Cloud Engineer Resume
5.00/5 (Submit Your Rating)
SUMMARY
- Experienced in designing, implementing, deploying, migrating, and integrating AWS & Azure hybrid cloud solutions.
- Experienced in designing and implementing AWS VPC network and IAM security solutions.
- Designed and implemented a real - time IOT streaming data BI solution with Amazon Kinesis Data Analytics.
- DevOps experience to support automation through CI/CD integration with code analysis, unit & regression testing, and deployment.
- Strategized, designed, and implemented on-prem Informatica cloud data IPaaS (Integration Platform as a Service) solution to support cloud-platform-agnostic cloud migration and cloud integration.
PROFESSIONAL EXPERIENCE
Confidential
Cloud Engineer
Responsibilities:
- To comply with local regulation and improve performance, used Route 53 geolocation routing policy to route user request to local website with Lambda@Edge and Cloudfront/S3.
- Designed and implemented a multi-layered VPC - based AWS network security solution:
- Used Internet Gateway, NAT Gateway, and VPC endpoints for VPC layer’s security controls.
- Used NACLs (Network Access Control List), and Rout Tables for Subnet layer’s security controls.
- Used SGs (Security Group) for EC2 instance / ENI (Elastic Network Interface) layer’s security controls.
- Designed and implemented Cognito IAM solution:
- Used Cognito User Pool for authentication to API Gateway through on-prem SAML federating Identity Provider ADFS.
- Used Cognito Identity Pool/STS to map IAM roles to users for authorization to AWS resources.
- To fine-grained control access AWS resources for all IAM principals:
- Used SCPs (Service Control Policies) with AWS Organizations to set permission guardrails.
- Used identity-based policies for the requester’s account and resource-based policies for the resource’s account.
- Designed and implemented data security solution to protect data in transit and at rest:
- Used CloudHSM to manage TLS private keys and certs. Used https to secure data in transit for API and web access.
- Used KMS to store symmetric Customer Master Keys (CMKs) and generate Data Keys to encrypt data at rest.
- Implemented Server-Side Encryption with KMS-managed CMK for S3, DynamoDB, CloudTrail in S3 and EBS (Elastic Block Store).
- Published various type of requests to SNS topics for the corresponding SQS subscriptions for OLTP (On-Line Transaction Processing) and OLAP (On-Line Analytical Processing).
- Used DynamoDB for OLTP and Redshift for OLAP.
- Used CloudFormation to create/update stacks based on template to configure and provision AWS resources.
Environment: Eclipse, Bitbucket/Git, Jira, Maven, CloudFormation, Jenkins, JFrog Artifactory, BMC Release Process Management (BPM)
Confidential
Tech Architect
Responsibilities:
- Proven track record in designing and agile developing component-based SOA solutions for enterprise distributed systems in cloud (AWS/Azure), non-cloud as well as hybrid environments.
- Chief architect for global product line of Digitalization of Vehicle Distribution with seven products.
- Solution architect of cloud and cybersecurity and integration for major global programs: HR (Human Resource), DSC (Data Supplier Chain), Marketing & Sales, Connected Vehicle including Smart Finished Vehicle Delivery, China New Energy Vehicle Data Monitor projects, FordPass, and Autonomous Vehicle.
- Led and guided global interoperability forum to manage the interoperability technology standard and best practices.
- Solution architect for enterprise integration/interoperability and cybersecurity services: IBM DataPower, Microsoft BizTalk, Axway B2Bi and Informatica IICS/CIH.
- Extensive experiences to use OOAD to analyze and design SOA applications. Co-author of SOA pattern for Web Services, Co-author of SaaS (Software as a Service) Usage Guide, and XML Security Gateway Guide.
- Research and POC (Proof of Concept) on emerging technologies: Authored Architecture Strategy of Managed File Transfer, Text analytics, RESTful API, Consumer-facing Identity and Access Management.
Environment: AWS, Kinesis Firehose/Data Streams/Data Analytics, Lambda, S3, DynamoDB, SNS, SQS, TMC/Autonomic, DataPower, SQL Server, Windows, Linux, Java, JavaScript, XML, JSON, Restful Web Services, Microservices, Dynatrace, Jenkins, Kubernetes, JIRA, Maven, GitHub, Rally, Nexus, Spring/Spring Boot/Spring Cloud, Tomcat, Swagger, Qlik Sense Cloud.
