Active U.S. Security Clearance

Sam Howard

Cloud Infrastructure Engineer · Secure, Automated, Cost-Optimized Infrastructure

I design zero-trust, cloud-native systems, engineering security in from the start and automating away cost and toil. I gravitate to the hard, ambiguous problems with no standard playbook, the ones where traditional approaches fall short and a working solution has to be built from first principles rather than looked up.

engineer.yaml
# provisioned 2020 · cloud · cybersecurity · devops
engineer:
  name: "Sam Howard"
  clearance: "active, details on request"
  domains: [cloud, cybersecurity, devops]
  aws: [EKS, ECS, Lambda, S3, DynamoDB, CloudFront,
        Route 53, API Gateway, IAM, VPC, KMS, SES]
  gcp: [GKE, Cloud Functions, GCS, Cloud KMS, IAM]
  zero_trust: [SPIFFE/SPIRE, mTLS, RMF]
  automation: [Python, GitLab CI/CD, MLOps]
  static_secrets: null  # by design
$156K
Annual AWS cost savings engineered
~130
DoD installations safeguarded
10
Analysts led as CSSP Technical Lead
5+
Years across IT, cyber & cloud
Professional experience

From cyber defense to cloud engineering

Apr 2024 - Present
Cloud Engineer II
Deloitte
  • Cloud architecture: Cut cloud spend ~87% (~$156K/year) through cost-governance automation: right-sizing, scheduling, reservations, and lifecycle policies.
  • DevOps & integrations: Engineered and debugged containerized pipelines across EKS, Lambda, S3, and AWS Systems Manager, driving CI/CD through GitLab.
  • ML & data pipelines: Containerized and operationalized ML models as production workloads across AWS (EKS), GCP, and Snowflake, adapting each model to run reliably in every environment.
  • Software engineering: Built Python monitoring tooling for a government client that restored web-traffic attribution previously obscured by VPN usage, delivered as both GUI and headless production builds.
  • System modernization: Drove the migration and decommissioning of Jira, Splunk, and Keycloak into managed environments as the effort's primary technical resource.
Mar 2022 - Apr 2024
Cyber Analyst I C5ISR CSSP Technical LeadPromoted in 11 months
COLSA
  • Led a team of 10 analysts monitoring network and cloud traffic across ~130 DoD subscriber sites (CONUS and OCONUS) to identify and mitigate cyber threats.
  • Coordinated internal and external teams to bring full CSSP capabilities to subscriber sites, and directly helped them pass Command Cyber Readiness Inspections (CCRIs).
  • Provided technical guidance and training to junior analysts; administered JQR end-of-training certification exams.
  • Conducted network traffic, security log, and ACAS vulnerability analysis; delivered monthly security posture reports in Tableau.
Oct 2020 - Feb 2022
Help Desk Analyst Lead Chat AnalystPromoted in 6 months
Hexagon
  • Promoted within six months from phone support to running online-chat operations solo; trained new analysts and exceeded response-time, quality, and retention targets.
Technical projects

Built end to end, hardened by design

Zero-Trust Workload Identity for Federal Cloud-Native Environments

Georgia Tech Practicum

A SPIFFE/SPIRE zero-trust control plane on Amazon EKS, built to emulate a restricted U.S. Army "Private Only" cloud, replacing long-lived static credentials with short-lived, auto-rotating identity.

IA-2IA-5SC-8AC-6AU-2 NIST 800-207CISA ZTMMOMB M-22-09
Interactive: watch a workload earn its identity
SPIRE Serveridentity authority Kubernetes APItoken validation EC2 node · spire-agentWorkload API socket workload podzero secrets on disk service-bpeer workload
// idle, click Request SVID to run the attestation flow
spiffe://demo.internal/ns/prod/sa/api
serial -TTL 4:00:00auto-rotate: armed
Accelerated ≈720× for demo (real TTL: 4 hours). No static secrets were used, that's the point.

Event-Driven Hybrid-Cloud Media Pipeline

emilynovellagalleries.com, in production

A custom photography platform and automated gallery-delivery system that replaced costly SaaS subscriptions and insecure USB handoffs, from a headless Raspberry Pi at the edge to a fully serverless AWS backend.

S3LambdaECSDynamoDBCloudFrontRoute 53GlacierPolly
Interactive: publish a gallery, then unlock it like a client
USB Raspberry Pi appliancesystemd · Polly voice uploads (S3)_uploads/*.zip trigger index_builder λunzip · thumbs · build DynamoDBhash only SES → client emailraw key, sent once CloudFront edgesigned-cookie gate auth λhash & compare client browserinbox → key → cookies
// idle, click Publish gallery to run the pipeline
🔊
🔒 403
🔒 403
🔒 403
The hash check is real, this page runs SHA-256 on your input and compares digests, exactly like the auth Lambda. Wrong key, no cookie.

This Website: Serverless Portfolio on AWS

You're looking at it, view the source on GitLab ↗

The site itself is a working case study: a fully serverless, infrastructure-as-code deployment where every resource is declared in Terraform and every commit ships itself to production through a GitLab pipeline.

TerraformGitLab CI/CD S3 (private + OAC)CloudFrontACMRoute 53API GatewayLambdaDynamoDB
Technical skills

The stack, in depth

Cloud & Infrastructure

AWS · EKSECSLambdaS3DynamoDBRoute 53CloudFrontIAMVPCKMSSystems ManagerGCPAzure

Security & Compliance

Zero-Trust ArchitectureSPIFFE/SPIREmTLSNIST 800-53 / 800-207RMFCISA ZTMMACASTenableKibanaAzure Sentinel

Containers & Orchestration

KubernetesDockerHelmAmazon EKS / ECS

DevOps, Data & Automation

GitLab CI/CDPythonBashLinuxETL pipelinesMLOpsSnowflakeDatabricksTableau
Education & certifications

Credentialed and current

M.S. Cybersecurity

Georgia Institute of Technology · Aug 2023 - Present

B.S. Information Technology, Cum Laude

Liberty University

Certifications

  • CompTIA PenTest+
  • CompTIA Cybersecurity Analyst (CySA+)
  • CompTIA Security+
  • Microsoft Certified: Azure Fundamentals
Contact

Let's talk about your cloud mission

Open to lead cloud engineering, DevOps, and zero-trust architecture roles, cleared, commercial, or anywhere in between.