Devops Engineer
CurrentNetworking and Security• Manage multi-account networks on AWS (VPC, Subnets, Nat, TGW, VPC Peering, etc)• Manage security policies on AWS (ACL, Security Groups, WAF, Shield, etc)• Manage IAM policies of AWS services Monitoring and Observability• Implemented and maintain solutions like: -> CloudWatch -> OpenSearch, Kibana -> Grafana, Tempo, Prometheus, Loki • Create key metrics and alerts to check the general health of our services• Implement and manage audit log service responsible for saving and querying access logs from Cloudfront distributions and LoadBalances (S3 and Athena) Cost Optimization• Decrease costs with data transfer on AWS • Implemented AWS shield to decrease cost with AWS WAF (40% cost reduction)• Plan and purchase RI and SP (Avarage of 40% cost reduction)• Remove or change underutilized instances to cheaper options• Added Spot Fargate to our ECS clusters (70% cost reduction for each task) Automation• Implement and maintain custom batch pipeline service used to deploy and schedule batches• [ISMS] Implement and maintain data lifecycle project to automatically mask, delete, or migrate data from our RDB instances to other databases and AWS Service (S3 and Athena)• Manage and maintain custom CLI with helpers and automation to be used by other developers CI/CD• Implement and manage custom CI/CD agent for Azure DevOps (Docker/ECS)• Manage AWS Code Pipeline environment• Manage and maintain a generic IaC library built with CDK to create the infrastructure necessary to run our services -> CloudFront, ALB, ECS, Lambda, API Gateway, Route 53 Development• Develop and maintain NodeJs Typescript applications running on Lambda and ECS• Developed, and optimized legacy C# applications hosted on AWS Beanstalk Support• Support and guide other teams on AWS services, and architecture• Support other teams with general technical questions, helping them to troubleshoot/debug and solve any major issue