Available for new opportunities

Salman
Ansari

AWS DevOps Engineer with 4.25+ years building private EKS clusters, JCasC Jenkins CI/CD systems, layered Terraform IaC, and GitOps pipelines for tier-1 enterprise clients.

4.25+
Years Experience
9
AWS Accounts (TCS)
1-2 Days
Env Delivery Time
50–60%
UAT Cost Savings
Jenkins JCasC Terraform EKS ArgoCD OTelGrafana IRSAKarpenterIstio
Technical Expertise

Core Skills

☁️
Cloud Computing & Architecture
EC2S3 Route 53CloudFront ALB/NLBAWS BedrockSSM
AWS Core Services90%
🏗️
Infrastructure as Code
TerraformCloudFormation TerragruntAWS Lambda Auto ScalingASG
Terraform / CF88%
🐳
Container Orchestration & GitOps
Amazon EKSEKS v1.35 KarpenterIstio (ambient) Helm 3ArgoCD cert-managerESO IRSA
EKS / GitOps85%
⚙️
CI/CD
Jenkins (JCasC) Shared Library AWS CodeBuild GitHub Actions (OIDC) Gitea ArgoCD
Jenkins / CodeBuild87%
🔐
Cloud Networking & Security
VPCTransit Gateway Direct ConnectOpenVPN IRSASecrets Manager ACMWAF
Networking & Security85%
📊
Observability, DB & FinOps
OpenTelemetryGrafana ClickHouseHeadlamp kube-state-metricsFluent Bit CloudWatchRDS PostgreSQL DocumentDBElastiCache RabbitMQTemporal FinOpsBash / Python
Observability / DB80%
Career Timeline

Work Experience

Software Engineer - DevOps
May 2026 – Present
🏢 Lumiq  ·  Noida

Cloud infrastructure, container platform, and CI/CD delivery for Lumiq's flagship enterprise SaaS product — an AI-powered workflow orchestration platform deployed for tier-1 BFSI clients across Dev, UAT, and Prod.

  • Architected and managed JCasC-configured Jenkins CI/CD control plane with a custom Shared Library (standardized application-build and Helm chart-build pipelines) for standardized multi-environment client releases.
  • Engineered private Amazon EKS (v1.35) clusters with Karpenter dynamic provisioning and an Istio ambient-mode service mesh (ztunnel + CNI); private API endpoint, internal ALB over VPN, in-account ECR mirroring, IRSA least-privilege roles, and OpenVPN EC2 gateway.
  • Built layered Terraform & CloudFormation IaC architecture across Dev, UAT, and Prod environments including VPC Peering, Transit Gateway, DocumentDB, ElastiCache Redis, and RDS.
  • Delivered 50–60% UAT infrastructure cost reduction via automated off-hours stop/start routines across compute, database and networking layers, plus a Cost Explorer Lambda publishing daily spend reports.
  • Built a self-hosted OpenTelemetry → ClickHouse → Grafana observability platform across 4 client environments — OTLP + Prometheus receivers dual-exporting to ClickHouse and CloudWatch, kube-state-metrics and kubeletstats collectors for cluster telemetry, and 4 authored Grafana dashboards provisioned via sidecar ConfigMap, with Headlamp K8s UI behind a shared internal ALB (IngressGroup) with ACM TLS.
AWS Cloud Engineer
July 2022 – April 2026
🏢 Tata Consultancy Services (TCS)  ·  Mumbai
  • Provisioned and governed AWS infrastructure across 9 accounts using AWS Organizations, custom subnet routing, and hybrid connectivity (Site-to-Site VPN, Direct Connect, Transit Gateway).
  • Built reusable, modular Terraform IaC templates reducing multi-environment delivery timelines from weeks to 1–2 days.
  • Operationalized Amazon EKS and Amazon ECS microservice container platforms with Auto Scaling Groups to sustain 99.9% High Availability.
  • Spearheaded AWS FinOps cost optimization driving 30–40% infrastructure spend reduction via rightsizing, idle resource cleanup, and Savings Plans.
  • Managed Linux RHEL EC2 workloads with custom Python (boto3) and Bash automation; built CloudWatch alarms and metric filters for proactive observability.
B.Tech Graduate (Information Technology)
2018 – 2022
🎓 PVPP College of Engineering, Mumbai  ·  CGPA: 7.4
  • Bachelor of Technology — completed foundational engineering and computer systems curriculum.
  • Obtained AWS Certified Cloud Practitioner shortly after graduation in 2022.
Featured Work

Key Projects

🚀
End-to-End SaaS Platform Deployment (Greenfield AWS Account → Production)
TerraformCloudFormation Amazon EKSKarpenter IstioAWS CodeBuild IRSAExternal Secrets Transit GatewayOpenTelemetry
⚡
Multi-Tenant CI/CD Control Plane & Private EKS Runtime
Jenkins (JCasC)Shared Library AWS CodeBuildHelm 3 (OCI) Amazon EKSIstio (ambient) GrafanaOpenVPN
🏗️
Production Multi-Tier Serverless & Containerised Infrastructure
CloudFrontS3 API GatewayNLB ECS FargateRDS PostgreSQL SQSLambda DynamoDBTerraform
💰
AWS Cost Optimization & FinOps Automation
S3 LifecycleSpot Instances EventBridgePython ASGCompute Optimizer Savings PlansReserved Instances
Architecture 01 — Multi-Tenant SaaS Platform (Production)

Platform Architecture

Per-Tenant AWS Account — Private EKS SaaS Deployment

Every tenant environment is built from the same ordered Terraform layers, applied into its own AWS account. Application nodes and data services sit in private subnets; the cluster API endpoint is private, and human access arrives only over VPN. Public exposure, where a tenant requires it, is terminated at a WAF-protected ALB.

ACCESS
Corporate Network
On-prem estate
Transit Gateway
+ VPC Peering
OpenVPN / Bastion
Engineer access · SSM
Internal ALB
ACM TLS · VPN-only
PUBLIC EDGE
Internet
Tenant users
AWS WAFv2
IP allowlist · rate limit
Internet-facing ALB
Public subnet
RUNTIME
Private EKS
Private API endpoint
Karpenter
Dynamic capacity
Istio Ambient
ztunnel + CNI
IRSA + ESO
Secrets Manager sync
DATA
DocumentDB
Primary store
RDS PostgreSQL
Temporal engine
ElastiCache
Redis cache
RabbitMQ
StatefulSet · gp3
S3 + KMS
Encrypted objects
DELIVERY
Jenkins (JCasC)
Shared Library
AWS CodeBuild
In-VPC · EKS access
Amazon ECR
OCI charts + images
Helm Release
Per tenant / env
TELEMETRY
OTel Collector
OTLP + Prometheus
ClickHouse
Columnar · TTL
Grafana
Dashboards + Headlamp
CloudWatch
Logs · Flow Logs
SNS
Alarm email
Private-subnet workloads · VPC Flow Logs to CloudWatch · SOC 2 resource tagging
Off-hours EventBridge shutdown across database, compute and gateway layers
Architecture 02 — Serverless & Containerised Multi-Tier

Reference Architecture

Production Multi-Tier Serverless & Containerised Infrastructure
ENTRY POINT
CloudFront
CDN + Edge
STATIC
S3
Static Assets
SYNC API
API Gateway
REST
NLB
Network LB
ECS Fargate
Prod / Spot
RDS
PostgreSQL · Multi-AZ
ASYNC
API Gateway
REST
SQS
Queue
Lambda
Consumer
DynamoDB
NoSQL · Results
Flow 1 — Static (CF → S3)
Flow 2 — Sync API (CF → APIGW → NLB → ECS Fargate → RDS PostgreSQL)
Flow 3 — Async (CF → APIGW → SQS → Lambda → DynamoDB)
Credentials

AWS Certifications

🏅
AWS Certified Solutions Architect – Associate
Amazon Web Services · SAA-C03
2024
☁️
AWS Certified Cloud Practitioner
Amazon Web Services · CLF-C02
2022
Get In Touch

Let's Connect

Open to New Roles
I'm actively looking for AWS Cloud / DevOps Engineering opportunities. Whether it's full-time, contract, or consulting — feel free to reach out.
Currently open to opportunities

Mumbai, India

Open to remote roles worldwide and relocation opportunities.

Send Email ⬇ Download Resume