Work

Recent work from October 2025 through October 2026, followed by the earlier platform and cloud foundations it builds on. Internal systems are described through their engineering problems and public-safe outcomes.

Production software, cloud execution, and developer-platform reliability. The case studies show my responsibilities, the decisions behind the implementation, and the delivered result.

2026 – present
Production evidence · Live engineering data, a personal work view, and caching designed around freshness.

Wrote the product requirements and delivered live-data views, a personal work timeline, and shared caching for a team-owned engineering evidence product now in production. The work connects product definition, backend performance, and the acceptance checks behind reliable delivery.

typescript redis github-actions aws

2026 – present

Designed and stood up a shared knowledge repository with an agent-maintained wiki schema, hybrid retrieval, a structural knowledge graph, and a memory lifecycle. Repository-owned skills, hooks, and CI lint checks make research and decisions reusable across agent tools.

hybrid-search knowledge-graph memory skills github-actions

2026 – present

Ran Codex and Claude Code in company-controlled cloud sandboxes and returned inspectable patches. Added credential proxying, then implemented a keyless Codex pilot with per-run identity federation. The execution proof, pilot, and planned agent-team controls have distinct completion boundaries.

cloudflare-sandbox codex claude-code ai-gateway identity-federation

2026 – present

Built a versioned trust layer around a skill scanner, separating scan observations from policy decisions and emitting SARIF for CI. Packaged local pre-PR reviews, branch-review skills, and feedback hooks so trust practices can travel across repositories.

python skill-scanning sarif github-actions review-skills

Late 2025 – early 2026

Hardened an event-driven separation-of-duties platform with observability, automatic incident creation, and processor consolidation. Worked through security findings, maintained vulnerability-data integrations, reviewed organization governance, and introduced agent tooling into the team’s own repositories.

aws github-actions event-driven datadog python typescript

The platform work this chapter builds on: cloud networking, secure data access, and the operational plumbing that lets other teams move fast. Earlier career work stays separate from recent delivery.

2023 – 2025

Led enterprise network consolidation to simplify NAT Gateway usage, orchestrated a DNS migration, and moved AWS ACM certificates from email to automated DNS validation. The work reduced cloud costs and the operational burden of fragmented network patterns.

aws vpc transit-gateway route53 terraform acm

2023 – 2025

Owned AWS account automation and replaced manual account and VPC deletion with an event-driven Step Functions and Lambda workflow. Built DNS verification and cleanup to address subdomain-hijacking risk, and introduced Dev Containers for reproducible onboarding.

step-functions lambda event-driven python route53 dev-containers

2021 – 2023

I worked behind the customer experience for purchasing digital capabilities on John Deere equipment. During a hackathon, I built a secure data-ingestion pipeline that proved license data could serve internal teams while preserving isolation and access controls, helping make the case for an enterprise Data Engineering team.

java aws data-pipeline oauth

2019 – 2021

External API Platform

First external API

At John Deere Financial, I helped turn an early API-gateway effort into a safer path for dealer software by architecting the platform's first external-facing API with role-based authorization and audit logging. That foundation later matured into a gateway used for both internal and external APIs.

java api-gateway oauth rbac