pa@dev:~$ cat experience.log
experience.log
● CURRENT
Tech Lead, DevOps & Managed Services
Run the managed-services vertical: five enterprise customers across AWS, GCP and Azure. I set the milestones, verify delivery readiness ahead of each release, and run the customer syncs that align on the value being delivered, while carrying a delivery load alongside the engineers I delegate to. Fortnightly portfolio reporting to founders is generated from each cycle's activity rather than hand-assembled.
> Managed Services Practice: Five-customer portfolio across three clouds. Proactive milestones set per engagement, delivery readiness verified before each release, and regular customer syncs to align on delivered value. Work is delegated across a team, but I take a share of the delivery myself: migrations, cost analyses and incident RCAs. Fortnightly founder reporting is produced by a pipeline that classifies each cycle's activity per customer, measured on in-cycle completion rather than a burndown ratio.
> Platform Migration: Moved a production analytics platform off a shared AWS account into isolated managed accounts: 2 TB RDS Postgres, 13.9M DynamoDB items and 928K S3 objects with server-side encryption preserved end to end, plus 95 tables / 198M rows from Redshift to ClickHouse with resumable state. Traffic cut over inside a planned 2-hour window.
> Cost Engineering & Guardrails: Four guardrail policies (compute ceilings, instance-class allowlists) so teams self-serve inside enforced budgets instead of queuing for review. Cost-driver analyses across customer AWS organizations: lower environments right-sized, backup retention rebuilt for a 75% cut, spot pools diversified after an interruption outage, per-account budgets enforced.
> Zero Trust Access: Identity-aware Teleport access (SSH, Kubernetes, databases, internal apps) on the flagship account, retiring standing VPN and bastion access in favour of short-lived, audited sessions, then templated for portfolio-wide rollout.
> Shared Module Engineering: Extended shared Terraform modules backwards-compatibly instead of forking flavors: an optional IAM-statement escape hatch and conditional lifecycle rules landed with zero terraform diff across six existing consumers. Also fixed a Prometheus module that silently ignored its own retention field.
> K8s PostgreSQL Operator: Built a Go Kubernetes operator with CRDs for PostgreSQL users and permissions at scale. Version-controlled manifests replaced tickets, cutting dependency on a central team by 90%.
> Log Collector Integration: Integrated centralized log collection into the Facets platform using Grafana Loki, Promtail and MinIO with per-cloud long-term storage and component alerts: a 70% cut in time spent pulling logs out of cloud storage.
TeleportKubernetesTerraformHelmArgoCDPrometheusGrafana LokiClickHouseKyvernoGoPythonAWSGCPAzure
Digital Engineering Lead Consultant
Leading cloud infrastructure initiatives and developing reusable AWS CDK constructs/patterns for enterprise clients.
> Solar Turbines: Reusable AWS CDK constructs/patterns with CI/CD workflow using Azure Pipelines.
> BMW: Microservices on EKS, migration from On-Prem to AWS.
AWS CDKPythonAzure PipelinesAzure ArtifactsCookiecutterPre-commit
DevOps Engineer Sr. Specialist
SRE work and platform engineering for various enterprise clients.
> AT&T (SRE): Improving performance and adding features to USM Anywhere security monitoring tool.
> Platforms Team: Integrating Cloud Custodian with MS Teams, creating security policies.
JavaSpring BootRundeckCloud CustodianAWS Lambda
DevOps Engineer
Infrastructure as Code and cloud migration projects.
> Medifast: Migration of 4TB MySQL database from On-Prem to AWS RDS using DMS.
> CBRE: Creating reusable Terraform modules and application patterns.
> Platforms Team: Serverless framework for automated tests, backup solutions.
TerraformAnsibleAWS DMSServerlessTerratest
Software Engineer
Started DevOps journey working with AWS services and application support.
> BT (DevOps): Managing AWS infrastructure, Lambda development, RDS management.
> App Support: Incident management, deployments, server maintenance.
AWS EC2LambdaRDSS3JavaShell Script
// end of experience.log