Designing and Defending Secure Cloud Architectures.
Hands-on ownership of production AWS infrastructure, cloud security architecture, IAM governance, Kubernetes workloads, CI/CD security, and SRE-grade observability for high-reliability, HIPAA-regulated platforms.
Professional Summary
Cloud Security Engineer with hands-on ownership of production AWS infrastructure, cloud security architecture, IAM governance, infrastructure-as-code, Kubernetes workloads, CI/CD security, and observability for a HIPAA-regulated healthcare platform.
Designs and implements least-privilege IAM/RBAC controls, Terraform-based security automation, secure deployment architectures, and production monitoring across cloud, application, and data layers.
Experienced in site reliability engineering (SRE) for the production environment, including SLO/SLI definition, capacity planning, configuration-drift remediation, incident management with blameless postmortems, and reliability engineering for scalable, fault-tolerant systems. Proficient in Python and shell scripting, with growing hands-on development in Go for reliability automation and AI tools that accelerate detection and triage.
Work Experience
Demonstrated impact across production AWS infrastructure, SRE, and DevSecOps.
Cloud Security Engineer
Jan 2025 – Present- Site Reliability Ownership: Owned site reliability engineering for a HIPAA-regulated pharmacy production environment on AWS, aligning feature velocity with reliability via defined SLIs/SLOs and error-budget driven priorities.
- Zero-Downtime Migration: Architected and executed a zero-downtime migration of a HIPAA-regulated pharmacy platform to AWS, deploying parallel production infrastructure and performing a blue-green cutover through Route 53 while supporting 400 to 500 daily eRx transactions.
- Terraform Standardization: Established Terraform-driven infrastructure standardization across dev, stage, and production, enforcing environment parity and eliminating configuration inconsistencies that previously created recurring compliance exposure.
- Fault-Tolerant High Availability: Designed highly available, scalable, fault-tolerant systems for the eRx platform using multi-AZ RDS, automated failover, and recovery runbooks, improving resilience during infrastructure events.
- Database Security Hardening: Hardened production database security and availability through encrypted RDS replication, automated failover, IAM database authentication, and short-lived IAM-issued database credentials, eliminating reliance on static database passwords.
- Kubernetes Latency Optimization: Diagnosed recurring Kubernetes and container crash loops by debugging resource-limit and request configuration, then rearchitected the eRx processing pipeline for parallel execution, reducing application latency by approximately 35% while preserving data-integrity controls.
- Configuration Drift Remediation: Refactored monolithic Terraform infrastructure into peer-reviewed, least-privilege modules covering networking, compute, IAM, and security groups, reducing configuration drift by approximately 40% and addressing recurring audit findings caused by manual infrastructure changes.
- SRE Observability Stack: Built and operated an SRE-grade observability stack (Prometheus, Grafana, Loki, Mimir, CloudWatch) with actionable alerts and service dashboards, reducing incident frequency by approximately 30% and MTTR by approximately 40%.
- Incident Management: Drove incident management and a blameless postmortems culture, owning on-call response, root-cause analysis across cloud, application, and data layers, and tracking corrective actions to closure while maintaining SLA-level reliability.
- Safe Delivery Procedures: Partnered with application engineers on release procedures and safer rollouts (canary and blue-green patterns), improving change safety while meeting uptime requirements in a regulated environment.
Associate Cybersecurity & QA
Oct 2024 – Jul 2025- Reliability CI/CD Guardrails: Built reliability-focused CI/CD guardrails, adding rigorous testing and release procedures (staged rollouts, automated health checks, and rollback) to keep high-change services stable.
- Shift-Left Security Controls: Integrated shift-left security controls directly into CI/CD workflows, enforcing automated vulnerability scanning and API security validation as build gates covering OAuth 2.0/OIDC, SAML-based authentication and authorization, input validation, and encryption controls.
- Serverless Malware Pipeline: Architected a serverless malware detection and quarantine pipeline using GCP Cloud Run and ClamAV, automatically scanning uploaded media and preventing malicious files from reaching production storage.
- Distributed Systems Troubleshooting: Performed distributed systems troubleshooting across event-driven services (webhooks, queues, and storage), isolating failure modes such as retries, duplication, and backpressure, and implementing mitigations to reduce incident recurrence.
- Rapid Incident Response: Led technical incident response for a data-exfiltration event caused by a misconfigured third-party webhook, performing exposure analysis, containment, remediation, and secure-data-handling restoration within 24 hours.
- SDLC Assurance: Strengthened application security assurance by integrating authentication, authorization, vulnerability detection, and security validation into the software delivery lifecycle, reducing the reliance on post-deployment security discovery.
Cyber Security Intern
Mar 2024 – May 2024- Operational Readiness & Baselines: Supported production support readiness by building an asset inventory, documenting operational baselines, and validating endpoint compliance against defined security controls.
- NIST Governance Framework: Established the organization’s initial security governance foundation, authoring security policies and baseline standards aligned with the NIST Cybersecurity Framework.
- Control Gap Remediation: Implemented asset inventory and endpoint compliance validation against defined security baselines, identifying configuration and control gaps for remediation.
- Threat Research & Risk Register: Supported vulnerability assessment, threat research, and risk-register development, translating technical findings into actionable security and governance requirements.
- Systems Diagnostics: Strengthened fundamentals in UNIX and networking (processes, system logging, TCP/IP basics) to better support incident triage and root-cause analysis in production systems.
Technical Skills Matrix
Comprehensive skill inventory aligned with modern cloud security and reliability engineering standards.
Cloud Security & Identity
Infrastructure as Code
DevSecOps & CI/CD
Containers & Platforms
Observability & Reliability
Security, Code & Compliance
Featured Projects
Production-grade cloud security platforms and automation suites.
Automated IAM Governance & Configuration Drift Detection Engine
- Engineered an automated IAM governance platform that evaluates AWS IAM policies and access configurations against least-privilege baselines to identify excessive permissions and configuration drift.
- Implemented continuous access-governance validation, CloudTrail-based monitoring, real-time SNS alerting, and audit-ready reporting, replacing manual IAM reviews with automated security controls.
- Added a lightweight anomaly-scoring workflow to prioritize risky access changes, an AI tools-style triage layer that reduced alert noise and sped up investigation queues.
Secure CI/CD & Infrastructure Automation Pipeline
- Engineered a security-focused CI/CD pipeline integrating source validation, Terraform plan/apply workflows, approval gates, container deployments, and automated rollback controls.
- Embedded infrastructure and deployment validation into the software delivery lifecycle, preventing misconfigurations from progressing through deployment workflows.
- Built canary health probes auditing `/healthz` and response latency SLAs, triggering self-healing rollbacks in < 2.0s with automated post-mortem incident generation.
Serverless Malware Detection & File Quarantine Pipeline
- Designed an event-driven malware detection and quarantine architecture using AWS Lambda and ClamAV to automatically scan uploaded media before allowing clean content to reach S3.
- Implemented automated quarantine and SNS-based security alerting to isolate malicious uploads and reduce the attack surface associated with user-generated content.
- Integrated DynamoDB tracking for immutable audit logging and incident analysis.
SAMYA — Cloud-Native Health Management Platform
- Architecting a cloud-native health management platform that brings medication tracking, wellness, health readings, prescriptions, reports, nutrition, hydration, exercise, women's health, and health records into a unified platform.
- Engineering secure REST APIs and role-based access controls (RBAC) with encryption and audit logging to protect sensitive health information and maintain traceability across user workflows.
- Developing an AI-powered wellness experience designed to help users understand health patterns, build healthier habits, and receive personalized lifestyle guidance from their health data.
- Containerizing the application with Docker and designing the platform around security, privacy, and healthcare data-protection requirements aligned with HIPAA and DPDP principles.
Education
Pace University
Master's, Computer Science
Savitribai Phule Pune University
Bachelor's, Computer Engineering
Certifications & Achievements
HashiCorp Certified: Terraform Associate (004)
HashiCorp • Jun 2026
AWS Certified Solutions Architect – Associate
Amazon Web Services • Aug 2025
CompTIA Security+ ce
CompTIA • Jun 2025
AWS Certified Cloud Practitioner
Amazon Web Services • Jul 2024
Let's Connect
I am currently open to exciting opportunities in Cloud Security, Site Reliability Engineering (SRE), and DevSecOps. Feel free to reach out directly or send a message below.