DELPHINE WEPONG KHAN
San Jose California, 95128
Phone number: 669-***-****
Email: ***********@*****.***
PROFFESSIONAL SUMMARY
A competent AWS engineer offering 5 years of experience and knowhow skills in Devops, and architecture to meet and exceed prospects and existing customer requirement in Compute resources, networking, route 53, s3, IAM management, security, CloudFormation, terraform, docker, Kubernetes, CICD pipeline, CloudWatch, auto scaling, graphic presentations, sustainable strategies, and many others. As an AWS cloud engineer, I work to bring satisfactory solutions to both potential and existing customers, thereby enabling the organization to achieve optimum cost and maximize their profit margin to the later. PROFESSIONAL SKILLS
Cloud Orchestration/Automation: AWS CloudFormation, Terraform, AWS Lambda, AWS Systems Manager, AWS SSM Parameter Store, Ansible, Docker
Implemented container management and deployment with Kubernetes clusters
Monitoring & Event Management: AWS CloudWatch (Events & Logs), AWS SNS, AWS S3
Identity & Access Management: AWS Organization, AWS IAM, Active Directory, AWS Workspaces, AWS Secrets Manager, etc
Governance & Compliance: AWS Config Rules, AWS Organization, AWS Control Tower, AWS Trusted Advisor, AWS Well Architected Tool, AWS Budgets, etc
Programming Languages: Bash, YML, Python
Application Delivery: Jenkins
Network: VPC, VGW, TGW, CGW, IGW, NGW etc
AWS Platform: AWS CloudFormation, AWS Lambda, AWS Systems Manager, S3, VPC, EC2, ELB, RDS, SNS, SQS, SES, Route53, CloudFront, Service Catalog, AWS Auto Scaling, Trusted Advisor, CloudWatch etc
Ability to gather technical requirements from potential and exiting customers and architecting the solutions to meet their requirements, while integrating seamlessly with their network, API gateways, and application infrastructure.
Ability to build a strong conviction to the customer by presenting strong proof of concept (PoC)
Keeping in mind and always making use of AWS best practices which helps potential and existing customers to derive maximum benefits from the solutions. some of such may include, giving least privileges to your security groups. Proper management of authentication and authorization for IAM, encrypting information and many others.
Develop detailed migration plans for workload from and platform to AWS.
Utilizing workload migration tools to AWS such as cloud endure, ADS and CART.
Detailed knowledge to evaluate and utilize the most suitable migration strategy.
Setting up an AWS landing zone that is safe and secured for both server and data base migration
Migrating both homogenous and heterogenous data base to AWS
Implementing security access policies using least privilege principle and segregation of duties. PROFESSIONAL EXPERIENCE
Tesla INC- DevOps Engineer
Accomplishments/Main Duties:
JAN 2019 present
Developed CI / CD to standardize the infrastructure and automate the DevOps processes, allowing customers to rapidly build, test, and release code while minimizing errors.
RESTful API. Communicating between micro services using GET, PUT, DELETE APIs.
Bash Scripting for installing packages and running croon jobs
Designed secured, cost optimized, highly available and fault tolerant infrastructure in AW
Architected and configured Dev/Stage/QA environments in AWS (VPC, subnets, security groups, EC2 instances, load balancer, RDS, Redis, route53, etc)
Implemented security best practices in AWS including multi factor authentication, access key rotation, role based permissions,
enforced strong password policy, configured security groups and NACLs, S3 bucket policies and ACLs, etc
Optimized cost through reserved instances, selection and changing of EC2 instance types based on resource need, S3 storage
classes and S3 lifecycle policies, leveraging Auto Scaling etc
Making us of security tools such as nexpose to do a vulnerability scanning in my environment.
Configured CloudWatch alarm rules for operational and performance metrics for our AWS resources and applications
Setup and configured logs files for detail monitoring and alerts notification when changes are made.
Monitoring from end-to-end view of runtime systems CPU, bandwidth, disk space and log files using New Relic
Deployed and configured infrastructure using Terraform and Ansible
Architected and implemented continuous integration and deployment pipelines using Jenkins Kaiser Permanente: CA- AWS Architect June 2018 - Dec 2018 Accomplishments/Main Duties:
Designed for high availability and business continuity using self-healing-based architectures, fail-over routing policies, multi-AZ deployment of EC2 instances, ELB health checks, Auto Scaling, and other disaster recovery models.
designs/development aspects of migration journey - assess, mobilize and migrate phase including leveraging CART, ADS, Migration Evaluator, DMS, Cloud Endure etc
Implemented AWS Systems Manager management service capabilities to automatically collect software inventory, apply OS patches, and automate administration tasks and complex workflows across our environments.
Leveraged different design principles for security in the cloud and implemented various AWS services to improve our security posture for Authentication, Authorization, Monitoring, Auditing, Encryption and Data path security.
Implemented docker containers on AWS using ECS and complementary services, including Amazon Elastic Container Registry
(ECR).
Developed terraform modules and CloudFormation templates to provision infrastructures in cloud
Leveraged AWS Control Tower to set up and govern a secure, multi-account AWS environment based on developed and created custom Service Control Policies and attached them to approved OUs and AWS accounts as required
Deployed GuardDuty across our Control Tower managed organization with the Audit account being the delegate administrator
Designed secured, cost optimized, highly available and fault tolerant architecture designs and infrastructure in AWS.
Implemented security best practices in AWS including multi factor authentication, access key rotation, role-based permissions, enforced strong password policy, configured security groups and NACLs, S3 bucket policies and ACLs.
Optimized cost through reserved instances, selection and changing of EC2 instance types based on resource need, S3 storage classes and S3 lifecycle policies, leveraging Autoscaling.
Configured CloudWatch alarm rules for operational and performance metrics for our AWS resources and applications.
Configured S3 events to set up automated communication between S3 and other AWS services.
Designed highly available infrastructure using Elastic load balancer and auto-scaling for Web servers which Scale in and scale out automatically, also isolated environment by having security groups and NACL across subnets for EC2 instances.
Architected and Implemented AWS Cloud cost effective solution for Non-Production environment such as Development, and Test.
Managed tools like JIRA, Confluence, Jenkins and their usage / process ensuring traceability, repeatability, and quality. HCL AMERICA, INC.-AWS Infrastructure Engineer December 2017 –May 2018 Accomplishments/Main Duties:
Managed provisioning of AWS infrastructures using CloudFormation and Terraform.
Designed for high availability and business continuity using self-healing-based architectures, fail-over routing policies, multi-AZ deployment of EC2 instances, ELB health checks, Auto Scaling, and other disaster recovery models.
Created patch management using Systems Manager automation for multi-region and multi account execution.
Implemented detective guardrails using Cloud Custodian policies and AWS config.
Designed and implemented for elasticity and scalability using ElastiCache, CloudFront – Edge locations, RDS (read replicas, instance sizes), etc.
Used AWS system manager to automate operational tasks across AWS resources.
Used System Manager to automate operational tasks across customer’s AWS infrastructure.
Developed and documented security guardrails for AWS Cloud environments.
Built custom images though docker server, docker compose with multiple local containers, and created production grade workflows and a continuous application workflow for multiple images. PROFESSIONAL SUMMARY
To secure a position in the cloud technology industry that will utilize my strengths as a logical and process-oriented person helping to direct an enterprise toward greater success by optimizing and improving existing processes then implementing new technologies to place that enterprise in the fore front of its competitors. I strongly believe and practice that whenever one is giving an opportunity to serve do it with all due diligence.
CERTIFICATION &EDUCATION
- AWS CERTIFIED SOLUTIONS ARCHITECT – ASSOCIATE
- SWISS SCHOOL OF BUSINESS : MASTERS IN INTERNATIONAL ACCOUNTS AND BUSINESS MANAGEMENT- 2015-2017