Start of main content

DevSecOps & Cloud Infrastructure

I build cloud platforms that have to work at 3 am.

Payments, healthcare, aviation and retail — on AWS, Azure and GCP. I design for the security audit as hard as for the outage.

20+ Years in IT infrastructure

20,000+ Servers on automated patching

~300 Services migrated, zero downtime

Approach

How I work

  1. Design for the failure, not the demo.

    Multi-AZ data, multi-region clusters, restores that have actually been run — and blast radius drawn on purpose, so one compromised account cannot reach the next tenant.

  2. If it isn't in Git, it doesn't exist.

    Terraform provisions, Argo CD syncs, and any environment can be rebuilt from the repo without a single console click.

  3. Hand it back operable.

    Dashboards, alerts and runbooks that name the cause, so the team on call doesn't need me at 3 am.

Services

What I do

Seven things, all of them hands-on.

  • Cloud architecture

    Multi-region AWS, Azure and GCP designs: networking, identity, data paths, and the failure modes behind them.

  • Kubernetes platforms

    EKS, AKS and GKE with Gateway API, Istio, KEDA and Karpenter. Multi-tenant, and boring to operate.

  • Infrastructure as Code

    Terraform and Terragrunt modules with OIDC-based CI, so every environment is rebuildable from Git.

  • CI/CD & automation

    GitLab CI, GitHub Actions and Azure DevOps feeding Argo CD. Git becomes the deploy button.

  • Security & compliance

    Segmented subnets, private endpoints, secrets in Vault. CISA-aligned patch baselines across a whole AWS Organization, with the compliance evidence an audit asks for.

  • Observability

    Metrics, logs and traces wired into the on-call rotation, so a 3 am page points at the cause.

  • Mentoring & coaching

    Coaching for engineers moving into cloud, Kubernetes and DevOps — 15+ senior and mid-level engineers so far, taught from production rather than slides.

Architectures

Reference architectures

Six platforms I have built, drawn the way they actually run.

Reference architectures and sector examples here are anonymized. Client names stay confidential.

AWS · API & EKS

Text description follows.

  • Route 53
  • ACM
  • API Gateway
  • Lambda
  • EKS
  • AWS Batch

DNS & TLS

Route 53 public zone to an ACM cert, through CloudFront/WAF, into an API Gateway custom domain.

Compute

Lambda for edge logic, VPC Link to the internal ALB, EKS pods with IRSA, AWS Batch for async jobs.

Data

Aurora Multi-AZ, S3 for job I/O, Secrets Manager. Multi-region EKS behind private Route 53 zones.

Expertise

Stack and credentials

Certifications

  • AWS DevOps Engineer — Professional
  • AWS Solutions Architect — Professional
  • AWS Advanced Networking — Specialty
  • Certified Kubernetes Administrator (CKA)
  • HashiCorp Certified: Terraform Associate
  • Microsoft Certified: Azure Administrator Associate (AZ-104)

Alongside the certificates: Red Hat Enterprise Linux and Cisco networking in the field, on air traffic management systems.

Cloud & platform

  • AWS · Azure · Google Cloud
  • Kubernetes · Docker · Helm
  • Terraform · Terragrunt · Vault
  • Gateway API · Istio · KEDA · Karpenter

Delivery & data

  • GitLab CI · GitHub Actions · Azure DevOps
  • Argo CD · Artifactory · Lambda · Batch
  • BigQuery · API Gateway · CloudFront
  • SSM Patch Manager · Private endpoints

Work

Selected work

Nine engagements, from air traffic control to the two products I helped start.

  • Aviation · ATM

    Flight data and pilot comms on Indra ATM

    Provisioned and hardened Red Hat Enterprise Linux servers carrying flight data and pilot communications, built the Cisco switching and routing underneath them with redundant links and segmented multicast domains, and integrated the result into the Indra ATM core. Airport work, on systems that do not get a maintenance window.

    • flight data & pilot comms servers
    • RHEL provisioning & hardening
    • Cisco switching, routing, multicast
    • Indra ATM integration
  • Healthcare · Azure/AKS

    Containerized clinical apps on private AKS

    Clinical applications on private AKS with Key Vault-backed secrets, private endpoints, audit logging and role-based access, rolled out on a staged plan so no patient data was ever exposed publicly.

    5+containerized applications

    120hphased deployment plan

    • zero public PHI exposure
  • Financial services · AWS EKS

    Multi-region payment platform on EKS

    EKS clusters across Canada and the US running payment batch workloads, with the whole estate provisioned from Terraform and Terragrunt modules rather than the console.

    6+EKS clusters

    13+payment batch jobs

    • multi-region CA + US
    • Terraform/Terragrunt
  • Education · GCP/GKE

    Gateway API migration on GKE

    Two isolated GCP projects on current Kubernetes, moved off legacy ingress onto Gateway API without disrupting the public hosts students and staff use every day.

    2dedicated GCP projects

    30+public ingress hosts

    • K8s 1.34-1.35
    • Gateway API migration
  • Enterprise security · AWS

    Patch compliance across an AWS Organization

    Patch baselines and maintenance windows across a mixed Linux and Windows estate, targeted by tags — EC2 across every account in the organization, and the servers still sitting in the company's own data centres, on the same schedule and the same reporting. Lambda turns the scans into the compliance and vulnerability reporting auditors ask for.

    20,000+servers on automated patching

    1,000+EC2 across multiple regions

    • Linux + Windows
    • cloud and on-prem
    • CISA-aligned baselines
    • AWS Organization
  • Retail · Kubernetes

    Store platform on autoscaling Kubernetes

    Moved roughly 300 business-critical services off Docker Swarm and onto Kubernetes without downtime — inventory, orders, payments and fulfilment kept trading throughout. The platform now runs on a small set of hardened base images and scales to zero with KEDA when the stores are closed.

    ~300services migrated, zero downtime

    700+retail locations

    22+application domains

    25+container base images

    • Docker Swarm -> Kubernetes
    • Terraform & Vault
    • KEDA scale-to-zero
  • Gaming & media · GCP

    Zero-downtime migration at 1M+ MAU

    CI/CD for a large microservice estate on GCP. Three live titles and the Spanner-to-BigQuery data move went across without a maintenance window.

    1M+monthly active users

    100+microservices CI/CD

    • zero-downtime migration
    • Spanner -> BigQuery
  • Scheduling SaaS · Visionary

    Product vision for Calendmax

    Visionary and product inspirer for Calendmax, a scheduling platform that takes the back-and-forth out of finding a time. It ships under the line Schedule Smarter, Live Better.

    • scheduling & calendar SaaS
    • product vision & growth
  • Reference architectures and sector examples here are anonymized. Client names stay confidential.

Readiness

Platform readiness check

Six questions on the things that decide whether an outage is an inconvenience or a weekend: IaC coverage, GitOps and delivery, observability, DR and backup, secrets, and on-call maturity. Nothing leaves your browser — no account, no email, no tracking.

This check needs JavaScript to run. Nothing leaves your browser either way.

    Contact

    Get in touch

    Tell me what's breaking, or what you're about to build.

    MaxDCloudOps Corp — South Carolina S-Corporation — Est. 2024
    EIN 99-3529933
    Indian Land, South Carolina

    Pick a time and it lands straight in my calendar — no back-and-forth about which Tuesday works.

    Booking runs on Calendmax, which is my own product. Prefer to write? Use the address on the left.

    Book a slot

    Runs on Calendmax. Rather write? maxdcloudops@gmail.com