Cloud Infrastructure Engineer · Secure, Automated, Cost-Optimized Infrastructure
I design zero-trust, cloud-native systems, engineering security in from the start and automating away cost and toil. I gravitate to the hard, ambiguous problems with no standard playbook, the ones where traditional approaches fall short and a working solution has to be built from first principles rather than looked up.
# provisioned 2020 · cloud · cybersecurity · devops engineer: name: "Sam Howard" clearance: "active, details on request" domains: [cloud, cybersecurity, devops] aws: [EKS, ECS, Lambda, S3, DynamoDB, CloudFront, Route 53, API Gateway, IAM, VPC, KMS, SES] gcp: [GKE, Cloud Functions, GCS, Cloud KMS, IAM] zero_trust: [SPIFFE/SPIRE, mTLS, RMF] automation: [Python, GitLab CI/CD, MLOps] static_secrets: null # by design
A SPIFFE/SPIRE zero-trust control plane on Amazon EKS, built to emulate a restricted U.S. Army "Private Only" cloud, replacing long-lived static credentials with short-lived, auto-rotating identity.
A custom photography platform and automated gallery-delivery system that replaced costly SaaS subscriptions and insecure USB handoffs, from a headless Raspberry Pi at the edge to a fully serverless AWS backend.
The site itself is a working case study: a fully serverless, infrastructure-as-code deployment where every resource is declared in Terraform and every commit ships itself to production through a GitLab pipeline.
terraform apply.Open to lead cloud engineering, DevOps, and zero-trust architecture roles, cleared, commercial, or anywhere in between.