Anh-Tuan Pham
Senior AWS Cloud Engineer · Landing zone · FinOps · SOC2
Summary
Senior AWS cloud engineer with eight years across two SaaS companies. Owns the landing zone + IAM posture for a 280-engineer org ($8M annualised AWS spend across 38 accounts). Cut RDS spend by $620k/yr (-38%) via right-sizing + RI ladder. Led SOC2 Type II audit prep — zero findings. AWS Solutions Architect Professional (2024).
Skills
AWS depth
EKS + KarpenterRDS / Aurora Serverless v2IAM + SSO + Organizations + SCPsGuardDuty + Security Hub + ConfigCloudTrail + CUR + Athena
IaC + Governance
Terraform (38 modules)terratestCheckov + tfsecOPA / Sentinel
Compliance + Practices
SOC2 Type IIFinOps Foundation frameworkDR + GameDayMentorship + on-call
Experience
Senior Cloud Engineer
Q
Quill · Remote (San Jose, CA)
Apr 2022—Present
- Cut RDS spend by $620k/yr (-38%) via a three-part ladder: right-sized 38 instances using p99 CPU data, layered a 3-year RI commitment on 70% of remaining capacity, and migrated 12 read replicas to Aurora Serverless v2.
- Own 38 Terraform modules across the AWS estate; module test coverage at 84% via terratest; module-version PRs require 2 reviewers + tfsec + Checkov gates.
- Led SOC2 Type II audit prep over 8 weeks; shipped 14 control remediations (CloudTrail org-trail, GuardDuty enablement, Config aggregator, KMS rotation). External auditor signed off with zero findings.
- Led a 6-month migration of 28 services from EC2 to EKS with Karpenter autoscaling; compute spend fell $1.1M/yr (-42%) and p99 deploy time dropped from 18 min to 3 min.
- Reduced IAM permission-creep via SCP guardrails + Access Analyzer; high-privilege roles fell from 380 to 42 across 38 accounts.
Cloud Platform Engineer
S
Snowflake · San Mateo, CA
Sep 2019—Mar 2022
- Built the team's first AWS landing zone (Control Tower + custom Terraform overlays); 38 product accounts onboarded in 4 months with SSO + GuardDuty + CloudTrail org-trail + cost guardrails baked in.
- Authored the FinOps dashboard (Athena over CUR + Grafana); per-team unit-economics now drives the weekly cost-review meeting (avg $80k/qtr in surfaced opportunities).
- Built the DR posture for the customer-data store (cross-region Aurora Global Database + S3 CRR + scripted failover runbook); GameDay-tested twice with RTO under 8 minutes.
DevOps Engineer
A
Asana · San Francisco, CA
Jul 2017—Aug 2019
- Migrated the secrets surface from EC2 IAM roles + parameter store to IRSA + Secrets Manager + KMS keys per service; reduced cross-service blast radius from 28-service-shared to per-service-isolated.
Certifications
AWS Solutions Architect Professional
Amazon Web Services·Apr 2024
AWS Solutions Architect Associate
Amazon Web Services·Aug 2021
Open Source & Community
aws/karpenter-provider-aws
Contributor (2 merged PRs)Two merged PRs to Karpenter — one closed a node-termination race during scale-down; one extended the consolidation policy for spot-capacity-aware workloads. Plus: AWS Community Builder (2024) — published 'Landing-zone migration patterns for Series B-to-C orgs.'
GoKubernetesAWS
Education
BSc in Computer Science
University of California, San Diego
Sep 2013—Jun 2017
Senior (AWS)
8 years AWS. Owns landing zone + $8M spend for 280-engineer org. SAP cert 2024.
Use this template