Infrastructure built
by the guy who got
paged for it.
Fixed-price AWS and Azure engagements — landing zones, security hardening, and the automation work that actually reduces pages. Twenty years running the systems, not just diagramming them.
Scoped engagements, priced before work starts
Fixed-price, scoped up front — you get a written proposal with a firm number before I touch your account, usually within 48 hours.
Cloud architecture & build
Landing zones, multi-account and multi-subscription governance, networking, cross-account architecture — AWS or Azure. Delivered as CloudFormation or Terraform, reviewable and yours to keep.
Security & compliance hardening
GuardDuty, Security Hub, IAM, CloudTrail — audit-ready posture built once, not re-explained at every review. Comes out of incident response.
AI-assisted automation & MCP
Lambda and Bedrock automation for security triage and alert enrichment, plus custom MCP servers connecting your data to an LLM instead of a chatbot bolted onto a dashboard.
Still running today
Working systems, doing the job they were built for.
SMS scheduling, off the sole proprietor's plate
A home-services business running Jobber, its field service management platform, needed customer reminders and scheduling that didn't depend on someone remembering to send them — plus a way to not lose the message when SMS delivery failed. Built an AWS Lambda automation against the Jobber API, backed by an SES email fallback on full production DNS routing.
GuardDuty Triage Investigator
GuardDuty throws a finding — someone still has to pull CloudTrail context, correlate events, and call it a real threat or noise, usually at 2am. A Bedrock-powered Lambda assumes a cross-account read role, pulls the surrounding CloudTrail context automatically, and returns a verdict: HTML report over SES, JSON copy to an S3 audit archive.
Off a vendor, onto native AWS Backup
A 24-account AWS Organization was paying for third-party backup software while coverage gaps sat unnoticed. Migrated the production-workload accounts to AWS's own backup service — cross-account vaults, cross-account copy, live recovery points. Before authorizing the old vendor's data for deletion, verified every surviving backup — 893 AMIs, 1,051 EBS snapshots — was already covered by the new setup.
A SIEM without the SIEM invoice
Built a SIEM on native AWS tooling — Security Lake as the ingestion spine, Athena as the query layer. CloudTrail, VPC Flow, DNS, and Security Hub findings, ingested org-wide. First catch, day one of it running: four critical vulnerabilities across four production services, found and patched same-day.
Quiet unless something's actually wrong
One Lambda, two jobs: hunts CloudTrail daily for privilege-escalation patterns and credential-abuse signals, and rolls Security Hub findings into a single daily email. Stays silent unless something clears the bar — it once flagged a real privilege-escalation-shaped sequence that turned out to be an unannounced but authorized contractor action. Correctly caught, correctly resolved.
Built by someone who's run production cloud infrastructure
Every engagement I take comes with the scar tissue of a production incident, a 2am page, or a compliance audit that couldn't wait. Twenty years in infrastructure — help desk to CTO — means I've seen what breaks, and usually why.
A working deliverable on a realistic timeline, not an open-ended hourly clock.
Based in Brecksville, Ohio. Available for fixed-price project engagements, AWS and Azure both.
Focus areas
- AWS & Azure Infrastructure — landing zones, networking, multi-account/subscription primary
- Security & Compliance — GuardDuty, Security Hub, IAM, CloudTrail
- Custom MCP servers & AI agent workflows Python 3.12
- Amazon Bedrock & Lambda automation
- Infrastructure as Code — CloudFormation, Terraform, ARM/Bicep YAML · HCL
- AWS WorkSpaces & VDI 20yr background
Tell me what needs to ship.
I read and answer my own email.