Architected and built a full AI agent operations cockpit (the 'IT Operations Agent') — a metagit-based atlas, orchestration spine, and Taskfile-driven verb layer — giving both human operators and autonomous agents a shared, auditable interface into ~90 repos across ~40 AWS accounts.
Designed a dual-mode agent access model (Operator vs. Sentinel) with a deterministic capability-probing preflight check, ensuring autonomous AI agents downgrade any risky write to a reviewable GitLab MR or queued approval rather than acting directly — closing the human-in-the-loop gap for unattended AI operations.
Built an org-wide, read-only AWS query layer using Steampipe/Powerpipe fronted by a per-account read only role StackSet, letting a single SQL query fan out across the entire AWS organization for compliance benchmarking and fleet audits without granting any data-plane access (secrets, KMS, S3 object content excluded by policy).
Implemented a GitOps-driven account lifecycle system (workload onboarding, permission-set authoring/assignment, patch policies, cross-account IAM, budget management) — each a discrete, agent- and human-usable skill/task that lands as a Terraform MR rather than a manual console change.
Established an agent isolation doctrine for concurrent human/AI collaboration on the same GitLab project — dedicated agent-owned clones, one persistent per-day working branch, MR-on-signal (not auto-merge) — eliminating the recurring merge-conflict class caused by agents editing a human's live working tree.
Stood up a CI/CD validation gate (secret scanning, lint, skill-schema, atlas, script index, task-naming convention checks) enforced on every merge request, catching both human and AI agent contributions before they land on main.
Delegated infrastructure-as-code implementation work to Claude Code subagents with automatic routing based on target-repo agent-readiness (AGENTS.md/CLAUDE.md, local skills, MCP servers), improving delegated MR success rates over generic subagents lacking repo-local context.
Used AI agents to run and document real cost/security audits — including an org-wide Fargate platform retirement exposure sweep and an AWS Savings Plan renewal assessment — publishing findings through automated docs pipelines (MkDocs + GitLab Pages).
Built a knowledge ingestion and institutional-knowledge pipeline pulling Confluence spaces into a git-tracked, searchable knowledge base to ground AI agent responses in authoritative internal documentation rather than hallucinated context.
Authored and maintain 30+ reusable operational skills (playbooks) for AI agents covering AWS account governance, Terraform authoring conventions, GitLab MR workflows, secrets handling (SecretZero), and DevOps task automation — turning tribal knowledge into executable, versioned procedure.
Extended cross-account IAM automation with scoped, least-privilege assume-role patterns (explicit actions/ARNs, never wildcard) reused across DNS sync, backup, and audit use cases via a shared, locally-patched Terraform module.
Introduced a compliance risk-tiering model (low/medium/high/critical) governing which AI-agent actions can proceed autonomously vs. require explicit human approval, formalizing safe autonomy boundaries for infrastructure automation.
Designed and implemented a multi-account AWS environment using AWS Control Tower and Organizations to support the organization's global cloud strategy.
Implemented guardrails and security baselines to ensure compliance with industry standards and best practices.
Automated account provisioning and management using Infrastructure as Code (IaC) principles.
Collaborated with cross-functional teams to ensure seamless integration of cloud services with existing on-premises infrastructure.
Built SES email sending solution for the organization to support various business units' email needs.
Provided training and documentation to internal teams on AWS best practices and governance.
Authored terraform modules and shared GitLab CICD component libraries to support the organization's cloud infrastructure as code strategy.
Developed GitOps approach for managing AWS account access and permissions using AWS SSO and IAM Identity Center.
Developed several Python scripts to generate AWS documentation for internal teams.
Implemented organizational logging and monitoring using AWS CloudTrail, Config, and CloudWatch to ensure visibility and compliance across all accounts.
Created terraform provisioning process for various team's AWS workloads that automated the GitLab integrated CICD pipelines to deploy and manage resources in a consistent and repeatable manner.
Employed AI to assist in the generation of terraform code and documentation to speed up the delivery of infrastructure as code solutions.
Deployed FortiGate firewalls in AWS using terraform for the organization's secure network architecture and SDWAN initiative.
Technical support for deployed EKS cluster issues and workloads.
Implemented AWS Backup and DR strategies for critical workloads in the AWS environment.
Commvault backup implementation and deployment in AWS using terraform to support the organization's data protection strategy for critical workloads.