Agyapong Gyamfi

Cloud Security | DevSecOps | AI Infrastructure

Summary

Cloud Security Engine, currently my work sits at the intersection of cloud engineering, DevSecOps, technical support, and cybersecurity: designing secure infrastructure, troubleshooting production issues, hardening access paths, and creating runbooks. Securing cloud infrastructure, identity federation, DevSecOps pipelines, multi-cloud technical support — resolving IAM and role-assumption failures, TLS/certificate binding, and firewall, API-security issues, and incident triage. I build and hardens Terraform-based secure baselines, least-privilege IAM, keyless CI/CD (Federation OIDC, IAM Roles Anywhere, TPM-backed certificates), and centralized detection-and-response, GitHub Actions deployments, logging, and detection-focused security controls. Holds an MS in Cybersecurity, AWS Solutions Architect and AWS Security – Specialty certificates. Extending this foundation into AI/LLM security — securing AI agents, MCP servers, and the cloud infrastructure they run on.

Experience

Cloud DevSecOps Engineer - Security & Infrastructure Consulting @ G&A Nexus Inc

02/2025 - 04/2026"Raleigh, NC

  • Keyless CI/CD Federation: Eliminated long-lived AWS keys by implementing OIDC federation, IAM Roles Anywhere, and TPM-backed certificates; hardened GitHub Actions environments, secrets handling, and pre-deployment scanning.
  • Multi-Account Architecture: Designed multi-account AWS structure with Organizations, an OIDC federation landing account, and controlled role chaining — spanning landing zones, networking, IAM strategy, disaster recovery, cost, and security architecture.
  • Identity & Access: Implemented least-privilege access with AWS Identity Center, IAM roles, permission boundaries, and trust policies; enforced controlled cross-account role assumption and removed long-lived IAM users where feasible.
  • Infrastructure as Code: Built VPC, EC2, RDS, and IAM requirements into Terraform and CloudFormation modules promoted as the team standard for repeatable, drift-free delivery.
  • Cost Optimization: Drove cost optimization by decommissioning redeployable EC2 instances, purchasing savings plans, leveraging autoscaling, and right-sizing instances.
  • Governance & Compliance: Established multi-account governance with AWS Organizations, Control Tower concepts, and AWS Config conformance packs for centralized policy enforcement and continuous configuration monitoring.
  • Network & Workload Security: Hardened VPC, EC2, and RDS workloads with subnetting, VPC Flow Logs, encrypted EBS/RDS volumes, and KMS-managed keys aligned to workload sensitivity.
  • Policy-as-Code Pipelines: Engineered CI/CD with Git, CodePipeline, and CodeBuild; integrated infrastructure scanning to catch misconfigurations before deployment and reduce drift.
  • Security Testing: Performed authorized API and application security testing with Burp Suite, OWASP ZAP, and Postman; documented findings, severity, and remediation guidance.

Cloud Technical Support Engineer | Cloud Infrastructure, Data Protection & Resilience @ NetApp Inc

04/2026 - Present"Morrisville, NC

  • Multi-Cloud Engineering & Triage: Own technical resolution for enterprise customers running Cloud Volumes ONTAP and cloud-connected data services across AWS, Azure, and GCP environments. Analyzing HAR files and packet captures for structured root-cause analysis. Backup restore, replication repair, failed or corrupted disk recovery, storage availability, ransomware recovery scenarios, and business continuity requirements.
  • Data Protection and Resilience: Resolve production cloud infrastructure issues involving backup failures, replication errors, tiering misconfigurations, disaster recovery setup, data classification, federation, API access, redeployment workflows, and cloud connectivity.
  • Identity & API: Remediate IAM, role-assumption, networking, firewall, certificate, deployment, API, and availability issues affecting hybrid and cloud-native storage workloads, validate request signing, isolate misconfigurations.
  • Security Hardening: Validate secure connectivity, SSL/TLS certificate binding, cross-region replication, immutable backup concepts, disaster recovery readiness, and cloud storage resilience patterns. Guides SSL/TLS certificate binding for VMs, Docker/Podman containers, and cloud volumes; reviews CVE advisories to determine mitigation; resolves firewall-rule and permission issues blocking API calls.
  • Incident Response & Observability: Analyze NetApp Console, System Manager, API responses, logs, HAR files, packet captures, backup status, replication status, and cloud telemetry to isolate root cause and restore service.
  • Resilience & Recovery: Execute data protection and recovery workflows involving backup restore, replication repair, failed or corrupted disk recovery, storage availability, ransomware recovery scenarios, and business continuity requirements.
  • Knowledge Engineering: Partner with customers, engineering teams, and internal support organizations to stabilize high-impact incidents, document repeatable solutions, and improve operational knowledge around cloud data protection and secure infrastructure.

Technical Support Engineer @ Perigen Inc

04/2023 - 02/2025"Cary, NC

  • Regulated Operations: Owned technical resolution for FDA-regulated healthcare applications across Windows, Linux, Microsoft SQL Server, networking, and cloud-connected environments, including Azure-integrated components, investigated SQL, Python, and HL7-related data flow issues across healthcare application workflows, collaborating with engineering, implementation, and client IT teams to remediate defects and configuration gaps.
  • Incident Response: Restored production service across application, database, server, network, certificate, and integration layers using structured triage, log analysis, and root-cause investigation; and documented remediation.
  • Hardening & Network Analysis: Strengthened production security posture through SSL/TLS certificate binding, server hardening, vulnerable cipher/protocol remediation, firewall-rule validation, and access-related configuration reviews. and HL7 integration issues.
  • Automation: Built scripts and automation for log analysis, alerting, monitoring, and repeat-issue detection to improve operational visibility and reduce recurring incidents.
  • Network Troubleshooting: Analyzed network traffic with Wireshark to isolate connectivity, latency, firewall, and protocol-level issues affecting clinical workflows and HL7 integrations. Validated API behavior using Postman, inspecting authentication flows, request/response patterns, endpoint behavior, and failure conditions to isolate application and integration issues.
  • Knowledge Base and Runbooks- Authored technical documentation, resolution notes, and operational knowledge artifacts to improve team consistency, escalation quality, and speed of future incident response.

Technical Support - Lead @ Infosys Limited

12/2021 - 04/2023"Raleigh, NC

  • Leadership: Led incident response and triage for three enterprise applications, mentored team members in structured triage, production monitoring, documentation discipline, and escalation communication.
  • Hybrid Networking & Automation: Diagnosed cloud / on-prem hybrid networking issues across VPC connectivity and routing; built automation for log analysis and batch monitoring; standardized RCA templates in ServiceNow.
  • Legacy systems support: Supported hybrid application environments involving mainframe workflows, DB2, JCL, COBOL, batch processing, cloud-connected systems, and enterprise service-management processes.

Production Process Technician @ Procter & Gamble

12/2019 - 12/2021"Brown Summit, NC

  • Oversaw SCADA/PLC-related operational configurations and resolved system faults that impacted manufacturing workflows.
  • Ensured compliance-driven execution within regulated environments (FDA/cGMP context).

Program Manager | Web Developer | System Administrator @ Sem Fronteiras

11/2010 - 12/2019"Uxbridge, UK

  • Developed and maintained IT infrastructure including LAN networks, Linux/Windows servers, workstations, patching, and application deployments.
  • Created web applications and databases (HTML/CSS/JavaScript/PHP/SQL) and supported operational reporting and stakeholder coordination.
  • Managed logistics and reporting for healthcare outreach programs, fostering strong execution discipline and operational ownership.

Skills

Cloud & Security Architecture

  • AWS
  • Azure
  • IAM / Identity
  • Secure configuration
  • TLS / Certificate management
  • VPC / VNet patterns
  • Segmentation
  • Least-privilege policies
  • SSO / OAuth2
  • Azure AD / Entra

DevSecOps & IaC

  • Terraform
  • CloudFormation
  • Git
  • CodePipeline
  • CodeBuild
  • CI/CD automation
  • Config drift reduction
  • AWS Config
  • Organizations / Control Tower

AWS Services

  • Identity Center
  • EC2
  • RDS
  • S3
  • VPC
  • Kinesis Firehose
  • Glue
  • Athena
  • CloudFormation
  • AWS Config

Security & Testing Tools

  • Burp Suite
  • OWASP ZAP
  • Postman
  • Wireshark
  • SSLyze
  • Penetration testing concepts
  • NIST CSF
  • MITRE ATT&CK

Incident Response & Ops

  • Structured triage
  • Root cause analysis
  • Bridge calls
  • Escalation management
  • Playbooks & runbooks
  • Splunk
  • Observability / Logging

Scripting & Data

  • Python
  • Java
  • SQL
  • JavaScript
  • Shell scripting
  • HL7 concepts
  • Microsoft SQL Server

ITSM & Collaboration

  • Jira
  • ServiceNow
  • Dynamics 365
  • ClickUp
  • KB authoring

Education

Master of Science - Cybersecurity

North Carolina A&T State University"-"Greensboro, NC

Bachelor of Science - Information Technology

North Carolina A&T State University"-"Greensboro, NC

Certifications

AWS Certified Security – Specialty

AWS Certified Solutions Architect – Associate

DevOps on AWS (Professional Certificate)

In Progress: Certified Cloud Security Professional (CCSP – ISC2)

Infosys Certified Mainframe JCL Programmer

Infosys Certified COBOL-DB2 Programmer