Available for consulting & remote roles

Kenneth Tafadzwa
Zendera

Solutions Architect&DevOps Engineer ·ISO 42001/27001/27701 Lead Auditor

Cloud architecture, security & AI governance — built, shipped, and certified

📍 Cape Town, South Africa 🕐 UTC+2 🌍 Remote · EMEA & US East

6+
Years experience
10
Certifications
2
AWS Organizations
12
Featured projects

Experience

Solutions Architect

Current · Remote

Cloud architecture and AI governance delivery across two AWS Organizations — multi-account landing zones with Control Tower and IAM Identity Center, production Terraform, security baselines, and ISO 27001 / 42001 control implementation. Led GCP → AWS workload migrations, RDS Blue/Green upgrades, IAM → Identity Center transitions, and S3 + CloudFront OAC cutovers.

AWS Automation Engineer

Previous

Built the cross-account automation that ran the platform — Bash and Python tooling for CloudWatch alarm management, cost and quota auditing, Security Hub remediation, and account provisioning. Self-healing deployments via SSM State Manager, with ASG-dimensioned alarms that survive instance replacement.

SOC Engineer — where it started

Foundations

Incident response end-to-end — triage, root cause, remediation, post-mortem, and the runbook that made the next one shorter. The operational discipline that still runs under everything I ship.

Projects

panafrican-payments

Case study · Fintech

Multi-provider payment orchestration API for African rails — M-Pesa, Flutterwave, Paystack, Stripe. Double-entry ledger, payment routing/split/payout engine, reconciliation, idempotency and rate-limiting middleware, webhook signature verification, and a published-style TypeScript SDK.

FastAPI PostgreSQL Redis TypeScript SDK pytest
Private build · architecture walk-through on request

aws-scanner

Case study · DevOps tooling

Multi-account AWS audit platform. Ten security, cost, and optimization scans executed through cross-account IAM role assumption — deployable via CloudFormation, orchestrated by an async FastAPI backend, surfaced in a React dashboard.

FastAPI boto3 React CloudFormation Docker
Private build · architecture walk-through on request

multichannel-ai-assistant

Case study · Serverless AI

Conversational AI across chat and voice channels — Python Lambda adapters, Amazon Connect with Nova Sonic, Bedrock inference, Comprehend language detection, DynamoDB session state. Fully Terraform-deployed and verified live in AWS.

Terraform Lambda Bedrock Amazon Connect DynamoDB
Private build · architecture walk-through on request

cross-account-aws-toolbox

Case study · AWS operations

Six years of multi-client AWS delivery distilled into 100+ production operational scripts — security baselines, Control Tower control governance, org-wide audits, CloudWatch alarm lifecycle, account migrations between Organizations, and recurring cost reporting. Every mutating script is dry-run-first; all fan out across accounts via STS assume-role with org auto-discovery and drift guards.

Bash AWS CLI STS assume-role Control Tower Security Hub CloudWatch
Private build · architecture walk-through on request

org-cost-reporting

Case study · FinOps

Monthly multi-account AWS cost reporting, run straight from the payer account — Cost Explorer queried directly with no role assumption into member accounts, Organizations auto-discovery, tag-based account inclusion, and six-month trend reporting. Built as a 750-line CLI tool with profile and instance-role run modes.

Bash AWS CLI Cost Explorer AWS Organizations
Private build · architecture walk-through on request

gitlab-502-postmortem

Case study · Incident response

Self-managed GitLab in Docker kept going down with 502s — a cron log-rotation race was SIGKILLing Postgres mid-checkpoint. Root-caused from container logs, then hardened: safe in-place log truncation, container stop-timeouts, rotation ordering, and a dry-run/apply tool with post-change validation.

GitLab Docker PostgreSQL Incident response
Private build · architecture walk-through on request

complyagent

Open source

EU AI Act audit-ready evidence collection for AI agent deployments. Cryptographically signed audit trails, real-time OPA policy evaluation, and PDF reports you can hand to a regulator. Python SDK + MCP integration.

FastAPI OPA · Rego Docker MCP Ed25519
View on GitHub →

terraform-aws-security-baseline

Terraform

Reusable module enabling Security Hub (CIS + FSBP), GuardDuty, Config with managed rules, multi-region CloudTrail with KMS, and IAM Access Analyzer — all in one apply.

Terraform Security Hub ISO 27001
View on GitHub →

terraform-aws-bedrock-governance

Terraform · AI

Private, VPC-endpointed Amazon Bedrock with Guardrails, Knowledge Base, and CloudWatch monitoring. Every resource annotated to the ISO 42001 control it satisfies.

Terraform Bedrock ISO 42001
View on GitHub →

aws-cwagent-deployer

Bash · SSM

Self-healing CloudWatch Agent deployment via SSM State Manager. ASG-dimensioned alarms that survive instance replacement — fixes the two most common ways this is done wrong in production.

Bash SSM CloudWatch
View on GitHub →

aws-cost-auditor

Bash · FinOps

Read-only cross-account cost reporting using Cost Explorer. Month-over-month variance flagging, top-N services per account, EC2 rightsizing summary. CloudShell-native, no profile required.

Bash AWS CLI FinOps
View on GitHub →

ai-governance-toolkit

Governance

Practitioner templates for EU AI Act risk classification, ISO 42001 clause-by-clause audit, NIST AI RMF implementation, incident response playbook, and vendor assessment questionnaire.

EU AI Act ISO 42001 NIST AI RMF
View on GitHub →

What I do

🏢

AWS multi-account architecture

Landing zones, Control Tower, IAM Identity Center, and Security Hub across multiple AWS Organizations. Multi-region, multi-client infrastructure designed for MSP scale.

📦

Infrastructure as Code

Production Terraform — modular, remote-state backed, CI/CD deployed with TFSec, Checkov, and manual approval gates. Idempotent and audit-compliant. CloudFormation where it fits.

🔁

CI/CD & GitOps

GitLab CI and GitHub Actions pipelines with OIDC federation — no long-lived keys. Policy-as-code gates, manual approvals, and deployments you can replay.

⚙️

Platform & backend engineering

Python (FastAPI) and TypeScript/Node services on PostgreSQL, MongoDB, and Redis — ledgers, payment orchestration, reconciliation, idempotency. The systems in the case studies above.

🔐

Cloud security

GuardDuty, Config, Security Hub, KMS, WAF — implemented as code and monitored continuously. ISO 27001 controls mapped to AWS services, not to spreadsheets.

🛡️

AI & data governance

EU AI Act risk classification, NIST AI RMF implementation, ISO 42001/27701 AIMS design and audit. Governance as engineering — policy-as-code and signed audit trails.

🚀

Migrations & incident response

GCP → AWS, RDS Blue/Green upgrades, IAM → Identity Center, S3 + CloudFront OAC cutovers. Incidents end-to-end: triage, root cause, post-mortem, runbook.

Certifications

Tech stack

Cloud
AWS Control Tower IAM Identity Center ECS · EKS RDS Lambda CloudFront Bedrock Azure
IaC & CI/CD
Terraform CloudFormation GitLab CI GitHub Actions TFSec Checkov
Platforms & languages
Python TypeScript FastAPI Node.js PostgreSQL MongoDB Redis React
Security
Security Hub GuardDuty Config IAM KMS WAF CloudTrail
Observability
CloudWatch CWAgent Prometheus Grafana Kibana
Governance
EU AI Act NIST AI RMF ISO 42001 ISO 27001 ISO 27701 CIS Benchmarks

Let's work together

Open to consulting engagements — EU AI Act readiness, fractional CISO, cloud security architecture — and remote solutions-architecture / DevOps roles. Remote across EMEA & US East.