Expertise
Technical skills and certifications across cloud, infrastructure and security
Technical Skills
Cloud & Platform
- AWS (EC2, EKS, VPC, IAM, S3, RDS, Lambda, CloudWatch)
- Kubernetes & Docker
- Helm
- Terraform (Infrastructure as Code)
- Ansible
- Auto-scaling & High Availability Architecture
Pipelines & Supply Chain
- GitHub Actions
- GitLab CI
- OIDC Federation (no long-lived credentials)
- Gitleaks (secret scanning)
- Trivy (container & dependency scanning)
- SonarQube (static analysis)
Detection & Response
- Graylog SIEM
- VictoriaMetrics
- Loki
- Grafana & Alertmanager
- Zabbix
- Incident Response & Root Cause Analysis
Security & Compliance
- IAM Hardening
- Network Segmentation (VPC Design, Security Groups, NACLs)
- AWS WAF
- IPsec
- CIS Benchmarks
- Compliance Frameworks (ISO 27001, PCI DSS, GDPR)
Systems & Programming
- Linux Administration
- Nginx
- APISIX (API Gateway, EKS ingress)
- Python (Boto3, pandas, scikit-learn)
- Bash Scripting
Certifications
AWS Certified Solutions Architect – Associate
Amazon Web Services
AWS Certified Cloud Practitioner
Amazon Web Services
CompTIA Security+ CE
CompTIA
Google Cybersecurity Certificate
Current Focus
My current work is production payments infrastructure: keeping it available, keeping it defensible, and being able to prove both. I'm particularly focused on:
- Reliability under real load: Running AWS and Kubernetes at 99.99% uptime against a 99.9% SLA, where every minute of downtime is a failed transaction.
- Supply chain and pipeline security: Security gates inside the pipelines engineers already use, and no long-lived cloud credentials anywhere.
- Detection and response: Observability and SIEM built to shorten the time between something going wrong and somebody knowing about it.
- Where I'm heading: Securing AI systems and training pipelines. My MSc dissertation applied machine learning to security detection, and that's the direction I want to take further. Stated as interest, not expertise.