AWS DevOps consultant who builds it — and makes it audit-ready.
Freelance AWS DevOps, Terraform and Kubernetes engineering with security baked into the pipeline. 16+ years shipping production infrastructure for fintech, SaaS and healthcare — CISA & AWS Solutions Architect Professional. Remote across the US, Australia and UAE.
Book a free 30-min callEmail meWhat I ship
Terraform & IaC
- Modular Terraform — networking, compute, data, security, observability
- Remote state, environment promotion, peer-reviewed plans
- OPA/Conftest blocking public S3, open SGs, unencrypted RDS at plan time
Kubernetes / EKS
- Private-subnet EKS, IRSA, VPC endpoints, no long-lived keys
- Helm, autoscaling (HPA / Cluster Autoscaler), distroless images
- ArgoCD GitOps — drift detection & reconciliation every 3 minutes
CI/CD pipelines
- GitHub Actions, GitLab CI, Jenkins, AWS CodePipeline
- Security gates: SAST, Trivy image scan, OPA policy-as-code
- Blue/green & canary on ECS/EKS, automated rollback on 5xx
Migration, cost & Linux
- Colo→AWS and lift-and-shift migrations (150+ servers, <4h downtime)
- Cost optimization / FinOps — right-sizing, Savings Plans, NAT teardown
- Linux server administration, hardening (CIS), 24/7 managed AWS retainers
Why hire me over a generic DevOps freelancer
Most cloud engineers can't pass an audit; most auditors can't write Terraform. I hold CISA + AWS Solutions Architect Professional — a rare pairing that means your pipeline is fast and your infrastructure is compliant by construction. IAM maps to ISO 27001 Annex A, CloudTrail satisfies SOC 2 CC7, KMS traces from key policy to encrypted volume in three clicks. You ship faster because security is in the pipeline, not bolted on after.
Proof, not promises
AI lending platform — private-subnet EKS
Private-subnet-only EKS with VPC endpoints, multi-account AWS Org, SLO-driven SRE. Zero SOC 2 findings, −30% MTTR, −$1.8k/mo NAT cost.
Fintech migration — colo to AWS Sydney
Segmented CDE, KMS key rotation, DMS migration for NZ banking clients. 150+ servers, <4h downtime, zero PCI findings.
DevSecOps practice — 6 AWS accounts
Standardized Terraform modules + AWS Config dashboards across a 12-engineer team. 4 audits passed, −75% vulns to prod, −15% cloud cost.
Java on EKS — GitOps pipeline
CodePipeline → ECR → EKS on every commit, rotating DB secrets, ALB+WAF edge. Push-to-deploy, automated secret rotation.
How we'd work together
Project
Greenfield AWS — multi-AZ VPC, EKS, Terraform, CI/CD. All reviewable, all auditable.
Retainer
Ongoing DevOps with embedded security gates, GitOps reconciliation, on-call support.
Fixed-fee audit
I find what an assessor will find — first — and hand you a prioritized remediation roadmap.
Guides and comparisons
Deciding on your container platform? Read my hands-on comparison of Amazon EKS vs ECS. Choosing IaC tooling? See Terraform vs CloudFormation and Argo CD vs Flux for GitOps.
FAQ
What does an AWS DevOps consultant do?
Designs and automates AWS with Terraform, builds and hardens EKS and CI/CD pipelines, migrates workloads, optimizes cost, and administers Linux — with security controls in the pipeline so the result is production- and audit-ready.
Do you work with US, Australia and UAE clients?
Yes — remote-first across US, Australia, UAE, UK and EU time zones.
Project, retainer, or one-off?
All three — greenfield builds, ongoing retainers, or fixed-fee audits of an existing environment.
What makes you different?
CISA + AWS Solutions Architect Professional — infrastructure built to pass PCI DSS, SOC 2, ISO 27001 and HIPAA from day one.
Let's ship your AWS platform.
Free 30-minute discovery call — infrastructure, pipelines or an audit on the calendar.
Book a callSee the Terraform + EKS + CI/CD build →