Agyapong Gyamfi
Cloud Security | DevSecOps | AI Infrastructure
Summary
Cloud Security Engine, currently my work sits at the intersection of cloud engineering, DevSecOps, technical support, and cybersecurity: designing secure infrastructure, troubleshooting production issues, hardening access paths, and creating runbooks. Securing cloud infrastructure, identity federation, DevSecOps pipelines, multi-cloud technical support — resolving IAM and role-assumption failures, TLS/certificate binding, and firewall, API-security issues, and incident triage. I build and hardens Terraform-based secure baselines, least-privilege IAM, keyless CI/CD (Federation OIDC, IAM Roles Anywhere, TPM-backed certificates), and centralized detection-and-response, GitHub Actions deployments, logging, and detection-focused security controls. Holds an MS in Cybersecurity, AWS Solutions Architect and AWS Security – Specialty certificates. Extending this foundation into AI/LLM security — securing AI agents, MCP servers, and the cloud infrastructure they run on.
Experience
Cloud DevSecOps Engineer - Security & Infrastructure Consulting @ G&A Nexus Inc
- Keyless CI/CD Federation: Eliminated long-lived AWS keys by implementing OIDC federation, IAM Roles Anywhere, and TPM-backed certificates; hardened GitHub Actions environments, secrets handling, and pre-deployment scanning.
- Multi-Account Architecture: Designed multi-account AWS structure with Organizations, an OIDC federation landing account, and controlled role chaining — spanning landing zones, networking, IAM strategy, disaster recovery, cost, and security architecture.
- Identity & Access: Implemented least-privilege access with AWS Identity Center, IAM roles, permission boundaries, and trust policies; enforced controlled cross-account role assumption and removed long-lived IAM users where feasible.
- Infrastructure as Code: Built VPC, EC2, RDS, and IAM requirements into Terraform and CloudFormation modules promoted as the team standard for repeatable, drift-free delivery.
- Cost Optimization: Drove cost optimization by decommissioning redeployable EC2 instances, purchasing savings plans, leveraging autoscaling, and right-sizing instances.
- Governance & Compliance: Established multi-account governance with AWS Organizations, Control Tower concepts, and AWS Config conformance packs for centralized policy enforcement and continuous configuration monitoring.
- Network & Workload Security: Hardened VPC, EC2, and RDS workloads with subnetting, VPC Flow Logs, encrypted EBS/RDS volumes, and KMS-managed keys aligned to workload sensitivity.
- Policy-as-Code Pipelines: Engineered CI/CD with Git, CodePipeline, and CodeBuild; integrated infrastructure scanning to catch misconfigurations before deployment and reduce drift.
- Security Testing: Performed authorized API and application security testing with Burp Suite, OWASP ZAP, and Postman; documented findings, severity, and remediation guidance.
Cloud Technical Support Engineer | Cloud Infrastructure, Data Protection & Resilience @ NetApp Inc
- Multi-Cloud Engineering & Triage: Own technical resolution for enterprise customers running Cloud Volumes ONTAP and cloud-connected data services across AWS, Azure, and GCP environments. Analyzing HAR files and packet captures for structured root-cause analysis. Backup restore, replication repair, failed or corrupted disk recovery, storage availability, ransomware recovery scenarios, and business continuity requirements.
- Data Protection and Resilience: Resolve production cloud infrastructure issues involving backup failures, replication errors, tiering misconfigurations, disaster recovery setup, data classification, federation, API access, redeployment workflows, and cloud connectivity.
- Identity & API: Remediate IAM, role-assumption, networking, firewall, certificate, deployment, API, and availability issues affecting hybrid and cloud-native storage workloads, validate request signing, isolate misconfigurations.
- Security Hardening: Validate secure connectivity, SSL/TLS certificate binding, cross-region replication, immutable backup concepts, disaster recovery readiness, and cloud storage resilience patterns. Guides SSL/TLS certificate binding for VMs, Docker/Podman containers, and cloud volumes; reviews CVE advisories to determine mitigation; resolves firewall-rule and permission issues blocking API calls.
- Incident Response & Observability: Analyze NetApp Console, System Manager, API responses, logs, HAR files, packet captures, backup status, replication status, and cloud telemetry to isolate root cause and restore service.
- Resilience & Recovery: Execute data protection and recovery workflows involving backup restore, replication repair, failed or corrupted disk recovery, storage availability, ransomware recovery scenarios, and business continuity requirements.
- Knowledge Engineering: Partner with customers, engineering teams, and internal support organizations to stabilize high-impact incidents, document repeatable solutions, and improve operational knowledge around cloud data protection and secure infrastructure.
Technical Support Engineer @ Perigen Inc
- Regulated Operations: Owned technical resolution for FDA-regulated healthcare applications across Windows, Linux, Microsoft SQL Server, networking, and cloud-connected environments, including Azure-integrated components, investigated SQL, Python, and HL7-related data flow issues across healthcare application workflows, collaborating with engineering, implementation, and client IT teams to remediate defects and configuration gaps.
- Incident Response: Restored production service across application, database, server, network, certificate, and integration layers using structured triage, log analysis, and root-cause investigation; and documented remediation.
- Hardening & Network Analysis: Strengthened production security posture through SSL/TLS certificate binding, server hardening, vulnerable cipher/protocol remediation, firewall-rule validation, and access-related configuration reviews. and HL7 integration issues.
- Automation: Built scripts and automation for log analysis, alerting, monitoring, and repeat-issue detection to improve operational visibility and reduce recurring incidents.
- Network Troubleshooting: Analyzed network traffic with Wireshark to isolate connectivity, latency, firewall, and protocol-level issues affecting clinical workflows and HL7 integrations. Validated API behavior using Postman, inspecting authentication flows, request/response patterns, endpoint behavior, and failure conditions to isolate application and integration issues.
- Knowledge Base and Runbooks- Authored technical documentation, resolution notes, and operational knowledge artifacts to improve team consistency, escalation quality, and speed of future incident response.
Technical Support - Lead @ Infosys Limited
- Leadership: Led incident response and triage for three enterprise applications, mentored team members in structured triage, production monitoring, documentation discipline, and escalation communication.
- Hybrid Networking & Automation: Diagnosed cloud / on-prem hybrid networking issues across VPC connectivity and routing; built automation for log analysis and batch monitoring; standardized RCA templates in ServiceNow.
- Legacy systems support: Supported hybrid application environments involving mainframe workflows, DB2, JCL, COBOL, batch processing, cloud-connected systems, and enterprise service-management processes.
Production Process Technician @ Procter & Gamble
- Oversaw SCADA/PLC-related operational configurations and resolved system faults that impacted manufacturing workflows.
- Ensured compliance-driven execution within regulated environments (FDA/cGMP context).
Program Manager | Web Developer | System Administrator @ Sem Fronteiras
- Developed and maintained IT infrastructure including LAN networks, Linux/Windows servers, workstations, patching, and application deployments.
- Created web applications and databases (HTML/CSS/JavaScript/PHP/SQL) and supported operational reporting and stakeholder coordination.
- Managed logistics and reporting for healthcare outreach programs, fostering strong execution discipline and operational ownership.