# deployments.list
System Deployments
Production systems engineered for resilience, security, and scale.
Multi-Account AWS Cloud Platform
ProductionArchitected a secure, scalable multi-account AWS environment at Screenrights using Control Tower and Terraform - Zero Trust networking between Production, Non-Production, and On-Prem.
use ← → arrow keys to navigate
# work.logs
Experience
▸Architected a multi-account AWS cloud environment using Control Tower, IAM Identity Center, and Terraform - implementing Zero Trust networking between Production, Non-Production, and On-Prem.
▸Built Bitbucket CI/CD pipelines with shift-left security scanning (Checkov, Semgrep, Snyk, Trivy) and serverless sandbox environments for developer autonomy.
▸Improved delivery cycle time by 30% as Scrum Master through automated release pipelines and deployment tooling.
▸Established monitoring with AWS CloudWatch and Sentry; authored E2E test suite with Cypress for screenrights.app.
▸Led end-to-end migration of Marketing team AWS workloads to the new ANZ platform - standardised CI/CD pipelines in Codefresh for IaC, EKS, and Lambda releases.
▸Provisioned EKS clusters with Helm and delivered a Terraform/Terragrunt Lambda + DynamoDB Unsubscribe API for marketing email compliance.
▸Embedded security in the pipeline with Twistlock (Prisma Cloud), IAM least-privilege, and continuous vulnerability scanning.
▸Established team-wide observability standards via CloudWatch and Splunk dashboards; led incident post-mortems and mentored engineers.
▸Maintained top 5% global standing in incident management across EKS, ECS, Fargate, ECR, Batch, and Cloud Map portfolios.
▸Performed deep root-cause analysis on complex container service issues, collaborating with AWS engineers on time-sensitive enterprise escalations.
▸Upheld SLAs through proactive issue detection; authored support procedures and mentored new engineers on container services.
▸Product Owner for the Observability Squad - delivered Elastic, New Relic, and PagerDuty dashboards and alerts, reducing MTTD and MTTR.
▸Integrated Snyk into the SDLC to embed a security-first approach for microservices; supported AKS and EKS clusters with Terraform and Ansible.
▸Enabled CI/CD adoption with Jenkins and drove DevOps best practices across cross-functional teams.
❯ verified.credentials
Certifications
# system.pipeline
DevSecOps Lifecycle
Security integrated at every stage. Continuous feedback from plan to monitor.
Plan
Threat modeling & security reqs
SECCode
SAST, linting & secure standards
DEVBuild
CI pipelines, SCA & signing
DEVSecure
DAST, container scan & gates
SECDeploy
GitOps, IaC & immutable infra
OPSMonitor
SIEM, runtime & incident response
OPS# initiate_contact