. I also bring Azure and GCP experience across identity, governance, cloud operations, and hybrid infrastructure support.
I bring a cloud engineering background where architecture, automation, security, and operations intersect, supporting environments that require reliability, governance, scalability, and production readiness.
Current Operating Scope
Multi-account governance, access, security, and platform operations.
Release workflows supporting application and platform delivery.
Cloud operations aligned to business and technical stakeholders.
PROJECTS
Select a project to view architecture, scope, impact, and tools.
Built and maintained repeatable infrastructure deployment patterns using CloudFormation templates, StackSets, Azure DevOps pipelines, YAML pipeline definitions, template validation, approval stages, and automated updates when accounts were created, moved, or added to deployment scope.
Implemented and maintained governance patterns for a multi-account AWS environment using Control Tower, AWS Organizations, IAM role baselines, SCPs, CloudTrail, AWS Config, Security Hub, and account separation across production, pre-production, shared services, audit, security, and sandbox-style accounts.
Built containerized application delivery patterns using Docker, container image workflows, private registry patterns, and cloud-native container services. The work connects local container builds, image tagging, registry workflows, CI/CD pipelines, runtime configuration, service exposure, logs, and operational troubleshooting across ECS and EKS-style deployments.
Designed serverless application patterns where users access a web front end through static hosting and CDN-style delivery, API Gateway receives application requests, Lambda handles backend logic, and managed AWS services store data, logs, and application artifacts.
Built and operated a Linux web-hosting stack on an Ubuntu EC2 instance covering the full path from server provisioning to public website delivery. The work covered package installation, service validation, Apache virtual hosts, MySQL database setup, PHP integration, WordPress deployment, DNS routing, Elastic IP usage, and HTTPS configuration.
/var/www, Apache config under /etc/apache2, logs under /var/log/apache2, Route 53 DNS, Elastic IP, and Certbot TLS.
Delivered security visibility using Security Hub, AWS Config, CloudTrail, CloudWatch, account-to-business-unit mappings, OU-level findings aggregation, CSV reporting to S3, and quarterly evidence gathering for remediation and stakeholder review.
Managed EC2 fleet operations through AWS Systems Manager, centralized node visibility, inventory, patch scan associations, Resource Explorer views, managed execution, and operational runbook patterns that reduced dependency on direct SSH/RDP access.
Built and maintained automated credential rotation for SES SMTP and IAM access key workflows. The automation used scheduled Lambda execution, DynamoDB configuration tables, role assumption, target storage updates, verification, rollback handling, CloudWatch alarms, and SNS notifications.
Managed DNS and resilience operations using Route 53 hosted zones, private hosted zones, internal DNS patterns, DNS backup automation, disaster recovery planning, certificate validation workflows, and failover-ready operating documentation.
Contributed to quarterly cloud reviews that combined AWS Config, Security Hub, Trusted Advisor, CloudHealth, tagging evidence, rightsizing checks, stale resource checks, and cost-saving opportunities for business and technical stakeholders.
Managed cloud email operations and migration planning across Amazon WorkMail, SES, Route 53, identity integration, shared mailboxes, inbound/outbound mail flow, DNS records, and migration planning toward Zoho Mail with coexistence and rollback considerations.
Architecture Patterns
Control Tower customization, landing-zone prerequisites, account management, shared-resource buckets, Security Hub setup, StackSet deployment, baseline roles, service-linked roles, CloudWatch, CloudTrail, and AWS Config foundations.
IAM restriction SCPs, VPC and SSM guardrails, DNS access controls, permission boundaries, SAML/SSO role templates, access key controls, privileged-role exceptions, and account-level security standards.
Lambda-based Security Hub findings aggregation, account-to-business-unit mapping, high/critical finding filtering, CSV reporting to S3, control summaries, and evidence used for stakeholder-facing AWS reviews.
Organization-wide Systems Manager visibility using Resource Explorer views, patch scan associations, State Manager patterns, managed execution, inventory management, and operational visibility for EC2 fleets.
Route 53 hosted-zone backup automation, S3 archive storage, SES status notifications, centralized ALB ingress patterns, TLS policy enforcement, HTTP-to-HTTPS redirects, and DNS operations for recovery workflows.
Azure DevOps YAML pipelines, CloudFormation template validation, StackSet delivery, key cycling automation, tagging automation, deployment stages, approval gates, and production troubleshooting runbooks.
Credentials
Graduate Education
Concentration in Geographic Information Science
Unity Environmental University
Graduated: 2021
GPA: 3.97AWS Certification
Active: May 10, 2025 - May 10, 2028
Validation: WNGJFFVC7EB4QH97 View certificateAWS Certification
Active: August 25, 2023 - August 25, 2026
Validation: 2LVZ8B9CWBRQ1RSF View certificateContact
Cloud platform, governance, automation, and production operations contact.