Solutions Architect&DevOps Engineer ·ISO 42001/27001/27701 Lead Auditor
Cloud architecture, security & AI governance — built, shipped, and certified
Cloud architecture and AI governance delivery across two AWS Organizations — multi-account landing zones with Control Tower and IAM Identity Center, production Terraform, security baselines, and ISO 27001 / 42001 control implementation. Led GCP → AWS workload migrations, RDS Blue/Green upgrades, IAM → Identity Center transitions, and S3 + CloudFront OAC cutovers.
Built the cross-account automation that ran the platform — Bash and Python tooling for CloudWatch alarm management, cost and quota auditing, Security Hub remediation, and account provisioning. Self-healing deployments via SSM State Manager, with ASG-dimensioned alarms that survive instance replacement.
Incident response end-to-end — triage, root cause, remediation, post-mortem, and the runbook that made the next one shorter. The operational discipline that still runs under everything I ship.
Multi-provider payment orchestration API for African rails — M-Pesa, Flutterwave, Paystack, Stripe. Double-entry ledger, payment routing/split/payout engine, reconciliation, idempotency and rate-limiting middleware, webhook signature verification, and a published-style TypeScript SDK.
Private build · architecture walk-through on requestMulti-account AWS audit platform. Ten security, cost, and optimization scans executed through cross-account IAM role assumption — deployable via CloudFormation, orchestrated by an async FastAPI backend, surfaced in a React dashboard.
Private build · architecture walk-through on requestConversational AI across chat and voice channels — Python Lambda adapters, Amazon Connect with Nova Sonic, Bedrock inference, Comprehend language detection, DynamoDB session state. Fully Terraform-deployed and verified live in AWS.
Private build · architecture walk-through on requestSix years of multi-client AWS delivery distilled into 100+ production operational scripts — security baselines, Control Tower control governance, org-wide audits, CloudWatch alarm lifecycle, account migrations between Organizations, and recurring cost reporting. Every mutating script is dry-run-first; all fan out across accounts via STS assume-role with org auto-discovery and drift guards.
Private build · architecture walk-through on requestMonthly multi-account AWS cost reporting, run straight from the payer account — Cost Explorer queried directly with no role assumption into member accounts, Organizations auto-discovery, tag-based account inclusion, and six-month trend reporting. Built as a 750-line CLI tool with profile and instance-role run modes.
Private build · architecture walk-through on requestSelf-managed GitLab in Docker kept going down with 502s — a cron log-rotation race was SIGKILLing Postgres mid-checkpoint. Root-caused from container logs, then hardened: safe in-place log truncation, container stop-timeouts, rotation ordering, and a dry-run/apply tool with post-change validation.
Private build · architecture walk-through on requestEU AI Act audit-ready evidence collection for AI agent deployments. Cryptographically signed audit trails, real-time OPA policy evaluation, and PDF reports you can hand to a regulator. Python SDK + MCP integration.
View on GitHub →Reusable module enabling Security Hub (CIS + FSBP), GuardDuty, Config with managed rules, multi-region CloudTrail with KMS, and IAM Access Analyzer — all in one apply.
View on GitHub →Private, VPC-endpointed Amazon Bedrock with Guardrails, Knowledge Base, and CloudWatch monitoring. Every resource annotated to the ISO 42001 control it satisfies.
View on GitHub →Self-healing CloudWatch Agent deployment via SSM State Manager. ASG-dimensioned alarms that survive instance replacement — fixes the two most common ways this is done wrong in production.
View on GitHub →Read-only cross-account cost reporting using Cost Explorer. Month-over-month variance flagging, top-N services per account, EC2 rightsizing summary. CloudShell-native, no profile required.
View on GitHub →Practitioner templates for EU AI Act risk classification, ISO 42001 clause-by-clause audit, NIST AI RMF implementation, incident response playbook, and vendor assessment questionnaire.
View on GitHub →Landing zones, Control Tower, IAM Identity Center, and Security Hub across multiple AWS Organizations. Multi-region, multi-client infrastructure designed for MSP scale.
Production Terraform — modular, remote-state backed, CI/CD deployed with TFSec, Checkov, and manual approval gates. Idempotent and audit-compliant. CloudFormation where it fits.
GitLab CI and GitHub Actions pipelines with OIDC federation — no long-lived keys. Policy-as-code gates, manual approvals, and deployments you can replay.
Python (FastAPI) and TypeScript/Node services on PostgreSQL, MongoDB, and Redis — ledgers, payment orchestration, reconciliation, idempotency. The systems in the case studies above.
GuardDuty, Config, Security Hub, KMS, WAF — implemented as code and monitored continuously. ISO 27001 controls mapped to AWS services, not to spreadsheets.
EU AI Act risk classification, NIST AI RMF implementation, ISO 42001/27701 AIMS design and audit. Governance as engineering — policy-as-code and signed audit trails.
GCP → AWS, RDS Blue/Green upgrades, IAM → Identity Center, S3 + CloudFront OAC cutovers. Incidents end-to-end: triage, root cause, post-mortem, runbook.
Open to consulting engagements — EU AI Act readiness, fractional CISO, cloud security architecture — and remote solutions-architecture / DevOps roles. Remote across EMEA & US East.