About Me
Senior Cloud Engineer with 8+ years of experience supporting and operating production systems across AWS, Azure, and GCP. Expert in infrastructure automation, security orchestration, and site reliability engineering. Proven track record of reducing operational toil through CI/CD pipelines, secrets management, and cloud cost optimization.
Key Projects
Secrets Management at Scale
Designed and implemented HashiCorp Vault and AWS Secrets Manager across application and infrastructure workloads, enabling secure access for 300+ developers and integrating secrets into GitLab CI/CD for Terraform deployments.
$30K/Month Cloud Cost Savings
Designed and implemented a data-driven cost governance process using Vantage, identifying orphaned EBS volumes across AWS regions, coordinating owner approvals, and automating remediation.
GitOps-Driven Terraform Workflows
Architected GitOps-driven Terraform workflows using GitLab CI, enforcing plan-before-apply controls to eliminate configuration drift and accelerated developer onboarding by 80%.
100% SecOps Compliance
Standardized SSM-based access and removed SSH across production fleets using Ansible, achieving 100% SecOps compliance across the entire infrastructure estate.
Multi-Cloud Kubernetes Platform
Delivered a managed multi-cloud Kubernetes platform across EKS, GKE, and AKS using ArgoCD and Helm, enabling GitOps-driven, self-service application deployments for development teams.
Work Experience
Senior Cloud Infrastructure Engineer
Ripple — San Francisco, CA
- Built and maintained Bash-based automation frameworks that reduced customer deployment cycles from 2 hours to 15 minutes, improving release velocity and operational reliability.
- Integrated Semgrep into GitLab CI pipelines, shifting security left by automating static analysis and identifying vulnerabilities earlier in the SDLC.
- Automated DNS and SSL/TLS certificate monitoring using Datadog and Grafana, preventing downtime through proactive 30-day expiration alerts.
- Enforced least-privilege access by authoring custom HashiCorp Vault HCL policies, eliminating static secrets across production workloads.
- Collaborated on Go and Java code changes to resolve a production OOM incident impacting database-backed services.
- Implemented blue/green EC2 deployments using HAProxy load-balancer switching, enabling zero-downtime releases for bare-metal workloads.
- Standardized IAM and RBAC across AWS and GCP, enforcing least-privilege access through group-based provisioning and structured GCP project folder hierarchies.
Cloud Engineer
Renegade Bio — Oakland, CA
- Supported CI/CD and observability improvements to stabilize data and analytics workloads.
- Operated and scaled GKE clusters in production, resolving incidents and implementing GitOps deployments with ArgoCD.
- Partnered with data science teams to optimize infrastructure, improving deployment reliability and MTTR.
- Provisioned GCP and Azure infrastructure using Terraform, reducing manual operations through Ansible-based patching.
Security Operations Center Analyst
Cognizant — San Francisco, CA
- Enforced cloud security guardrails by deploying AWS Service Control Policies (SCPs) to block unencrypted volumes and snapshots organization-wide.
- Correlated and responded to cloud security threats using Microsoft Sentinel and AWS GuardDuty.
- Remediated OS-level vulnerabilities across Windows and Linux fleets using AWS Systems Manager and Tanium.
Technical Support Engineer
Gidibase LLC — Oakland, CA
- Administered Google Workspace, managing user lifecycle automation for onboarding and offboarding to support secure, scalable collaboration.
- Implemented Okta SSO, centralizing authentication across internal applications and improving access consistency and user experience.
Technical Skills
☁️ Cloud Platforms
🏗️ Infrastructure as Code
🔄 CI/CD & DevOps
🔒 Security & Networking
📊 Observability
☸️ Containers & Orchestration
💻 Scripting & OS
Education & Certifications
🎓 Education
🏅 Certifications
- AWS Certified SysOps Administrator – Associate
- HashiCorp Certified: Terraform Associate (003)
- LFS458: Kubernetes Administration
- AWS Certified Cloud Practitioner