My Work
Production engagements across FinTech, capital markets, insurance & non-profit — plus platform initiatives and personal projects
Live production work — infrastructure, DevSecOps & FinOps across multiple industries
- Standardised AWS infrastructure through reusable Terraform modules & Terragrunt with org-wide tagging and cost-allocation metadata built into provisioning
- Automated resource tagging at scale using Python & AWS APIs for consistent ownership, application, environment & client attribution
- Built an application-level FinOps framework using AWS Cost Categories with rule-based cost pillars for transparent spend visibility
- Eliminated cloud waste across unused, stale & over-provisioned workloads; implemented Savings Plans and Reserved Instances
- Migrated a production WordPress application from WP Admin hosting to AWS EC2 with VPC, Security Groups, ALB, WAF, SSL/TLS & Nginx
- Provisioned AWS infrastructure for a React, Node.js, MySQL & Redis application across dev and deployment environments
- Implemented Jenkins CI/CD with SonarQube, Trivy & Gitleaks security gates for repeatable, validated deployments
- Hardened public-facing applications with ALB, WAF, Security Groups, SSL/TLS & Nginx; added Prometheus/Grafana and CloudWatch endpoint monitoring
- Provisioned secure AWS infrastructure for a React + Python financial application, with PostgreSQL on Amazon RDS and a scalable S3 + CloudFront frontend
- Migrated production PostgreSQL from an EC2-hosted instance to Amazon RDS with zero downtime
- Automated deployments with Jenkins & Docker for containerized backend services on EC2
- Implemented cron-based data ingestion workflows to fetch, validate & sync external datasets, with Prometheus/Grafana/CloudWatch monitoring
- Architected multi-server AWS environments for Java, Python, React & WordPress applications with containerized workloads
- Configured S3-based hosting, ALB, WAF, SSL/TLS and network-level security controls for isolated, production-ready deployments
- Automated CI/CD, backups & observability with Jenkins, Docker, Prometheus, Grafana, Uptime Kuma & CloudWatch
- Re-architected a monolithic investment advisory application into a multi-tier AWS architecture for scalability & availability
- Implemented private-subnet networking & IAM permission boundaries to strengthen infrastructure security
- Automated deployments with Jenkins & GitLab CI/CD
- Responded to a production code-injection incident — isolated the affected environment and executed secure recovery procedures
- Implemented Lambda-based automation, GuardDuty threat detection & S3 lifecycle-managed backups
- Strengthened security, operational resilience & infrastructure cost efficiency post-incident
- Designed & provisioned scalable AWS infrastructure with networking, load balancing & security controls for production workloads
- Implemented IAM lifecycle governance and EventBridge-based EC2 scheduling for operational efficiency
- Built Windows EC2 recovery workflows to strengthen infrastructure resilience
Foundational infrastructure, DevOps platform engineering & FinOps practices built from the ground up
- Built a 7-node Proxmox VE cluster on existing office hardware — a secure hybrid-cloud platform for internal development, testing & infrastructure operations at zero added cloud spend
- Integrated GajShield firewall for controlled, secure internet-facing application exposure
- Extended hybrid connectivity into the AWS VPC via Site-to-Site VPN
- Architected and self-hosted an enterprise GitLab environment, eliminating dependency on third-party version-control licensing
- Integrated source control with CI/CD, code quality, security scanning & automated deployment workflows
- Built and maintained 15+ Jenkins pipelines spanning dev, UAT, and production environments
- Branch-based GitLab triggers driving zero-downtime, rolling Docker deployments
- M365 SSO on pipeline access, with Python + Jenkins automating weekly SSL expiry reporting
- Rolled out a 4-layer security pipeline — Gitleaks, SonarQube, Trivy & Secrets Manager — across 5+ production applications
- Secrets Manager replaced plaintext .env files; ECR configured to reject CVE-flagged images
- Stage-by-stage MS Teams & email alerts across build, scan, violation & deploy phases
- Prometheus + Grafana dashboards with threshold-based email alerts for CPU, disk & memory
- Uptime Kuma tracking 40+ URLs and SSL certificates, with automated weekly expiry reports
- CloudWatch Logs for developer visibility, plus EventBridge + Lambda server-state notifications
- Established a foundational AWS cost-optimization practice through a granular organisational cost audit
- Built a repeatable framework — resource utilisation, right-sizing, storage optimisation, workload scheduling, Reserved Instances & Savings Plans — later applied across client environments
Hands-on learning — Kubernetes, CI/CD pipelines & AWS automation
Vite + Tailwind CSS SPA with a custom vanilla-JS bilingual (English/Marathi) toggle, schema.org structured data for local SEO, and WhatsApp deep-link inquiries — built and deployed end-to-end as a static site on AWS S3 + CloudFront with GTM analytics.
EKS deployment with VPC, ALB, and Ingress Controller — advanced Kubernetes networking and AWS integration.
React + Node.js + MongoDB three-tier app deployed with Docker on AWS EC2 following multi-tier architecture best practices.
Jenkins pipeline with Docker, SonarQube, Trivy, and Gradle for automated build, security scan, and deployment on EC2.
Shell script using AWS CLI + jq to display EC2, S3, IAM, and RDS resource details — automated cloud visibility tool.
Bash script monitoring CPU, memory, and disk on AWS nodes — proactive detection of resource bottlenecks.
Scheduled Lambda function that removes unattached EC2 snapshots automatically — serverless cloud cost hygiene.