SENIOR AWS CLOUD SOLUTIONS ARCHITECT

Cloud Brain Ops

AWS · Kubernetes · DevOps · AI · Automation. Engineering resilient, cost-optimized cloud platforms — from enterprise Landing Zones to Kubernetes-native DevOps and AI-driven automation.

View Projects Get in Touch
15+
Years IT Experience
7
AWS Certifications
FinOps
Cost Optimization & TCO Reduction
Migration
Cloud Migration & Modernization
§ ABOUT

Background

I'm Pankaj Kumar, a Senior AWS Cloud Solutions Architect with 15+ years of IT experience, currently architecting enterprise-scale cloud platforms. My work spans AWS Landing Zone design, large-scale VM migrations, Kubernetes/EKS-based DevOps platforms, and increasingly, AI-driven automation and cloud cost governance.

I mentor a team of 3 cloud engineers and operate a personal multi-account AWS Organizations lab environment where I prototype and validate architecture patterns before they reach production engagements.

Core areas: AWS Landing Zone & Multi-Account Governance · Enterprise Cloud Migration · Kubernetes/EKS & GitOps CI/CD · Cloud Cost Optimization · AI/ML-Integrated Architectures

CERTIFICATIONS
SAP-C02Solutions Architect Professional
DOP-C02DevOps Engineer Professional
ANS-C01Advanced Networking Specialty
SCS-C02Security Specialty
AIF-C01AI Practitioner
SAA-C02Solutions Architect Associate
DVADeveloper Associate
TF-ATerraform Associate
§ PROJECTS

Case Studies

Enterprise engagements and personal lab builds. Client details are anonymized; architectures and outcomes are real.

Enterprise AWS Landing Zone & VM Migration
ENTERPRISE · QSR CLIENT

Client needed a secure, governed multi-account AWS foundation to migrate production VMs off legacy VMware infrastructure, with strict RTO/RPO requirements.

Designed a Landing Zone across management, network-hub, workload-prod, log-archive, and audit accounts. Implemented Transit Gateway-based hub-spoke networking, centralized logging, and guardrails via AWS Organizations SCPs.

34% TCO reduction · RTO ~2h20m · RPO ~12min · VMware-to-AWS VM migration
AWS OrganizationsTransit GatewayLanding Zone AcceleratorTerraform
DevOps CI/CD + EKS GitOps Platform
ENTERPRISE · TELECOM CLIENT

Client needed a modern CI/CD pipeline and container orchestration platform to replace manual deployment processes.

Built path-scoped CI/CD pipelines deploying to EKS via GitOps patterns for automated, auditable releases.

Faster, more reliable deployments with full GitOps audit trail
CodePipelineCodeCommitEKSGitOpsHelm
Event-Driven Cloud Cost Governance Pipeline
PERSONAL LAB

Personal multi-account AWS lab was accumulating orphaned resource costs — idle Transit Gateway attachments, unused Elastic IPs, an unused VPC Interface Endpoint — with no automated detection.

Built a serverless cost governance pipeline: Lambda scans for orphaned resources, DynamoDB tracks state, SNS alerts on findings, API Gateway exposes a dashboard endpoint. Fully deployed via Terraform.

Significant recurring monthly savings identified and eliminated
LambdaDynamoDBSNSAPI GatewayTerraform
Serverless API Platform
PERSONAL LAB

REST API via API Gateway, Lambda backend, DynamoDB storage, EventBridge for async workflows, Cognito for authentication, plus a private API endpoint pattern.

API GatewayLambdaDynamoDBEventBridgeCognito
MongoDB Replica Set on EKS
PERSONAL LAB

Deployed a MongoDB replica set via Helm charts, integrated with Secrets Manager through IRSA, configured PodDisruptionBudgets and HPA for resilience/scaling, monitored via kube-prometheus-stack.

EKSHelmSecrets ManagerIRSAPrometheus
§ REPOSITORIES

Open Source & Lab Code

Hands-on infrastructure code, open for review.

aws-landing-zone-isolation →
Terraform state isolation framework with GitHub Actions OIDC for secure, keyless CI/CD deployments.
TerraformGitHub ActionsOIDC
§ CONTACT

Get in Touch

OPEN TO: CLOUD ARCHITECTURE ROLES · CONSULTING ENGAGEMENTS