AWS DevOps · Terraform · EKS · CI/CD

AWS DevOps consultant who builds it — and makes it audit-ready.

Freelance AWS DevOps, Terraform and Kubernetes engineering with security baked into the pipeline. 16+ years shipping production infrastructure for fintech, SaaS and healthcare — CISA & AWS Solutions Architect Professional. Remote across the US, Australia and UAE.

Book a free 30-min callEmail me

What I ship

Terraform & IaC

  • Modular Terraform — networking, compute, data, security, observability
  • Remote state, environment promotion, peer-reviewed plans
  • OPA/Conftest blocking public S3, open SGs, unencrypted RDS at plan time

Kubernetes / EKS

  • Private-subnet EKS, IRSA, VPC endpoints, no long-lived keys
  • Helm, autoscaling (HPA / Cluster Autoscaler), distroless images
  • ArgoCD GitOps — drift detection & reconciliation every 3 minutes

CI/CD pipelines

  • GitHub Actions, GitLab CI, Jenkins, AWS CodePipeline
  • Security gates: SAST, Trivy image scan, OPA policy-as-code
  • Blue/green & canary on ECS/EKS, automated rollback on 5xx

Migration, cost & Linux

  • Colo→AWS and lift-and-shift migrations (150+ servers, <4h downtime)
  • Cost optimization / FinOps — right-sizing, Savings Plans, NAT teardown
  • Linux server administration, hardening (CIS), 24/7 managed AWS retainers

Why hire me over a generic DevOps freelancer

Most cloud engineers can't pass an audit; most auditors can't write Terraform. I hold CISA + AWS Solutions Architect Professional — a rare pairing that means your pipeline is fast and your infrastructure is compliant by construction. IAM maps to ISO 27001 Annex A, CloudTrail satisfies SOC 2 CC7, KMS traces from key policy to encrypted volume in three clicks. You ship faster because security is in the pipeline, not bolted on after.

16+years in production AWS
200+projects delivered
100%Upwork job success (Top Rated Plus)

Proof, not promises

AI lending platform — private-subnet EKS

Private-subnet-only EKS with VPC endpoints, multi-account AWS Org, SLO-driven SRE. Zero SOC 2 findings, −30% MTTR, −$1.8k/mo NAT cost.

Fintech migration — colo to AWS Sydney

Segmented CDE, KMS key rotation, DMS migration for NZ banking clients. 150+ servers, <4h downtime, zero PCI findings.

DevSecOps practice — 6 AWS accounts

Standardized Terraform modules + AWS Config dashboards across a 12-engineer team. 4 audits passed, −75% vulns to prod, −15% cloud cost.

Java on EKS — GitOps pipeline

CodePipeline → ECR → EKS on every commit, rotating DB secrets, ALB+WAF edge. Push-to-deploy, automated secret rotation.

How we'd work together

Project

Greenfield AWS — multi-AZ VPC, EKS, Terraform, CI/CD. All reviewable, all auditable.

Retainer

Ongoing DevOps with embedded security gates, GitOps reconciliation, on-call support.

Fixed-fee audit

I find what an assessor will find — first — and hand you a prioritized remediation roadmap.

AWSTerraformEKSKubernetesDockerGitHub ActionsGitLab CIJenkinsArgoCDHelmTrivyOPA/ConftestPrometheusGrafanaDatadogPython/Boto3Linux

Guides and comparisons

Deciding on your container platform? Read my hands-on comparison of Amazon EKS vs ECS. Choosing IaC tooling? See Terraform vs CloudFormation and Argo CD vs Flux for GitOps.

FAQ

What does an AWS DevOps consultant do?

Designs and automates AWS with Terraform, builds and hardens EKS and CI/CD pipelines, migrates workloads, optimizes cost, and administers Linux — with security controls in the pipeline so the result is production- and audit-ready.

Do you work with US, Australia and UAE clients?

Yes — remote-first across US, Australia, UAE, UK and EU time zones.

Project, retainer, or one-off?

All three — greenfield builds, ongoing retainers, or fixed-fee audits of an existing environment.

What makes you different?

CISA + AWS Solutions Architect Professional — infrastructure built to pass PCI DSS, SOC 2, ISO 27001 and HIPAA from day one.

Let's ship your AWS platform.

Free 30-minute discovery call — infrastructure, pipelines or an audit on the calendar.

Book a callSee the Terraform + EKS + CI/CD build →