PORTFOLIO [PLATFORM]
- CI/CD platform — ~45 build projects served by 9 shared pipelines, built and owned end to end. Event-driven, FIFO serialization per repository with distributed locking and hotfix preemption, cross-account releases.
- SOC 2 (Type 1 & 2) — both audits passed, compliance led from scratch: access control, deployment traceability, log retention, CVE scanning on container images, public edge locked down deny-by-default.
- Observability — ~$1,000/month of over-allocation identified and right-sized, 46,000 monthly throttled invocations surfaced and alarmed. Alarm baseline shipped as IaC across ~20 service repositories.
- Access as code — who can do what on AWS is declared in Git and applied automatically: least privilege across 27 services, every access change reviewed in a pull request instead of clicked in the console. Same SSO identities gate the VPN.
- Infrastructure as code — a console-built estate brought fully under Terraform/OpenTofu and SAM, with versioned shared modules teams reuse instead of copy-pasting.
More on LinkedIn.