Cloud Platform Engineer

AWS · AZURE · GCP · TERRAFORM

AWS platforms that are secure by default and simple to operate.

I take cloud infrastructure from requirement to running system: Terraform for every environment, pipelines for every release, least-privilege access and monitoring from day one.

UK based · remote-first AWS Certified Solutions Architect
Benjamin Cooper, Cloud Platform Engineer
AWS SAACertified
Terraform + CI/CDInfrastructure automation
40%Faster deployments at BKS
4+ yearsHands-on AWS in production
0Hardcoded credentials, by design
10+ yearsOperations, finance & tech

HOW I BUILD

Infrastructure treated like software.

  1. Define it in code. Every resource lives in Terraform with remote state. Nothing is hand-built in the console.
  2. Review it. Changes go through Git and a plan before they touch an account.
  3. Automate delivery. Pipelines deploy, not people.
  4. Monitor the result. Dashboards, alarms and alerting ship with the stack.

ABOUT

Platforms that teams can trust and run.

I design, automate and operate AWS infrastructure, weighing security, reliability, cost and maintainability on every decision.

My work spans cloud networking, identity and access management, monitoring, high availability, disaster recovery and CI/CD. I turn business requirements into infrastructure that is documented, repeatable and easy for the next engineer to operate.

I also bring more than ten years across operations, finance and technology. That background is why I frame technical choices in terms of risk, cost and delivery speed, explain them clearly to non-technical stakeholders, and own a problem from first requirement to a running, monitored system.

CORE CAPABILITIES

Infrastructure, delivery, security and operations.

AWS Architecture

EC2, VPC, S3, RDS, Lambda, Route 53, CloudFront, Transit Gateway, IAM, WAF and CloudWatch.

Infrastructure as Code

Terraform modules, reusable environments, remote state and multi-region stacks.

CI/CD & Automation

GitHub Actions, Jenkins, AWS CodePipeline, CodeBuild, Bash and Python.

Security

Least-privilege IAM, short-lived credentials, AWS WAF, secrets management, encryption and network segmentation.

Observability & Resilience

CloudWatch dashboards, logs and alarms, SNS alerting, RDS Multi-AZ and S3 Cross-Region Replication.

Engineering & Tooling

Python, REST APIs, Git/GitHub, GitHub Apps, JWT and event-driven automation.

EXPERIENCE

Professional impact.

2022 — 2026

Cloud Platform Engineer

BKS

  • Cut deployment times by 40% by automating application delivery with CodePipeline and CodeBuild.
  • Made infrastructure repeatable by provisioning and managing AWS in Terraform under version control.
  • Raised resilience with CloudWatch monitoring, SNS alerting, RDS Multi-AZ and S3 Cross-Region Replication.
  • Reduced attack surface through VPC design, least-privilege IAM, Security Groups and AWS WAF.
2021 — 2022

Junior Infrastructure Engineer

PCS

  • Ran IAM access management, S3 backups, endpoint security and Conditional Access controls.
  • Wrote technical documentation and resolved user-facing issues across business systems.
10+ years

Operations, finance & technology

  • Commercial grounding that shapes how I weigh cost, risk and delivery speed in architecture decisions.

CERTIFICATION

AWS Certified Solutions Architect – Associate

Validated knowledge of secure, resilient, high-performing and cost-optimised AWS architectures.

SAA

ARCHITECTURE

Designs across AWS, Azure and GCP.

Every diagram maps to infrastructure I’ve built and deployed in Terraform. Select one to view it full size.

AWS · TerraformProduction Cloud ArchitectureRoute 53, CloudFront and WAF in front of ECS behind an ALB, RDS Multi-AZ and DynamoDB, with CI/CD from GitHub Actions and automated incident response.
AWS · TerraformLanding ZoneMulti-AZ VPC with private-by-default subnets, plus a central audit pipeline: CloudTrail, Config and GuardDuty, with logs archived from S3 to Glacier.
AWS · TerraformLambda → SNSServerless, event-driven publishing with a least-privilege IAM role, remote state in S3 and one-command redeploys on every code change.
GCP · TerraformGKE-Ready NetworkCustom-mode VPC with secondary ranges for pods and services, Cloud NAT for egress and Private Google Access, with no public IPs on workloads.
Azure · TerraformTwo-VM LinuxTwo Ubuntu VMs from one for_each block, SSH-key only, locked to a single source IP by an NSG, with state in Azure Storage.

ON GITHUB

Public repositories.

Pulled live from GitHub, so the latest public work always shows here.

View GitHub profile ↗
Loading latest GitHub projects...

CONTACT

Need someone to own your AWS platform end to end?

I’m open to remote Cloud Platform, DevOps and Infrastructure Engineering roles, and happy to walk through any project above in detail.