AWS · Terraform · CI/CD

Cloud & DevOpsEngineer

My background includes system and network engineering, security operations, and serverless AWS projects.

Projects documented
2
Infrastructure roles
2
Certifications
14

Selected work

Cloud and infrastructure projects.

01 / Live

Cloud Resume Challenge

16-step cloud project · serverless AWS · multi-environment delivery

Challenge briefThe Cloud Resume Challenge is a 16-step project specification: earn a cloud certification; publish a styled HTML resume on S3 with HTTPS and custom DNS; add a JavaScript visitor counter backed by DynamoDB, API Gateway, Lambda, and Python; test the code; define the infrastructure as code; use source control and CI/CD; then document the work in a blog post. I used that specification as the baseline and extended it into separate test and production environments.

Route 53
CloudFront
Private S3
API Gateway
Lambda
DynamoDB

Implementation

  • Built the Next.js and TypeScript static frontend and Python serverless backend across two AWS accounts; Terraform provisions approximately 40 resources per environment.
  • Built a Python Lambda and DynamoDB visitor counter behind API Gateway, using atomic updates and unit tests with pytest and moto.
  • Reused one Terraform codebase across test and production workspaces in separate AWS accounts, with state managed in HCP Terraform.
  • Created GitLab pipelines using OIDC and short-lived AWS credentials for unit tests, environment plans and applies, frontend deployment, browser smoke tests, and test teardown.

Reliability & security

  • GitLab jobs assume AWS roles through OIDC, so the pipeline does not store long-lived AWS access keys.
  • CloudWatch alarms route through SNS and a notifier Lambda to Slack; the webhook is stored in SSM Parameter Store.
  • CloudFront Origin Access Control keeps the S3 bucket private, while Terraform prevent_destroy rules protect the CI identity resources.
Core CRC build liveTest + production environmentsUnit + Playwright testsFinal blog post pending
  • AWS
  • Terraform
  • HCP Terraform
  • GitLab CI
  • Next.js
  • TypeScript
  • Python
  • Lambda
  • DynamoDB
  • CloudWatch

02 / Case study

Highly Available AWS Web Infrastructure

Multi-AZ application architecture

ProblemDesign a multi-tier AWS environment that keeps the application tier replaceable and distributes traffic across availability zones.

Route 53
ALB
Auto Scaling
EC2
Private subnets
RDS

Implementation

  • Designed public and private subnets, route tables, and security boundaries across multiple availability zones.
  • Placed Linux and Windows workloads behind an Application Load Balancer and Auto Scaling Group.
  • Automated instance configuration with user data and connected the application tier to managed RDS.

Reliability & security

  • Applied network segmentation and least-privilege traffic paths between tiers.
  • Used CloudWatch health and performance signals to observe the environment.
  • Documented the RDS replication constraint encountered under the lab IAM policy and the production improvement path.
  • VPC
  • EC2
  • ALB
  • Auto Scaling
  • RDS
  • CloudWatch
  • IAM

Experience & education

System, network, and security experience.

Sep 2025 — Feb 2026

Zectech Pte Ltd · Singapore

System and Network Engineer Intern

Troubleshot infrastructure and connectivity across 20–30 client environments.

  • Investigated network, endpoint, and performance issues using Linux command-line tools and log analysis.
  • Deployed Layer 2/3 switches, wireless access points, endpoints, and AWS and DigitalOcean workloads.
  • Configured OpenVPN, firewall policies, NAT, and port forwarding, including hybrid AWS-to-on-premises connectivity.
  • Maintained network diagrams, configuration backups, asset records, and incident documentation.
Sep 2025 — Feb 2026

AGB Communication Co., Ltd · Remote

Security System Engineer (Part-time)

Assessed client infrastructure and supported remediation of security findings.

  • Identified multiple low- and medium-severity vulnerabilities across client environments.
  • Investigated logs and anomalies in Wazuh SIEM to support incident detection, triage, and response.
  • Reviewed segmentation, firewall policies, and access controls; worked with engineers to remediate findings without service disruption.
  • Produced reports with risk analysis, supporting evidence, and prioritized remediation recommendations.
2023 — 2026

Singapore Polytechnic · GPA 3.87 / 4.0

Diploma in Computer Engineering

  • Cloud Foundations
  • Network & Firewall Technologies
  • Enterprise Networking
  • Cybersecurity Operations
  • Network Forensics & Analysis

Tools & capabilities

Technologies used in my work and projects.

AWS Cloud Services

  • EC2
  • VPC
  • IAM
  • Lambda
  • API Gateway
  • DynamoDB
  • RDS
  • CloudFront
  • Route 53
  • SNS
  • SSM

Cloud & Data Platforms

  • DigitalOcean
  • Elastic Cloud
  • MongoDB

Infrastructure as Code

  • Terraform
  • HCP Terraform
  • AWS Organizations
  • org-formation

CI/CD & Testing

  • GitLab CI/CD
  • OIDC
  • Git
  • pytest
  • moto
  • Playwright

Systems Administration

  • Linux
  • Windows Server
  • Active Directory

Security & Monitoring

  • Wazuh SIEM
  • CloudWatch
  • Log analysis
  • Alert triage
  • Vulnerability assessment
  • Access control
  • Network segmentation

Networking

  • Layer 2/3 switching
  • Routing
  • VLANs
  • TCP/IP
  • DNS
  • DHCP
  • OpenVPN
  • IPsec/SSL VPNs
  • NAT
  • Port forwarding
  • Firewall policies

Credentials

Certifications and security recognition.

Cloud & infrastructure

  • AWS Solutions Architect Associate (SAA-C03)AWS
  • HashiCorp Terraform AssociateHashiCorp
  • AWS Cloud PractitionerAWS
  • Azure Fundamentals (AZ-900)Microsoft
  • Oracle Cloud Infrastructure FoundationsOracle
  • Oracle Cloud AI FoundationsOracle

Networking

  • Cisco CCNACisco
  • Fortinet Certified AssociateFortinet
  • Ruijie Certified Network AssociateRuijie

Security

  • Certified Ethical Hacker (CEH)EC-Council
  • eCPPT — Network & Application SecurityINE
  • eJPT — Network SecurityINE
  • TryHackMe SOC Analyst L1 (SAL1)TryHackMe
  • TryHackMe PT1TryHackMe

Recognition

2024

Lenovo Responsible Disclosure — Hall of Fame

Reported a security vulnerability in Lenovo web infrastructure through responsible disclosure.

2024

Cisco Security Hall of Fame

Reported a security vulnerability in Cisco web infrastructure through responsible disclosure.

2025

Cisco NetAcad Riders — Silver Award

Recognized for technical performance in Cisco networking challenges.

Contact

Open to cloud and DevOps roles.

I am interested in cloud infrastructure, platform engineering, DevOps, and SRE opportunities where operational thinking matters.

haw.connect@gmail.comSingaporeDownload résumé