I will review your AWS cloud architecture for scalability, security, and cost
About this Gig
Former CTO and Head of Architecture with 20+ years in software and cloud architecture. I review production AWS systems and identify the architectural risks most likely to hurt you as you scale.
I don't check your AWS against a generic checklist. I review whether the architecture itself makes sense.
WHAT I BRING
- 20+ years as a developer, architect, and CTO, accountable for production architecture
- Multi-account production AWS in regulated healthcare/HIPAA environments
- Legacy monolith-to-cloud-native migrations with zero downtime
- Scalable event-driven and data-intensive production systems
- Complex enterprise integrations involving security, identity, APIs, and real-time data
WHAT THIS COVERS
One defined AWS system or workload not your whole estate. Send an architecture diagram, system context, current and target scale, constraints, and your concerns. I'll review scalability, reliability, architecture-level security risks, and major cost drivers.
WHAT THIS ISN'T
This is not penetration testing or a formal compliance audit. Cost review focuses on architectural cost drivers, not detailed FinOps/billing analysis.
You get prioritized findings: what matters now, what can wait, and why.
Cloud provider:
Amazon Web Services
My Portfolio
FAQ
Is this a security audit or penetration test?
No. I review security at the architecture level: account boundaries, IAM, network/data flows, isolation, secrets, and relevant design decisions. This is not penetration testing or a formal compliance audit/certification.
Will you analyze my actual AWS bill for savings?
Not by default. I identify architectural cost drivers and likely optimization opportunities. If you need detailed analysis of Cost Explorer, CUR, or billing data, message me before ordering so we can scope it separately.
What if my system is bigger than one workload?
Each package covers one clearly bounded system or workload. If you have a large multi-service or multi-account estate, message me first; we can either define a custom engagement or focus on the highest-risk area.
What do I need to send before you start?
An architecture diagram (rough is fine), a short description of the system, current and target scale, important constraints, and the specific concerns or decisions you want reviewed.
Do you need access to my AWS account?
Usually, no. Most reviews work from architecture diagrams, documentation, relevant configuration details, and a discussion of the system. If deeper access would help, we'll agree on exactly what's needed first. Never send credentials or secret keys.
Can you review Terraform, CloudFormation, CDK, or code?
Architecture review does not automatically include a full source-code or IaC audit. Relevant snippets or infrastructure definitions can be used as supporting material. Large repositories or detailed code/IaC reviews require separate scope.

