OPEN TO CLOUD SECURITY / NETWORK SECURITY / ARCHITECT ROLES

Securing the path
from edge to cloud.

Kedar — Senior Cloud Support Engineer specializing in SASE, Zero Trust Network Access, and AWS cloud architecture. Austin, TX.

5
AWS Certifications
1
CCNP
3
Companies
AWS·SASE·ZTNA
Core Stack
// route trace

Career path

Each hop narrowed the focus — from securing the network edge to architecting in the cloud to defending it at scale.

hop · role
01
Network Security Analyst
exxonmobil.network · 2017–2018
Worked incident management, building SSL and ticketing runbooks that improved team resolution speed by 50%, and contributed to an L3/L4 redesign covering HA firewall configs and VRF segmentation across multiple sites.
02
Network Security & Proxy Engineer
exxonmobil.network · 2018–2022
Owned BGP routing across Cisco FTD and Juniper SRX for enterprise direct outbound locations. Ran an end-to-end PoC replacing Forcepoint with a new SWG cloud solution, directly supporting the procurement decision.
03
Cloud Support Engineer — Networking
aws.cloud · 2022–2024
Internal SME for ALB, NLB, GWLB, and AWS WAF — built a reusable CloudFormation template adopted team-wide to accelerate customer lab setup during escalations. Provisioned VPCs and Direct Connect for enterprise migrations.
04
Enterprise Solutions Architect
aws.cloud · 2024–2026
Technical advisor for automotive/manufacturing enterprise accounts. Migrated EC2 to ECS for 35% faster deployments and 15% lower costs. Built Terraform + GitHub Actions pipelines for AWS security architectures, and developed GenAI knowledge assistants with Bedrock.
05
Senior Cloud Support Engineer current
netskope.sase · 2026–Present
Focused on SASE, proxy/SWG, Zero Trust Network Access, and endpoint DLP. Partners with the account team on Terraform-based architectural deployments and resolves critical Proxy, Gateway, and eDLP issues for strategic customers.
// verified credentials

Certifications

Four active AWS Associate certifications, plus CCNP for the network layer underneath it all.

AWS · ASSOCIATE
Solutions Architect
ACTIVE
AWS · ASSOCIATE
SysOps Administrator
ACTIVE
AWS · ASSOCIATE
Developer
ACTIVE
AWS · ASSOCIATE
Machine Learning Engineer
ACTIVE
CISCO
CCNP
ACTIVE
AWS
Generative AI Foundational
ACTIVE
// policy categories

Where I operate

Four working areas, matched to how the job actually gets done.

01 SASE & Zero Trust
  • Proxy / Secure Web Gateway
  • Zero Trust Network Access (ZTNA / NPA)
  • Policy design for hybrid traffic
02 Cloud Architecture
  • AWS infrastructure & solutions design
  • VPC, Transit Gateway, BGP routing
  • CI/CD pipeline security
03 Data Protection
  • Endpoint DLP
  • Print / export policy controls
  • Data-in-motion inspection
04 Network Security
  • Enterprise proxy engineering
  • CCNP-level routing & switching
  • Perimeter & traffic control
05 Infrastructure & AI
  • Amazon EKS
  • Terraform (IaC)
  • AWS CloudFormation
  • Generative AI (Amazon Bedrock)
// recognition

Beyond the day job

Evaluating other builders' work as a judge for cloud and GenAI competitions.

Hackathon & Competition Judge
Judged multiple cloud and Generative AI hackathons/competitions, evaluating submitted projects on architecture design, security posture, and technical execution.
Cloud Architecture GenAI Security Review
// architecture work

Selected projects

AWS solution architectures designed across banking, insurance, IoT/agriculture, and global enterprise networking.

Bank Operation — Payments & GenAI Chatbot
Multi-account AWS architecture for core banking: account opening, payment processing, and a GenAI-powered banking chatbot. Cross-account connectivity via Transit Gateway and PrivateLink, ECS Fargate microservices, CloudHSM/KMS encryption, and Amazon Bedrock with Guardrails for safe, compliant AI responses.
ECS Fargate Bedrock Guardrails Transit Gateway CloudHSM / KMS
Big Company Enterprise Cloud — Global Network
Global enterprise network architecture spanning North America, South America, and the UK, with active/DR failover design, Direct Connect and Transit Gateway interconnects, and Gateway Load Balancer-based virtual firewall inspection for inbound/outbound traffic.
Multi-Region Direct Connect Active/DR Virtual Firewall
Insurance — Automated KYC & Claims
Automated KYC and claims-verification pipeline for an insurance platform — document and face verification via Textract, Rekognition, and Augmented AI, with a Bedrock-powered knowledge base (RAG) for automated claim decisioning and 7-year compliant audit retention in S3 Glacier.
Textract / Rekognition Bedrock RAG S3 Glacier
Smart Farming — IoT + GenAI Agent
IoT-driven smart farming solution using AWS IoT Core to ingest zone-based humidity and temperature sensor data, paired with a Bedrock AgentCore agent that reasons over live weather data, a RAG knowledge base, and automated grower notifications.
AWS IoT Core Bedrock AgentCore Lambda
// side project
Smart Mirror
A Raspberry Pi–based smart mirror, built as a hands-on learning project — custom OS setup, display integration, and hardware/software troubleshooting from the ground up.
Raspberry Pi Linux Hardware