ABOUT EXPERIENCE SKILLS PROJECTS CREDENTIALS CONTACT
Cloud Security Engineer • SRE • Infrastructure Automation

Designing and Defending Secure Cloud Architectures.

Hands-on ownership of production AWS infrastructure, cloud security architecture, IAM governance, Kubernetes workloads, CI/CD security, and SRE-grade observability for high-reliability, HIPAA-regulated platforms.

Kosha Gohil
Kosha Gohil working
Background & Focus

Professional Summary

Cloud Security Engineer with hands-on ownership of production AWS infrastructure, cloud security architecture, IAM governance, infrastructure-as-code, Kubernetes workloads, CI/CD security, and observability for a HIPAA-regulated healthcare platform.

Designs and implements least-privilege IAM/RBAC controls, Terraform-based security automation, secure deployment architectures, and production monitoring across cloud, application, and data layers.

Experienced in site reliability engineering (SRE) for the production environment, including SLO/SLI definition, capacity planning, configuration-drift remediation, incident management with blameless postmortems, and reliability engineering for scalable, fault-tolerant systems. Proficient in Python and shell scripting, with growing hands-on development in Go for reliability automation and AI tools that accelerate detection and triage.

0 Downtime
Production eRx Migrations
-40% Drift
Terraform Modularization
< 2s MTTR
Automated Rollback Engine
Track Record

Work Experience

Demonstrated impact across production AWS infrastructure, SRE, and DevSecOps.

Cloud Security Engineer

Jan 2025 – Present
Woodhull Rx Center • HIPAA-Regulated Production Environment (New York)
  • Site Reliability Ownership: Owned site reliability engineering for a HIPAA-regulated pharmacy production environment on AWS, aligning feature velocity with reliability via defined SLIs/SLOs and error-budget driven priorities.
  • Zero-Downtime Migration: Architected and executed a zero-downtime migration of a HIPAA-regulated pharmacy platform to AWS, deploying parallel production infrastructure and performing a blue-green cutover through Route 53 while supporting 400 to 500 daily eRx transactions.
  • Terraform Standardization: Established Terraform-driven infrastructure standardization across dev, stage, and production, enforcing environment parity and eliminating configuration inconsistencies that previously created recurring compliance exposure.
  • Fault-Tolerant High Availability: Designed highly available, scalable, fault-tolerant systems for the eRx platform using multi-AZ RDS, automated failover, and recovery runbooks, improving resilience during infrastructure events.
  • Database Security Hardening: Hardened production database security and availability through encrypted RDS replication, automated failover, IAM database authentication, and short-lived IAM-issued database credentials, eliminating reliance on static database passwords.
  • Kubernetes Latency Optimization: Diagnosed recurring Kubernetes and container crash loops by debugging resource-limit and request configuration, then rearchitected the eRx processing pipeline for parallel execution, reducing application latency by approximately 35% while preserving data-integrity controls.
  • Configuration Drift Remediation: Refactored monolithic Terraform infrastructure into peer-reviewed, least-privilege modules covering networking, compute, IAM, and security groups, reducing configuration drift by approximately 40% and addressing recurring audit findings caused by manual infrastructure changes.
  • SRE Observability Stack: Built and operated an SRE-grade observability stack (Prometheus, Grafana, Loki, Mimir, CloudWatch) with actionable alerts and service dashboards, reducing incident frequency by approximately 30% and MTTR by approximately 40%.
  • Incident Management: Drove incident management and a blameless postmortems culture, owning on-call response, root-cause analysis across cloud, application, and data layers, and tracking corrective actions to closure while maintaining SLA-level reliability.
  • Safe Delivery Procedures: Partnered with application engineers on release procedures and safer rollouts (canary and blue-green patterns), improving change safety while meeting uptime requirements in a regulated environment.

Associate Cybersecurity & QA

Oct 2024 – Jul 2025
Filmy AI • Remote
  • Reliability CI/CD Guardrails: Built reliability-focused CI/CD guardrails, adding rigorous testing and release procedures (staged rollouts, automated health checks, and rollback) to keep high-change services stable.
  • Shift-Left Security Controls: Integrated shift-left security controls directly into CI/CD workflows, enforcing automated vulnerability scanning and API security validation as build gates covering OAuth 2.0/OIDC, SAML-based authentication and authorization, input validation, and encryption controls.
  • Serverless Malware Pipeline: Architected a serverless malware detection and quarantine pipeline using GCP Cloud Run and ClamAV, automatically scanning uploaded media and preventing malicious files from reaching production storage.
  • Distributed Systems Troubleshooting: Performed distributed systems troubleshooting across event-driven services (webhooks, queues, and storage), isolating failure modes such as retries, duplication, and backpressure, and implementing mitigations to reduce incident recurrence.
  • Rapid Incident Response: Led technical incident response for a data-exfiltration event caused by a misconfigured third-party webhook, performing exposure analysis, containment, remediation, and secure-data-handling restoration within 24 hours.
  • SDLC Assurance: Strengthened application security assurance by integrating authentication, authorization, vulnerability detection, and security validation into the software delivery lifecycle, reducing the reliance on post-deployment security discovery.

Cyber Security Intern

Mar 2024 – May 2024
Bunchful Enterprise • New York
  • Operational Readiness & Baselines: Supported production support readiness by building an asset inventory, documenting operational baselines, and validating endpoint compliance against defined security controls.
  • NIST Governance Framework: Established the organization’s initial security governance foundation, authoring security policies and baseline standards aligned with the NIST Cybersecurity Framework.
  • Control Gap Remediation: Implemented asset inventory and endpoint compliance validation against defined security baselines, identifying configuration and control gaps for remediation.
  • Threat Research & Risk Register: Supported vulnerability assessment, threat research, and risk-register development, translating technical findings into actionable security and governance requirements.
  • Systems Diagnostics: Strengthened fundamentals in UNIX and networking (processes, system logging, TCP/IP basics) to better support incident triage and root-cause analysis in production systems.
Competencies

Technical Skills Matrix

Comprehensive skill inventory aligned with modern cloud security and reliability engineering standards.

Cloud Security & Identity

AWS IAM Least-Privilege Access RBAC Access Governance SAML OAuth 2.0 OpenID Connect AuthN & AuthZ IAM Database Auth CloudTrail Security Controls

Infrastructure as Code

Terraform Terraform Modules State Management CloudFormation Infra Standardization Configuration Drift Detection Automated Remediation

DevSecOps & CI/CD

GitHub Actions Jenkins GitLab CI CI/CD Security Gates Vulnerability Scanning API Security Testing Automated Rollbacks Deployment Controls Security-as-Code

Containers & Platforms

Docker Kubernetes Amazon EKS Kubernetes RBAC Network Policies Helm Container Security Resource Limits Workload Isolation

Observability & Reliability

Prometheus Grafana Loki Mimir ELK Stack CloudWatch SLOs / SLIs Error Budgets On-Call Response Blameless Postmortems MTTD / MTTR

Security, Code & Compliance

HIPAA-Aligned Infra NIST CSF Audit Readiness Python (Boto3) Go Bash / Shell PostgreSQL MySQL REST APIs Security Automation
Featured Implementations

Featured Projects

Production-grade cloud security platforms and automation suites.

AWS IAM • Security Governance

Automated IAM Governance & Configuration Drift Detection Engine

  • Engineered an automated IAM governance platform that evaluates AWS IAM policies and access configurations against least-privilege baselines to identify excessive permissions and configuration drift.
  • Implemented continuous access-governance validation, CloudTrail-based monitoring, real-time SNS alerting, and audit-ready reporting, replacing manual IAM reviews with automated security controls.
  • Added a lightweight anomaly-scoring workflow to prioritize risky access changes, an AI tools-style triage layer that reduced alert noise and sped up investigation queues.
Terraform • Python • Boto3 • AWS SNS View Source
DevSecOps • Automated Rollback

Secure CI/CD & Infrastructure Automation Pipeline

  • Engineered a security-focused CI/CD pipeline integrating source validation, Terraform plan/apply workflows, approval gates, container deployments, and automated rollback controls.
  • Embedded infrastructure and deployment validation into the software delivery lifecycle, preventing misconfigurations from progressing through deployment workflows.
  • Built canary health probes auditing `/healthz` and response latency SLAs, triggering self-healing rollbacks in < 2.0s with automated post-mortem incident generation.
GitHub Actions • Terraform • ECS Fargate • Docker View Source
Serverless • Threat Detection

Serverless Malware Detection & File Quarantine Pipeline

  • Designed an event-driven malware detection and quarantine architecture using AWS Lambda and ClamAV to automatically scan uploaded media before allowing clean content to reach S3.
  • Implemented automated quarantine and SNS-based security alerting to isolate malicious uploads and reduce the attack surface associated with user-generated content.
  • Integrated DynamoDB tracking for immutable audit logging and incident analysis.
AWS Lambda • ClamAV • S3 • DynamoDB • SNS View Source
Cloud-Native • HealthTech

SAMYA — Cloud-Native Health Management Platform

  • Architecting a cloud-native health management platform that brings medication tracking, wellness, health readings, prescriptions, reports, nutrition, hydration, exercise, women's health, and health records into a unified platform.
  • Engineering secure REST APIs and role-based access controls (RBAC) with encryption and audit logging to protect sensitive health information and maintain traceability across user workflows.
  • Developing an AI-powered wellness experience designed to help users understand health patterns, build healthier habits, and receive personalized lifestyle guidance from their health data.
  • Containerizing the application with Docker and designing the platform around security, privacy, and healthcare data-protection requirements aligned with HIPAA and DPDP principles.
Docker • HIPAA Compliance • RBAC • REST APIs
Academic Foundation

Education

Sep 2022 – May 2024

Pace University

Master's, Computer Science

New York, USA GPA: 3.91 / 4.0
Aug 2018 – Jul 2021

Savitribai Phule Pune University

Bachelor's, Computer Engineering

Pune, India GPA: 3.2 / 4.0
Industry Credentials

Certifications & Achievements

HashiCorp Certified: Terraform Associate (004)

HashiCorp • Jun 2026

Verified Active

AWS Certified Solutions Architect – Associate

Amazon Web Services • Aug 2025

CompTIA Security+ ce

CompTIA • Jun 2025

AWS Certified Cloud Practitioner

Amazon Web Services • Jul 2024

Get in Touch

Let's Connect

I am currently open to exciting opportunities in Cloud Security, Site Reliability Engineering (SRE), and DevSecOps. Feel free to reach out directly or send a message below.