AWS DevOps consultant who builds it — and makes it audit-ready.
Freelance AWS DevOps, Terraform and Kubernetes engineering with security baked into the pipeline. 16+ years shipping production infrastructure for fintech, SaaS and healthcare — CISA & AWS Solutions Architect Professional. Remote across the US, Australia and UAE.
Book a free 30-min callEmail meWhat I ship
Terraform & IaC
- Modular Terraform — networking, compute, data, security, observability
- Remote state, environment promotion, peer-reviewed plans
- OPA/Conftest blocking public S3, open SGs, unencrypted RDS at plan time
Kubernetes / EKS
- Private-subnet EKS, IRSA, VPC endpoints, no long-lived keys
- Helm, autoscaling (HPA / Cluster Autoscaler), distroless images
- ArgoCD GitOps — drift detection & reconciliation every 3 minutes
CI/CD pipelines
- GitHub Actions, GitLab CI, Jenkins, AWS CodePipeline
- Security gates: SAST, Trivy image scan, OPA policy-as-code
- Blue/green & canary on ECS/EKS, automated rollback on 5xx
Migration, cost & Linux
- Colo→AWS and lift-and-shift migrations (150+ servers, <4h downtime)
- Cost optimization / FinOps — right-sizing, Savings Plans, NAT teardown
- Linux server administration, hardening (CIS), 24/7 managed AWS retainers
Why hire me over a generic DevOps freelancer
Most cloud engineers can't pass an audit; most auditors can't write Terraform. I hold CISA + AWS Solutions Architect Professional — a rare pairing that means your pipeline is fast and your infrastructure is compliant by construction. IAM maps to ISO 27001 Annex A, CloudTrail satisfies SOC 2 CC7, KMS traces from key policy to encrypted volume in three clicks. You ship faster because security is in the pipeline, not bolted on after.
Proof, not promises
AI lending platform — private-subnet EKS
Private-subnet-only EKS with VPC endpoints, multi-account AWS Org, SLO-driven SRE. Zero SOC 2 findings, −30% MTTR, −$1.8k/mo NAT cost.
Fintech migration — colo to AWS Sydney
Segmented CDE, KMS key rotation, DMS migration for NZ banking clients. 150+ servers, <4h downtime, zero PCI findings.
DevSecOps practice — 6 AWS accounts
Standardized Terraform modules + AWS Config dashboards across a 12-engineer team. 4 audits passed, −75% vulns to prod, −15% cloud cost.
Java on EKS — GitOps pipeline
CodePipeline → ECR → EKS on every commit, rotating DB secrets, ALB+WAF edge. Push-to-deploy, automated secret rotation.
How we'd work together
Project
Greenfield AWS — multi-AZ VPC, EKS, Terraform, CI/CD. All reviewable, all auditable.
Retainer
Ongoing DevOps with embedded security gates, GitOps reconciliation, on-call support.
Fixed-fee audit
I find what an assessor will find — first — and hand you a prioritized remediation roadmap.
FAQ
What does an AWS DevOps consultant do?
Designs and automates AWS with Terraform, builds and hardens EKS and CI/CD pipelines, migrates workloads, optimizes cost, and administers Linux — with security controls in the pipeline so the result is production- and audit-ready.
Do you work with US, Australia and UAE clients?
Yes — remote-first across US, Australia, UAE, UK and EU time zones.
Project, retainer, or one-off?
All three — greenfield builds, ongoing retainers, or fixed-fee audits of an existing environment.
What makes you different?
CISA + AWS Solutions Architect Professional — infrastructure built to pass PCI DSS, SOC 2, ISO 27001 and HIPAA from day one.
Let's ship your AWS platform.
Free 30-minute discovery call — infrastructure, pipelines or an audit on the calendar.
Book a callSee the Terraform + EKS + CI/CD build →