Experience
Seven years building both the products and the cloud-native platforms that run them. Tap a company to see its projects.
Armor Defense Inc. (acquired Quantum Security)→
Senior Software Developer / Platform Engineer
The sole platform engineer for a ~60-engineer security organization, behind Nexus, a Frost & Sullivan Top-20 Global MDR platform (2025). I architect and operate the multi-tenant Amazon EKS platform the entire product suite ships on: 300–400 nodes, 250+ microservices, 3,000+ peak RPS, and 1–3+ TB/day of SIEM ingest.
Earning the platform: from Sentinel to threat intelligence
- Spent my first months on Azure Sentinel writing KQL analytic rules to learn the business, then built Terraform modules for the entire Sentinel stack (Log Analytics workspaces, connectors, analytic rules, playbooks, workbooks, watchlists, parsers), deployed into customer environments and shipped via Atlantis.
- Delivered production-grade OpenCTI on AWS (OpenSearch, ElastiCache, Okta SSO, connectors) after a prior team had failed to self-host it on EC2, feeding threat intelligence back into Sentinel. Later migrated it ECS→EKS, saving $130,200/year, and it has run since 2022 with zero infrastructure incidents.
Building Nexus
- Wrote the first Nexus microservices: mdr-customer, and mdr-reports (which fills a PPT template with customer metrics and renders a PDF on a schedule), then billing, incident-automation, xdr-kyc, mdr-authorizer (a lightweight adapter to Armor's IMC auth framework), and the defender / ti / jsm middleware, originally all on ECS.
- For IHiS / Synapxe (Singapore's national health-IT and a critical account), whose framework emitted ~200k events/sec, I built a Logstash pipeline ingesting from their S3 into Azure Sentinel at ~100k events/sec, solving a throughput and monitoring problem that earned personal congratulations from Armor's CEO.
The platform, and the direction I set
- At ~75 microservices I drafted the leadership proposal to move from ECS to Kubernetes, won approval, and owned the migration, setting the org-wide technical direction on five pillars: security-by-default, cost-awareness, observability, GitOps, and self-healing. That platform now runs 250+ services across 300–400 nodes.
- Built the internal developer platform (Crossplane compositions) that abstracts Kubernetes for ~60 engineers, and the multi-model LLM inference platform spanning AWS Inferentia2, Trainium2, and NVIDIA L40S. (Both written up in Projects.)
- Shipped 43 applications across Nexus, AI for dashboards, AI for Adversarial Emulation, and AI for GRC, and handed ~70% of SRE toil to an AI operator (HolmesGPT). Won 1st prize (year one) and 2nd prize (year two) at Innovation Week.
Ollion (previously CloudCover)→
Software Engineer / DevSecOps (SRE)
Built the secure, production-ready cloud foundations behind LetsBloom, a compliant landing-zone platform for Standard Chartered Ventures, since productized by Standard Chartered. I was the sole multi-cloud and Kubernetes expert on the engagement and one of three application developers.
Compliant-by-default landing zones
- Built 18 secure, compliant landing zones as reusable blueprints (entirely infrastructure-as-code), advocating shift-left security from the design stage.
- Kept customer-modified blueprints continuously compliant to the bank's posture with Cloud Custodian (c7n) enforcing 100+ AWS policies, alongside AWS WAF and Shield, and a Rego policy-as-code validator that gated Terraform changes before they merged.
- Set the security-pipeline standard: TfSec + Checkov on IaC, SAST/DAST, Trivy + Anchore for containers, OPA Gatekeeper admission control, and Falco runtime.
Migration and application engineering
- Led the AWS→Azure re-platform, including an ECS→AKS migration (100+ nodes, HashiCorp Consul mesh, Calico, Vault) with zero downtime, and established the Kubernetes culture and standards the team carried forward.
- Stood up the DevSecOps practice that onboarded three customers in four months.
- Wrote ~40% of LetsBloom's Go microservices, including a Casbin-based AuthN/AuthZ framework, a Celery distributed DAG task worker, and Secure Notes (a UI over Vault and its secret engines).
- Promoted twice in under two years.