Active U.S. Security Clearance AWS Solutions Architect – Associate

Sam Howard

Cloud Infrastructure Engineer · Huntsville, Alabama

I build cloud infrastructure for environments where the security requirements aren’t negotiable. DoD networks, federal ATO boundaries, regulated commercial workloads. Lately that’s meant cutting AWS bills and getting rid of long-lived credentials.

terraform/engineer.tfread-only
# samhoward.cloud · provisioned 2020 resource "engineer" "sam_howard" { name = "Sam Howard" clearance = "active, details on request" domains = ["cloud", "cybersecurity", "devops"] aws = ["EKS", "ECS", "Lambda", "S3", "DynamoDB", "CloudFront", "IAM"] gcp = ["GKE", "Cloud Functions", "GCS"] zero_trust = ["SPIFFE/SPIRE", "mTLS", "RMF"] automation = ["Python", "Terraform"] certs = ["SAA-C03", "PenTest+", "CySA+", "Security+"] }
$156K
Annual AWS savings
~130
DoD sites monitored
10
Analysts led
5+
Years in IT, cyber & cloud
2020 – present

Experience

~
Cloud Engineer II
Deloitte
Apr 2024 — Present
~
Cyber Analyst I → C5ISR CSSP Technical LeadPromoted in 11 months
COLSA
Mar 2022 — Apr 2024
~
Help Desk Analyst → Lead Chat AnalystPromoted in 6 months
Hexagon
Oct 2020 — Feb 2022
Three builds

Projects

Zero-Trust Workload Identity for Federal Cloud-Native Environments

Georgia Tech Practicum

A SPIFFE/SPIRE control plane on Amazon EKS, built to emulate a restricted U.S. Army "Private Only" cloud. It replaces long-lived static credentials with short-lived identity that rotates itself.

IA-2IA-5SC-8AC-6AU-2 NIST 800-207CISA ZTMMOMB M-22-09
Interactive: watch a workload earn its identity
SPIRE Serveridentity authority Kubernetes APItoken validation EC2 node · spire-agentWorkload API socket workload podzero secrets on disk service-bpeer workload
// idle, click Request SVID to run the attestation flow
spiffe://demo.internal/ns/prod/sa/api
serial -TTL 4:00:00auto-rotate: armed
Sped up about 720×. The real TTL is four hours.

Event-Driven Hybrid-Cloud Media Pipeline

emilynovellagalleries.com, in production

A photography platform and automated gallery-delivery system that replaced a stack of SaaS subscriptions and the habit of handing clients photos on a USB stick.

S3LambdaECSDynamoDBCloudFrontRoute 53GlacierPolly
Interactive: publish a gallery, then unlock it like a client
USB Raspberry Pi appliancesystemd · Polly voice uploads (S3)_uploads/*.zip trigger index_builder λunzip · thumbs · build DynamoDBhash only SES → client emailraw key, sent once CloudFront edgesigned-cookie gate auth λhash & compare client browserinbox → key → cookies
// idle, click Publish gallery to run the pipeline
🔊
🔒 403
🔒 403
🔒 403
The hash check is real. This page runs SHA-256 on what you type and compares digests, same as the auth Lambda. Wrong key, no cookie.

This Website: Serverless Portfolio on AWS

You're looking at it. View the source on GitLab ↗

Every resource here is declared in Terraform and every push to main deploys itself.

TerraformGitLab CI/CD S3 (private + OAC)CloudFrontACMRoute 53
Day to day

Skills

Cloud & Infrastructure

AWS · EKSECSLambdaS3DynamoDBRoute 53CloudFrontIAMVPCKMSSystems ManagerGCPAzure

Security & Compliance

Zero-Trust ArchitectureSPIFFE/SPIREmTLSNIST 800-53 / 800-207RMFCISA ZTMMACASTenableKibanaAzure Sentinel

Containers & Orchestration

KubernetesDockerHelmAmazon EKS / ECS

DevOps, Data & Automation

TerraformGitLab CI/CDPythonBashLinuxETL pipelinesMLOpsSnowflakeDatabricksTableau
Degrees and certifications

Education

M.S. Cybersecurity in Public Policy

Georgia Institute of Technology · Aug 2023 – Dec 2026

B.S. Information Technology, Cum Laude

Liberty University

Certifications

  • AWS Certified Solutions Architect – Associate
  • CompTIA Security+
  • CompTIA Cybersecurity Analyst (CySA+)
  • CompTIA PenTest+
Contact

Contact

Open to lead cloud engineering, DevOps, and zero-trust architecture roles. Cleared or commercial.

Straight to my inbox. I usually reply within a day or two.