Desmond Ndambi
**** **** ****** **, ***** Marlboro, MD 20774
**************@*****.*** 240-***-****
PROFESSIONAL SUMMARY
Highly skilled, self-motivated, and results-driven cloud IT professional with about 8+ years of working experience in Architecting Cloud Solutions in different environments. Proficient in cloud automation, orchestration, security, Identity & access management, event management, data protection, monitoring, governance and compliance, application delivery, image, and patch management. Highly experienced in building, planning, implementing, and maintaining system applications on InterSystems IRIS, AWS and AZURE Cloud platforms. Problem solver and committed team member with the flexibility to adapt to all environments.
TECHNICAL EXPERIENCE
Primary Languages:
PowerShell, TypeScript, Node.js, Python, Perl, BASH, C++, C#, Java, PHP, JavaScript, and HTML5
Tooling, Services & Libraries - Boto3, Puppet, Chef, Ansible, ScienceLogic, SolarWinds, PRTG, MRTG, Nagios, IBM Tivoli Netcool, Jenkins, Git, GitHub, Terraform, Trend Micro Deep Security
Containers - Docker, ECS, Trend Micro Smartcheck
Databases - MySQL, MSSQL, Oracle, and various NoSQL
Operating Systems - Windows Server 2012 R2, Windows Server 2016, CentOS, Ubuntu, Debian
Agile – Jira
Architecture styles – REST, GraphQL
AWS Experience:
AWS Infrastructure Scripting - AWS Lambda, AWS CDK, CloudFormation, AWS Systems Manager, AWS SSM Parameter Store,
AWS Core Services - AWS SaaS, Paas, IAM, AWS EKS, AWS Systems Manager, S3, VPC, EC2, ELB, SNS, SQS, SES, Route53, CloudFront, Service Catalog, AWS Auto Scaling, Trusted Advisor, CloudWatch.
AWS Networking Services - VPC, VGW, TGW, CGW, IGW, NGW, Client VPN
AWS Code* Services - AWS Codestar, AWS Code Pipeline, AWS Code Commit, AWS Cloud9
AWS Security Services - AWS Security Hub, AWS Guard Duty, AWS Shield, AWS Firewall Manager, AWS Inspector, MFA, access key rotation, security groups and NACLs, data encryption using KMS, S3 bucket policies, mitigating DDOS attacks etc.
AWS Serverless Services – AWS Lambda, AWS SDK.
AWS Database Services - RDS, Amazon Aurora, DynamoDB.
AWS Container Services - ECS
AWS Application Services - AWS Code Pipeline, AWS Code Commit, AWS Cloud9
Data Protection - AWS Certificate Manager, AWS KMS, AWS Cloud HSM, SSL Certificate lifecycle management, Snapshot Lifecycle Manager.
Monitoring & Event Management: AWS CloudWatch (Events &Logs), AWS SNS, SQS, AWS S3
Governance & Compliance: AWS Config Rules, AWS Organization, AWS Control Tower, AWS Trusted Advisor, AWS Well-Architected Tool, AWS Budgets, AWS License Manager
Azure Experience:
Compute: Virtual Machines, Azure Container Instances, Azure Kubernetes Service, Azure Functions, Azure Batch
Networking: Virtual Network, Azure Load Balancer, Azure Application Gateway, Azure VPN Gateway, Azure Firewall
Storage: Azure Blob Storage, Azure Files, Azure Queue Storage, Azure Table Storage, Azure Disk Storage
Databases: Azure SQL Database, Azure Cosmos DB, Azure Database for MySQL, Azure Database for PostgreSQL
Analytics: Azure Synapse Analytics, Azure HDInsight, Azure Data Lake Analytics, Azure Stream Analytics, Azure Databricks
AI + Machine Learning & Internet of Things (IoT): Azure Machine Learning, Azure Cognitive Services, Azure Bot Service, Azure Custom Vision, Azure IoT Hub, Azure IoT Central, Azure IoT Edge, Azure Time Series Insights
Security + Identity: Azure Active Directory, Azure Security Center, Azure Sentinel. Azure Key Vault, Azure Information Protection
DevOps: Azure DevOps Services, Azure DevTest Labs, Azure Artifacts, Azure Repos, Azure Pipelines
Management + Governance: Azure Monitor, Azure Resource Manager, Azure Policy, Azure Automation, Azure Cost Management + Billing
WORK EXPERIENCE
Quest Diagnostics June 2021 – Date
Senior AWS & Azure Infrastructure Architect DevOps Engineer
•Regularly intervene in different phases of the SDLC, including requirements gathering, design, development, testing, deployment, and maintenance.
•Used Amazon connect to create and configure a contact center by defining routing options, setting up hours of operation and creating custom prompts and messages for clients.
•Configuration of Continuous Integration (CI) and Continuous Delivery (CD) using Tekton, ArgoCD, and GitOps, Code Pipeline and Code Deployment for automation.
•Used CloudFormation, AWS CDK and Terraform to provision, manage and configure AWS services in a global configuration.
•Integrated Amazon Voice Connect with service now using a set of lambda functions. This integration enhanced the experienced of employees and customers who interacted with our contact center
•Working with configuration management tools including Ansible Automation Platform(AAP), Source Code Management tool GitHub and Jenkins for Continuous Build Management.
•Use Kubernetes extensively as a tool for automating, autoscaling, and management of containerized workloads.
•Use AWS ECR ECS and EKS container management and orchestration within the AWS platform.
•Design, develop, and implement scalable cloud-based solutions for enterprise clients using AWS technologies including Aurora, EKS, and AWS Glue.
•Collaborate with cross-functional teams including developers, QA, DevOps, and business analysts to gather requirements, design solutions, and ensure successful implementation.
•Use Jira to plan, track, support, and close requests, tickets, and incidents.
•Use Shell, Bash, YAML, JSON, and Python scripting languages, for day-to-day automation operations.
•Design and architect self-healing, secured, highly available, and fault-tolerant infrastructures.
•Use SSL certificate manager lifecycle to consolidate Deploy, renew track and manage keys.
•Experience in creating and editing shell, bash and python scripts for automation.
•Architect Amazon RDS with Multi-AZ for automatic failover.
•Maintenance and configuration of user accounts for Dev, QA, and production servers, creating roles for EC2, RDS, S3, and Cloud Watch resources to communicate with each other using IAM.
•Migrating and implementing multiple applications from on-premise to cloud using AWS services, SMS, DBMS, Cloud Endure, Cloud Formation, S3, Route 53, Glacier, EC2, RDS, SNS, Lambda, VPC, Cloud Trail, API gateway.
•Build and configure a virtual data center in the AWS Cloud to support Enterprise Data Warehouse hosting including Virtual Private Cloud (VPC), Public and Private Subnets, Security Groups (SG), Route Tables, Elastic Load Balancers ELB), Route 53.
•Build servers using AWS, importing volumes, launching EC2, RDS, creating SG, auto-scaling, ELBs in the defined VPC.
•Designed AWS CFT’s to create multi-region web applications and databases.
•Using CloudWatch, VPC Flow Logs to monitor and retain account activity related to actions across AWS infrastructure.
•Data fetching and manipulation through GraphQL mutations and RESTful CRUD operations.
•Leverage AWS System Manager to automate communication between S3 and other AWS services.
•Solution VPCs for various environments including NAT Gateway, VPC Peering and Transit Gateways.
•Used ElasticSearch security features like authentication, encryption for implementing security measures to protect Snowball Edge logs from unauthorized access.Also used for compliance and auditing purposes such as making sure all the data stored in snowball edge logs are HIPAA and PHI compliant.
•Used OpenSearch as part of Elastic Stack(ELK stack) as a centralized location for storing all kinds of logs,metrices on nodes and pods in the Kubernetes cluster. Also used to analyze CPU usage of EC2 instances.
HCL America Inc Feb 2019 – May 2021
Senior AWS & Azure Solution Architect DevOps Engineer Agile Coach
•Responsible for launching Amazon EC2 instances using AWS (Linux) and configuring launch instances with respect to specific applications and regions.
•Build servers using AWS importing volumes, lunching EC2 instances, RDS, creating SGs and NACL, auto-scaling, ELB in the defined VPCs.
•Created Lambda functions using TypeScript and Node.js and integrated them with AWS API Gateway to build RESTful APIs
•Configuration of Continuous Integration (CI) and Continuous Delivery (CD) using Code Pipeline and Code Deployments for automation.
•Used DevOps Tools to assist in the migration of applications to other cloud computing models such as platform as a service (Paas) and (IaaS).
•Responsible for creating monitors, alarms, and notifications for EC2 hosts using Cloud Watch, SNS, SMTP.
•Implemented Single Sign-On (SSO) solutions using OAuth2 and OpenID Connect protocols.
•Conducted security assessments and audits to identify and mitigate potential IAM vulnerabilities.
•Work with internal teams to create the migration process of legacy systems to AWS cloud.
•Work with business unit managers to understand project scope, suggest possible alternatives and document each step of the design.
•Work with Security division to design and manage IAM roles for users, vendors and other third-party vendors, Encrypting data.
•Work with several third-party vendors in big data and other areas to support our overall cloud initiative.
•Partner with the sales team, formulate and execute a sales strategy to exceed revenue objectives through the adoption of AWS
Africa Opportunity Platform (Breuillet, Ile-de-France) Jan 2015 – Dec 2018
AWS Infrastructure / DevOps Engineer
•Configuration of Continuous Integration (CI) and Continuous Delivery (CD) using Code Pipeline and Code Deployments for automation.
•Used DevOps Tools to assist in the migration of applications to other cloud computing models such as platform as a service (Paas) and (IaaS).
•Responsible for launching Amazon EC2 instances using AWS (Linux) and configuring launch instances with respect to specific applications and regions.
•Responsible for S3 buckets creation, policies and IAM role-based policies.
•Responsible for creating monitors, alarms, and notifications for EC2 hosts using Cloud Watch, SNS, SMTP.
•Migration and implementation of multiple applications from on premise to cloud using AWS services like, CloudFormation, S3, Route 53, EC2, RDS, SNS, Lambda, Kinesis and VPC.
•Work with internal teams to create the migration process of legacy systems to AWS cloud.
•Work with business unit managers to understand project scope, suggest possible alternatives and document each step of the design.
•Work with Security division to design and manage IAM roles for users, vendors and other third-party vendors, Encrypting data.
•Work with several third-party vendors in big data and other areas to support our overall cloud initiative.
•Partner with the sales team, formulate and execute a sales strategy to exceed revenue objectives through the adoption of AWS
Cyclad (Chorzow, Poland) Jan 2012 – December 2014
AWS Solution /Certified Scrum Master
•Used CloudFormation and Terraform to provision, manage and configure AWS services in a global configuration
•Design and Built multi-AZ, multi-region deployment of EC2 instances, ELB health checks, Auto Scaling and other disaster recovery models.
•Optimized cloud infrastructural cost and performance using the AWS prancing Calculator.
•Designed and implemented for elasticity and scalability using CloudFront – Edge locations, RDS (read replicas, instance sizes)
•Led daily scrum stand-ups and Agile development sprint planning meetings for multiple, concurrent projects
•Trained and mentor team members on best and most effective ways to use Scrum processes to improve efficiency and reduce production times
•Lead Agile teams in the development of data warehouse, business intelligence, data lake and cloud technologies within Agile environment
•Assessed team metrics and worked to drive improvements and innovate new approaches
•Managed multiple internal and outside scrum teams, ensuring effective collaboration and communication
•Coached teams on how to best refine the backlog and create stories
•Removed impediments and barriers to the team progress
•Drove and managed transparency through relevant JIRA dashboards and metrics for continuous improvement to communicate project/team health and status
•Ensured strong working relationships between the team and others outside of the team
•Track team progress using burn down chart, burn up and velocity
CERTIFICATIONS
•PCAP – Certified Associate in Python Programming
•CyberArk Defender – PAM
•Certified Kubernetes Applications Developer
•Nanodegree in AWS Solution Architect
•Nanodegree in AWS DevOps
•Certified Scrum Master.
EDUCATION
•Catholic University of America, Washington DC: Graduation 2019
•M.S. Engineering
•Udacity, California: Graduation 2020
•Scrum Alliance