jpcloudengineering.com

jpcloudengineering.com

AWS Cloud & Infrastructure Engineer automating production cloud at scale.

8 years across software development and infrastructure, including 5 years designing, deploying, and operating multi-account AWS and Microsoft 365 environments — provisioning infrastructure as code with Terraform, building multi-environment CI/CD pipelines, and architecting cost-optimized, highly available, SOC 2-compliant systems. I also build full-stack serverless apps on AWS with Next.js when the project calls for it.

Profile

About

AWS cloud and infrastructure engineering, end-to-end

Designing, deploying, and operating production cloud — multi-account AWS and Microsoft 365 environments provisioned as code with Terraform, automated with multi-environment CI/CD, and hardened for SOC 2 compliance and Zero Trust access.

Profile Links

Check out my LinkedIn profile and GitHub.

I'm an AWS cloud engineer with 8 years of industry experience spanning software development and cloud infrastructure, including 5 years designing, deploying, and operating production AWS environments. I specialize in infrastructure as code with Terraform, multi-environment CI/CD pipelines, and secure, cost-optimized, highly available architectures — including a SOC 2–compliant platform running 30+ servers on a $200K–$250K annual cloud budget.

I'm hands-on across VPC and least-privilege IAM design, multi-account provisioning under AWS Organizations, disaster recovery, observability, and Zero Trust network access (ZTNA). I support multiple client engagements in parallel and translate complex technical issues for technical and non-technical audiences alike.

I also build full-stack serverless applications on AWS — Next.js and TypeScript frontends wired to Lambda-backed APIs — and contribute to open-source GPU tooling for Kubernetes, so I can take a system from infrastructure all the way to a shipped product.

Skills

Skills & Strengths

Visual proficiency bars inspired by service-status gauge styling, categorized by platform, tools, languages, operations, and communication.

Entry Level: 0% - 49%
Intermediary: 50% - 89%
Senior: 90% - 100%

AWS Cloud Platform

Amazon Web Services (AWS)

%

EC2 / VPC / IAM

%

Lambda / API Gateway

%

S3 / CloudFront / Route 53

%

AWS Organizations

%

ALB / CloudWatch

%

Aurora / RDS / DynamoDB

%

SQS / EventBridge

%

KMS / CloudTrail

%

Cognito

%

Amazon Bedrock / Polly

%

Parameter Store

%

Multi-Cloud (Azure & GCP)

Azure AKS

%

Azure Resource Groups

%

GCP GKE

%

GCP VPC Networking

%

GPU Node Pools

%

Entra ID / Azure AD

%

Containers & Orchestration

Kubernetes (EKS / AKS / GKE)

%

Helm

%

KEDA Autoscaling

%

NVIDIA GPU Operator

%

Docker

%

ECS Fargate / ECR

%

CI/CD & Infrastructure as Code

Terraform

%

SST

%

Pulumi

%

Ansible

%

GitLab CI/CD

%

GitHub Actions

%

Git

%

Monitoring & Observability

CloudWatch

%

DattoRMM

%

Grafana

%

Nagios

%

SNMP Monitoring

%

Scripting & Languages

PowerShell

%

Bash

%

Python

%

Java (Spring Boot)

%

JavaScript / TypeScript

%

Next.js / React

%

Go

%

C++

%

REST / WebSocket APIs

%

Networking & Email

VPC Design / NAT Gateways & Instances

%

Site-to-Site / Client VPN

%

SonicWall Firewalls

%

Cloudflare DNS / WAF

%

DNS / DHCP

%

VLANs / WAPs

%

MX / SPF / DKIM / DMARC

%

Email Filtering & Security

%

Microsoft Infrastructure

Active Directory (ADUC / ADCS)

%

Microsoft 365 / Entra ID

%

Remote Desktop Services

%

FSLogix

%

Group Policy / DNS / DHCP

%

Operating Systems & Platforms

Windows Server

%

Debian / Ubuntu Linux

%

Proxmox

%

VMware ESXi

%

Security

SOC 2 Compliance

%

CIS Baselines

%

Zero Trust Network Access (ZTNA)

%

DevSecOps in CI/CD

%

IAM Policies

%

Firewall Management

%

Prowler

%

LDAP / RADIUS

%

Nessus

%

Kali Linux

%

Tools

AI-Assisted Development (Claude Code)

%

Veeam Backup & Replication

%

Postman

%

Experience

Work Experience

8 years across software development and infrastructure — from Java development and frontline support into senior cloud engineering on AWS and Microsoft 365.

Senior Cloud Engineer

Direct IT

April 2023 – Present
  • Designed, deployed, and managed AWS and Microsoft 365 infrastructure for multiple clients in parallel, including a SOC 2–compliant environment running 30+ servers on a $200K–$250K annual cloud budget.
  • Designed and deployed a Zero Trust Network Access (ZTNA) solution for the SOC 2–compliant environment, enforcing identity-based access controls and eliminating implicit network trust.
  • Provisioned production infrastructure as code with Terraform — VPCs, EC2, least-privilege IAM, Lambda, and security groups across multiple accounts under AWS Organizations.
  • Architected and deployed highly available disaster recovery environments in AWS with Terraform, enabling routine DR testing and business continuity planning.
  • Built and maintained multi-environment CI/CD pipelines using GitLab CI/CD and GitHub Actions for repeatable dev, pre-production, and production deployments.
  • Used resource tagging and cost analysis to tune infrastructure for both technical performance and budget efficiency across client environments.
  • Deployed virtual SonicWall firewall appliances in AWS and built site-to-site VPN tunnels connecting on-premises networks to cloud environments.
  • Monitored infrastructure health and performance across 30+ servers using CloudWatch, Grafana, and DattoRMM spanning multiple client environments.

Support Engineer

Direct IT

July 2021 – April 2023
  • Resolved 15–20 support tickets daily across L1–L3 in cloud, networking, and on-premises environments, with weekly on-site client visits.
  • Administered Windows Server environments — Active Directory (ADUC, ADCS), Group Policy, DNS, and DHCP across multiple client domains.
  • Deployed on-premises SonicWall firewalls and configured NAT policies, access rules, client and site-to-site VPN, LDAP/RADIUS authentication, and VLAN segmentation.
  • Deployed and maintained Remote Desktop Services farms with FSLogix profile containers for optimized user session management.
  • Imaged and provisioned Debian-based Linux monitoring appliances tracking uptime, SNMP, storage, and HTTP/HTTPS availability across 1,000+ endpoints.
  • Wrote automation scripts in PowerShell, Bash, and Python to streamline repetitive infrastructure tasks.
  • Trained new engineers, resolved complex escalations, and coordinated with external vendors on hardware and software issues.

Junior Java Developer

Sullivan and Cogliano

February 2018 – March 2020
  • Developed and maintained Java applications under senior developer guidance, writing object-oriented code for new features and enhancements.
  • Built REST APIs in Spring Boot for CRUD operations.
  • Troubleshot and resolved application defects, collaborating with developers and QA across the software development lifecycle.

Projects

Web Applications and Cloud Engineering Work

Representative work focused on cost, reliability, deployment automation, and production observability.

keda-gpu-scaler

KEDA external scaler that autoscales Kubernetes GPU workloads from native NVML metrics. Open-source contributor (6 merged PRs) — 107 stars, 32 forks.

2026
  • Provisioned GPU-enabled Kubernetes clusters across EKS, AKS, and GKE with Terraform — custom VPC networking, GPU node pools, and NVIDIA GPU Operator/KEDA deployment via Helm; resolved a GKE-specific NVIDIA container toolkit CNI failure.
  • Created a pre-built Grafana dashboard for GPU fleet visibility (utilization, VRAM, temperature, power draw).
  • Added table-driven Go unit tests for the multi-GPU metric aggregation logic (max/min/avg/sum).
  • Authored the project's architecture documentation and diagrams.
KubernetesKEDANVIDIA GPU OperatorNVMLHelmTerraformGoEKSAKSGKEGrafana

gpu-mcp-server

MCP server giving AI agents real-time access to NVIDIA GPU metrics via NVML. Open-source contributor (4 merged PRs) — 12 stars, 14 forks.

2026
  • Provisioned GPU-enabled Kubernetes clusters across EKS, AKS, and GKE with Terraform — custom VPC networking, GPU node pools, and NVIDIA GPU Operator/KEDA deployment via Helm; resolved a GKE-specific NVIDIA container toolkit CNI failure.
  • Hardened the supply chain with CodeQL security scanning and OpenSSF Scorecard CI workflows.
  • Automated Docker image publishing on release via GitHub Actions.
MCPNVMLNVIDIA GPU OperatorKubernetesHelmTerraformDockerGitHub ActionsCodeQLOpenSSF ScorecardEKSAKSGKE

Remote Desktop Farm Modernization & Zero Trust Migration

Client engagement at Direct IT — rebuild and hardening of a production Remote Desktop Services farm in AWS, replacing gateway-fronted access with Zero Trust Network Access.

Aug 2025 – Jun 2026
  • Rebuilt an aging RDS farm from 7 gateway-fronted session hosts to 12 hardened hosts on a single broker, eliminating the RD Gateway and closing all inbound ports in favor of SonicWall ZTNA.
  • Provisioned the fleet with a for_each Terraform module and a reusable Packer golden image AMI, automating host rename and unattended domain join via EC2 user data and SSM Parameter Store.
  • Built Grafana observability — CPU, memory, EBS, network, and per-host session counts — to diagnose disconnects and host overload, later migrating collection to Grafana Alloy (OpenTelemetry).
  • Replaced legacy User Profile Disks with FSLogix, enforced CIS Benchmarks and AppLocker fleet-wide, and migrated 3 application servers with their MSSQL databases.
TerraformPackerAWS EC2SSM Parameter StoreWindows ServerRemote Desktop ServicesSonicWall ZTNAFSLogixGrafanaGrafana AlloyOpenTelemetryCIS BenchmarksAppLockerMSSQL

Ephemeral Disaster Recovery Environment for SOC 2 Tabletop Exercises

Client engagement at Direct IT — an on-demand, fully isolated disaster recovery environment provisioned and destroyed per exercise, so annual SOC 2 DR testing carries no standing cost.

Feb 2025 – Mar 2025
  • Built a Terraform project that stands up an isolated DR environment in a secondary AWS region, auto-resolving the latest EBS snapshot and registering AMIs so each run restores current production data.
  • Designed an air-gapped VPC — no default route, host-based routing, and a narrow allow-route for MFA agents — preventing restored apps from reaching live SaaS integrations.
  • Delivered through HCP Terraform VCS workflows, with GitHub Actions running fmt, validate, and plan on PRs and gating applies on merge, authenticating via IAM OIDC instead of static keys.
  • Enables repeatable annual SOC 2 DR tabletop exercises with video evidence, and full teardown to eliminate standing costs.
TerraformHCP TerraformAWS EC2EBS SnapshotsAMIVPCMulti-RegionIAM OIDCGitHub ActionsSOC 2
TransformMyNotes screenshot

TransformMyNotes

Mobile-first web app that digitizes handwritten study notes with image capture, AI transcription, a Notion-style block editor, and a full-text searchable notebook.

2026
  • Mobile-first web app that digitizes handwritten study notes — image capture, transcription via Amazon Bedrock (Claude vision), a Notion-style block editor, and a full-text searchable notebook.
  • Fully serverless AWS stack defined as code with SST v4 (deployed via Pulumi) — Next.js App Router, Lambda, S3, DynamoDB, Cognito authentication, CloudFront, and Resend.
  • Invite/approval-gated access with an admin panel, plus groups, shared notes, and a spaced-repetition review deck.
Next.jsTypeScriptSST v4PulumiAWS LambdaDynamoDBAWS S3CognitoCloudFrontAmazon BedrockResendGitHub Actions
Token Buzz screenshot

Token Buzz

Real-time crypto signal-intelligence platform that ingests social chatter across X, Farcaster, Telegram, and Reddit to surface trending tokens with watchlists, alerts, and LLM-summarized context.

2026
  • Real-time crypto signal-intelligence platform ingesting social chatter from X, Farcaster, Telegram, and Reddit, surfacing trending tokens with watchlists, alerts, and LLM-summarized context via Amazon Bedrock.
  • Full serverless AWS stack defined as code with SST v4 (deployed via Pulumi) — CloudFront, Lambda, DynamoDB, SQS, EventBridge, and IAM — fronted by Cloudflare DNS/WAF with Clerk authentication and Resend email.
  • DynamoDB single-table data model with purpose-built GSIs and typed key-builders; per-user third-party API keys encrypted at rest using AES/KMS envelope encryption.
  • AWS account hardened to the CIS Foundations Benchmark v6.0 via a dedicated Terraform project (CloudTrail, IAM Access Analyzer, default-SG lockdown, scheduled Prowler evidence scans); CI/CD ships through GitHub Actions using short-lived OIDC credentials with ephemeral per-PR preview environments.
Next.jsTypeScriptSST v4PulumiAWS LambdaDynamoDBSQSEventBridgeCloudFrontCloudflareClerkResendAmazon BedrockTerraformGitHub Actions
Dorval Construction screenshot

Dorval Construction

Marketing site for a custom home remodeling contractor — multi-page Next.js build with image gallery, services pages, and a serverless contact form deployed on AWS.

2026
  • Multi-page Next.js 15 site with image gallery and services pages for a home remodeling contractor.
  • Serverless contact form using API Gateway HTTP API, Lambda, and SES with full domain verification.
  • Static site hosted on a private S3 bucket behind CloudFront with Origin Access Control and HTTPS-only enforcement.
  • Deployed via GitLab CI/CD with DNS managed through Cloudflare.
Next.js 15TypeScriptTailwind CSSshadcn/uiAWS S3CloudFrontLambdaAPI GatewaySESCloudflare DNS
Saudade Café screenshot

Saudade Café

Bilingual (Portuguese/English) café site with Sanity headless CMS for menu management and a coworking booking subdomain with multi-step calendar and payment flow.

2026
  • Bilingual (Portuguese/English) Next.js site with Sanity headless CMS powering menu and content management.
  • Coworking booking subdomain with a multi-step calendar, time-slot selection, and payment flow.
  • Static export hosted on AWS S3 + CloudFront with DNS on Cloudflare.
Next.js 15TypeScriptTailwind CSSSanity CMSAWS S3CloudFrontLambdaAPI GatewayCloudflare DNS
This Website screenshot

This Website

A statically exported Next.js portfolio deployed on AWS with fully automated Terraform infrastructure, serverless contact form, and daily cost monitoring.

2026
  • Static site served from a private S3 bucket through CloudFront with Origin Access Control, TLS 1.2, and HTTPS-only enforcement.
  • Serverless contact form using API Gateway HTTP API, an ARM64 Lambda function, and SES with full DKIM and domain verification.
  • Automated daily cost digest via EventBridge-triggered Lambda querying Cost Explorer, plus AWS Budgets with threshold alerts.
  • Four reusable Terraform modules (static-site, contact-api, cost-monitor, cloudflare-dns) managing the entire stack.
  • Tag-driven GitLab CI/CD pipeline using OIDC federation to deploy, sync to S3, and invalidate the CloudFront cache.
Next.jsTypeScriptTailwind CSSMotionshadcn/uiTerraformAWS S3CloudFrontLambdaAPI GatewaySESCloudflare DNSGitLab CI/CD

FintechMetrix

Cost-optimized, scale-to-zero AWS platform that provisions services on demand to reduce idle spend while preserving production-grade reliability. Later rebuilt and relaunched as Token Buzz.

2026
  • Cost-optimized, scale-to-zero AWS platform deployed with Terraform — 5 ECS Fargate services behind ALB/CloudFront/Route 53 with Aurora PostgreSQL auto-scale-down policies.
  • Full GitLab CI/CD pipeline for multi-environment deployments, managing secrets via GitLab variables and AWS Parameter Store.
  • Dual-mode networking with NAT gateways (production HA) and NAT instances (low-cost dev), plus Grafana observability dashboards.
  • Full-stack build in Java Spring Boot, Next.js/TypeScript, and PostgreSQL; later rebuilt from the ground up and relaunched as Token Buzz (no longer live).
AWSTerraformECS FargateAurora PostgreSQLALBCloudFrontRoute 53GitLab CI/CDGrafanaNext.jsTypeScriptJava Spring Boot

Credentials

Certifications & Education

Validated cloud, security, and infrastructure capabilities with hands-on delivery across client environments.

HashiCorp Certified: Terraform Associate (004)
July 2026
AWS Certified Solutions Architect – Associate
March 2024
eLearnSecurity Junior Penetration Tester (eJPT)
July 2023
CompTIA A+
April 2021
Bunker Hill Community College

Associate in Science, Computer Science Transfer

May 2025

Contact

Let's build something together

Send me a message and I'll get back to you.