Aws Cloud Engineer
Current• Managed user accounts for personnel and external entities, adhering to least privilege principles and IAM best practices.• Enabled CloudTrail for security monitoring, with SNS notifications for system changes.• Designed VPCs with public and private subnets, route tables, and NAT instance. Implemented AWS Site-to-Site VPN using OpenSwan Instance as customer gateway.• Created launch templates for ASGs to deploy EC2 instances with userdata scripts for Apache installation, CodeCommit integration, and CodeDeploy agent setup.• Enhanced security with internet-facing NLB for SSH connections to bastion hosts in private subnets.• Implemented login banner on Linux instances, mounted EFS for file sharing, and scheduled Lynis scans using SSM for internal audits.• Created "Break Glass" user for emergency access and automated instance updates.• Collected custom metrics using CloudWatch agent and Ansible playbooks.• Configured Lambda functions to manage ProCore Lab environments during work hours for cost reduction.• Installed Pritunl client for on-premise CheckMK server access and AWS account service limit monitoring.• Deployed Splunk Enterprise Server and Universal Forwarder Agent for centralized log management.• Developed CloudFormation template for improved website deployment across VPCs and accounts.• Collaborated on Terraform project for WordPress deployment with RDS MySQL.• Assisted with CRM app deployment, including LAMP stack initialization and Lambda function configuration for work-hour operation.• Deployed client websites using ECS containers, utilizing S3, EFS, and NGINX docker image.