USAA
Lead Cloud Security Engineer & Systems Engineer
- Led AWS data perimeter strategy—roadmap, governance, and alignment across business, architecture, and security engineering.
- Enriched CloudTrail across billions of daily events to map zones of trust and prioritize high-risk access.
- Built inner-sourced CI/CD for thousands of VPC endpoint policies across hundreds of accounts; bulk updates in minutes.
- Led Elastic Serverless Forwarder PoC projected to save $750K+ per year in logging infrastructure.
- Migrated Elasticsearch to Elastic Cloud—~$100K annual savings and 20 fewer engineering hours per month on cluster management.
- Cut logging cluster costs ~$500K (2022 tier reconfig) and ~$200K annually (2024 warm/cold tier removal).
- Designed GCP foundational security—org hierarchy, onboarding automation, VPC SC, SIEM—featured on Google Cloud's security blog.
- Site Commander for Availability Command Center, advising teams on high-risk emergency production changes.
Senior Cloud Security Engineer
- Deployed secure cloud key management with hardened DSMs and HSMs.
- Wrote Terraform provider in Go for automated CMK provisioning, rotation, and revocation via CI/CD.
- Automated certificate and TLS lifecycle across AWS—on-prem to ACM for thousands of certificates, SSM/ACME for hundreds of VMs, and reduced outage risk.