We provide IT Staff Augmentation Services!

Cloud Engineer Resume

5.00/5 (Submit Your Rating)

SUMMARY

  • Experienced in designing, implementing, deploying, migrating, and integrating AWS & Azure hybrid cloud solutions.
  • Experienced in designing and implementing AWS VPC network and IAM security solutions.
  • Designed and implemented a real - time IOT streaming data BI solution with Amazon Kinesis Data Analytics.
  • DevOps experience to support automation through CI/CD integration with code analysis, unit & regression testing, and deployment.
  • Strategized, designed, and implemented on-prem Informatica cloud data IPaaS (Integration Platform as a Service) solution to support cloud-platform-agnostic cloud migration and cloud integration.

PROFESSIONAL EXPERIENCE

Confidential

Cloud Engineer

Responsibilities:

  • To comply with local regulation and improve performance, used Route 53 geolocation routing policy to route user request to local website with Lambda@Edge and Cloudfront/S3.
  • Designed and implemented a multi-layered VPC - based AWS network security solution:
  • Used Internet Gateway, NAT Gateway, and VPC endpoints for VPC layer’s security controls.
  • Used NACLs (Network Access Control List), and Rout Tables for Subnet layer’s security controls.
  • Used SGs (Security Group) for EC2 instance / ENI (Elastic Network Interface) layer’s security controls.
  • Designed and implemented Cognito IAM solution:
  • Used Cognito User Pool for authentication to API Gateway through on-prem SAML federating Identity Provider ADFS.
  • Used Cognito Identity Pool/STS to map IAM roles to users for authorization to AWS resources.
  • To fine-grained control access AWS resources for all IAM principals:
  • Used SCPs (Service Control Policies) with AWS Organizations to set permission guardrails.
  • Used identity-based policies for the requester’s account and resource-based policies for the resource’s account.
  • Designed and implemented data security solution to protect data in transit and at rest:
  • Used CloudHSM to manage TLS private keys and certs. Used https to secure data in transit for API and web access.
  • Used KMS to store symmetric Customer Master Keys (CMKs) and generate Data Keys to encrypt data at rest.
  • Implemented Server-Side Encryption with KMS-managed CMK for S3, DynamoDB, CloudTrail in S3 and EBS (Elastic Block Store).
  • Published various type of requests to SNS topics for the corresponding SQS subscriptions for OLTP (On-Line Transaction Processing) and OLAP (On-Line Analytical Processing).
  • Used DynamoDB for OLTP and Redshift for OLAP.
  • Used CloudFormation to create/update stacks based on template to configure and provision AWS resources.

Environment: Eclipse, Bitbucket/Git, Jira, Maven, CloudFormation, Jenkins, JFrog Artifactory, BMC Release Process Management (BPM)

Confidential

Tech Architect

Responsibilities:

  • Proven track record in designing and agile developing component-based SOA solutions for enterprise distributed systems in cloud (AWS/Azure), non-cloud as well as hybrid environments.
  • Chief architect for global product line of Digitalization of Vehicle Distribution with seven products.
  • Solution architect of cloud and cybersecurity and integration for major global programs: HR (Human Resource), DSC (Data Supplier Chain), Marketing & Sales, Connected Vehicle including Smart Finished Vehicle Delivery, China New Energy Vehicle Data Monitor projects, FordPass, and Autonomous Vehicle.
  • Led and guided global interoperability forum to manage the interoperability technology standard and best practices.
  • Solution architect for enterprise integration/interoperability and cybersecurity services: IBM DataPower, Microsoft BizTalk, Axway B2Bi and Informatica IICS/CIH.
  • Extensive experiences to use OOAD to analyze and design SOA applications. Co-author of SOA pattern for Web Services, Co-author of SaaS (Software as a Service) Usage Guide, and XML Security Gateway Guide.
  • Research and POC (Proof of Concept) on emerging technologies: Authored Architecture Strategy of Managed File Transfer, Text analytics, RESTful API, Consumer-facing Identity and Access Management.

Environment: AWS, Kinesis Firehose/Data Streams/Data Analytics, Lambda, S3, DynamoDB, SNS, SQS, TMC/Autonomic, DataPower, SQL Server, Windows, Linux, Java, JavaScript, XML, JSON, Restful Web Services, Microservices, Dynatrace, Jenkins, Kubernetes, JIRA, Maven, GitHub, Rally, Nexus, Spring/Spring Boot/Spring Cloud, Tomcat, Swagger, Qlik Sense Cloud.

We'd love your feedback!