AWS Architecture
EC2, VPC, S3, RDS, Lambda, Route 53, CloudFront, Transit Gateway, IAM, WAF and CloudWatch.
AWS · AZURE · GCP · TERRAFORM
I take cloud infrastructure from requirement to running system: Terraform for every environment, pipelines for every release, least-privilege access and monitoring from day one.
HOW I BUILD
ABOUT
I design, automate and operate AWS infrastructure, weighing security, reliability, cost and maintainability on every decision.
My work spans cloud networking, identity and access management, monitoring, high availability, disaster recovery and CI/CD. I turn business requirements into infrastructure that is documented, repeatable and easy for the next engineer to operate.
I also bring more than ten years across operations, finance and technology. That background is why I frame technical choices in terms of risk, cost and delivery speed, explain them clearly to non-technical stakeholders, and own a problem from first requirement to a running, monitored system.
CORE CAPABILITIES
EC2, VPC, S3, RDS, Lambda, Route 53, CloudFront, Transit Gateway, IAM, WAF and CloudWatch.
Terraform modules, reusable environments, remote state and multi-region stacks.
GitHub Actions, Jenkins, AWS CodePipeline, CodeBuild, Bash and Python.
Least-privilege IAM, short-lived credentials, AWS WAF, secrets management, encryption and network segmentation.
CloudWatch dashboards, logs and alarms, SNS alerting, RDS Multi-AZ and S3 Cross-Region Replication.
Python, REST APIs, Git/GitHub, GitHub Apps, JWT and event-driven automation.
EXPERIENCE
BKS
PCS
CERTIFICATION
Validated knowledge of secure, resilient, high-performing and cost-optimised AWS architectures.
SELECTED WORK
Each one is provisioned end to end in Terraform. Source is kept private; I’m happy to walk through the design or demo any of them live.
AWS SERVERLESS • SECURITY • TERRAFORM
Replaces long-lived Git credentials with short-lived, repository-scoped access that is requested, evaluated against policy, approved where required, issued, used and revoked. A Git gateway mints and enforces repo-scoped GitHub App tokens at clone time, behind an auditable grant state machine with replay protection.
AWS SERVERLESS • PYTHON • TERRAFORM
API Gateway receives POST /intake, a Python Lambda validates the request and writes to RDS MySQL. No servers to patch, and nothing sensitive in the codebase.
AWS • SECURITY • TERRAFORM
Locked-down infrastructure as code: CloudFront and AWS WAF in front of the application, least-privilege access throughout, and automation that writes its own incident reports when something breaks.
AWS • NETWORKING • TERRAFORM
A private three-tier stack (VPC → EC2 → RDS) provisioned entirely in Terraform, with application and data tiers kept off the public internet.
MULTI-REGION • RESILIENCE • TERRAFORM
A production-shaped stack across Tokyo and São Paulo: ALB with real TLS, AWS WAF, a CloudFront CDN and cross-region Transit Gateway, all from one Terraform codebase.
AWS • STATIC HOSTING • CI/CD
The site you’re reading: delivered through S3, CloudFront, Route 53 and ACM over HTTPS, deployed by pipeline with automatic cache invalidation on every push.
ARCHITECTURE
Every diagram maps to infrastructure I’ve built and deployed in Terraform. Select one to view it full size.
ON GITHUB
Pulled live from GitHub, so the latest public work always shows here.
CONTACT
I’m open to remote Cloud Platform, DevOps and Infrastructure Engineering roles, and happy to walk through any project above in detail.