Skip to main content

Portfolio

Three platform systems the rest of the org now builds on — a governed AI control plane, a 70k-resource migration run without losing a day of delivery, and a zero-trust bootstrap that turns acquisitions into onboarded teams.

The work clusters around the platforms an organization depends on: a governed AI control plane, capital-efficient infrastructure migration at scale, and secure cloud bootstrapping for complex, acquisitive organizations. Each artifact is here because it shows an operating decision and a business outcome — reduced risk, preserved velocity, compressed onboarding — not because it fills space.

Career timeline

3 roles

Impact case studies

AI Control Plane and Agentic Operations

Built the enterprise control plane that exposes internal tooling to LLM-driven workflows through a governed gateway and model-context boundary — so the organization could adopt agentic AI without adopting its risks.

Business impact: Created the secure execution layer behind internal agentic apps, OKR-linked leadership visibility, and CMS narrative automation — AI adoption as governed platform capability, not scattered experiments.

MintMCPLLM GatewayAWS BedrockEKSPython

Key decisions

  • Gateway Evaluation & Implementation: POC'd Bifrost, TrueFoundry, and MintMCP, ultimately implementing MintMCP as the core Model Context Protocol gateway to standardize tool execution.
  • Agentic Workflows: Enabled 'Penny,' a financial literacy narrative agent for the CMS, and a Leadership App that dynamically wires bottom-up team metrics and Jira initiatives to top-level executive OKRs.
  • Security Boundary: The LLM Gateway ensures all agentic actions are authenticated, rate-limited, and audited before hitting the MCP tool registry, preventing prompt-injection blast radius expansion.

N-Tier

AI Control Plane architecture deployed in production

2+

internal agentic apps powered by the platform

OKR-linked

real-time executive initiative visibility

IaC Migration at Scale and AI Remediation

Re-platformed the entire infrastructure estate from Terraform Cloud to Scalr while preserving developer velocity across deeply segmented environments — a 70k-resource move most orgs would freeze delivery for.

Business impact: Reduced vendor lock-in and cost, cut toil, and turned broken-workspace recovery into an automation problem instead of an operations fire drill — all without asking 700+ services to slow down.

ScalrTerraformGitHub ActionsPythonAWS

Key decisions

  • Topology Mapping: Architected the migration to support private modules, community forks, and local modules across highly segregated environments.
  • AI-Powered Self-Healing: Instead of manually fixing state locks or drift post-migration, built an automation loop that detects broken workspaces, analyzes the Terraform plan drift, and suggests or auto-applies the remediation.
  • Business Value: Eliminated the 'IaC toil' bottleneck, saving the platform team hundreds of hours per quarter while securing a more cost-effective enterprise contract.

70k+

IaC resources migrated to Scalr

AI-driven

automated drift remediation & workspace self-healing

700+

services with uninterrupted deployment velocity

Secure Cloud Bootstrap for M&A

Engineered the baseline for bringing newly acquired cloud footprints under zero-trust and compliance controls immediately — turning an acquisition from a security liability into an onboarded team.

Business impact: Compressed acquisition onboarding time by making private connectivity, logging, policy, and shared platform access the default from day one — a direct enabler of the company's M&A strategy.

AWS Transit GatewayAWS PrivateLinkCloudflare WAFCloudflare ZTNATerraform

Key decisions

  • Zero-Trust by Default: Enforced E2E privacy for all data movement. Partnered with the Data Infra team to secure Fivetran tunnels directly into AWS managed storage without traversing the public internet.
  • Edge Security: Partnered with the Security team to standardize Cloudflare configurations, wrapping all new acquired web properties in enterprise WAF and ZTNA policies.
  • Cross-Account Networking: Leveraged AWS Transit Gateway and PrivateLink to ensure acquired resources could securely access centralized platform tools (logging, Cortex secrets, ArgoCD) instantly.

Zero-Trust

E2E enforcement for all acquired workloads

Automated

compliance baseline provisioned on acquisition

E2E Private

Fivetran tunnels secured into AWS without public internet

You've seen the work.

Next: How I think