PHEAA
— Enterprise/Solutions/Development/QA/Performance Architect & Developer
(Consultant)
6
Years, 2mo
Self-driven, multi-hat Enterprise/Solutions/Performance Architect
and Developer instrumental to the modernization of mission-critical mainframe
systems (COBOL/DB2) to cloud-native Java/PostgreSQL hosted on AWS and
on-premises. The ported platform was initially frail — prone to data leakage,
errors, and unable to sustain even a fraction of expected production load.
Consistently advocated for non-functional requirements — performance,
observability, caching, and security — as equal priorities alongside functional
development, often pushing back to ensure production stability was not
sacrificed for feature velocity. Faced resistance from both internal teams and
external vendors reluctant to acknowledge defects, but remained unrelenting —
proving issues through demonstration and purpose-built tooling that made problems
undeniable and drove resolution. Without this persistence, the effort risked
repeating a failed prior modernization attempt years earlier.
Authored multiple whitepapers driving architectural decisions
and standards. Proactively ventured beyond own group in a heavily siloed
environment, rolling up sleeves to assist other teams — recognizing that the
success of the port depended on all teams succeeding together. This cross-team
engagement broke down silos and built reciprocal relationships that accelerated
delivery.
Designed and delivered 35+ production services, shared
libraries, and tooling across a 70+ account AWS Control Tower environment
spanning observability, security, caching, automation, and performance
engineering — all architected with self-healing and fault-tolerant patterns
including queues, dead-letter retries, transient connectivity handling, and
other defensive strategies — while concurrently supporting other consulting
clients.
Cloud
Infrastructure & Platform Engineering (AWS CDK / TypeScript / Python)
- Architected and deployed
centralized observability and logging across a 70+ account AWS Control
Tower environment, forwarding CloudWatch, GuardDuty, WAF, and VPC Flow
logs to Azure Sentinel and Azure Log Analytics
- Designed ECS-based centralized
metrics pipeline forwarding CloudWatch and Prometheus agent metrics to AWS
Managed Prometheus and Grafana
- Implemented single-pane-of-glass
centralized Managed Grafana for dashboards and alerting driven by
CloudWatch and Prometheus across 70+ accounts
- Monitored AWS Health events per
account (70+) and region with centralized notification via Grafana
alerting
- Built a self-service datalake
platform automating database, table, and Glue creation for
Athena/QuickSight consumers covering VPC Flow, CloudTrail, S3 Access,
Config, WAF, and DNS data sources
- Engineered a solution to an AWS
Config delivery bottleneck caused by excessive config drops across 70+
accounts exceeding Athena limits, deploying automated S3 file
decomposition logic to maintain datalake viability
- Deployed custom AWS Active
Directory and PKI infrastructure for ported mainframe applications across
20+ accounts
- Developed an Active Directory
event monitoring service publishing AD changes using ElastiCache Redis
pub/sub, enabling real-time user/RBAC cache invalidation for ported
applications
- Architected PostgreSQL table
caching strategy using ElastiCache Redis pub/sub to reduce IO-bound
database pressure inherited from COBOL/DB2 access patterns, with real-time
invalidation on table changes
- Implemented centralized CloudWatch
log retention policy enforcement and S3 bucket lifecycle management across
the enterprise
- Developed CloudFront log
forwarding to centralized logging and S3 event ingestion to Athena
datalake
- Built centralized ECS-based CloudWatch
log forwarding to Splunk (later Azure) and/or Datalake for enterprise-wide
log analytics
- Deployed ECS service forwarding SIEM
events to Azure Log Analytics across 70+ accounts
- Built S3 audit stack capturing
expiry events to the datalake for compliance
Performance
Engineering & Load Testing (Java / C#)
- Championed custom SQL telemetry
specifically focused on IO-bound behavior inherited from the COBOL/DB2
origins, driving the need to heavily instrument application database
access for both batch and transactional workloads
- Created custom JMeter extensions
with database-backed dynamic request drivers simulating ambient and peak
production loads against ported mainframe applications
- Built a forked AWS JDBC driver
with embedded SQL telemetry capturing query counts, cursor usage,
nanosecond-precision response percentile distributions (P10–P90), and
row-level impact metrics — adopted by the broader team and combined with
flame graphs to optimize ported application logic
- Designed a six-browser
concurrent .NET test harness that exposed stability and cross-talk defects
in the application runtime — directly driving critical vendor fixes
- Later developed a CASE tool that
auto-generates JMeter test fixtures from live mainframe analytics, target
database connections and data, and parameterized request transactions
- Built a CASE tool that auto-generates
Selenium tests from drive analytics and parameterized request files driven
by live data
- Developed a single-browser .NET
transaction executor for prototyping web requests against transpiled
COBOL/DB2 apps with full SQL instrumentation capture
- Built SQL instrumentation
reporting tools for deduplication, aggregation, and tabular performance
analysis
- Developed mainframe analytics
parser utility used by custom JMeter extensions to throttle backend
requests based on production patterns
Shared Libraries
& Core Services (Java)
- Developed a common utilities JAR
providing DB connection governance, log regex metrics and SQL telemetry
for all (ported COBOL) applications
- Created custom asynchronous
logging handlers, formatters, and Juli valve replacements for
Tomcat-hosted ported applications
- Engineered a shared Redis
pub/sub–enabled web application enabling real-time cache flush
notifications for user/RBAC and PostgreSQL lookup table caches, with
built-in mock services to drive CPU, RAM, network, and DB load at targeted
levels from JMeter
- Developed ECS application
handling PostgreSQL lookup table change notifications to optimize caching
in ported apps hosted in AWS and on-premises, reducing repetitive IO-bound
queries inherited from COBOL/DB2 patterns
Workflow Automation
(Stonebranch / Python)
- Designed and deployed a SSO-enabled
Stonebranch automation stack for hybrid AWS/on-premises workflows
- Built custom Stonebranch
Universal Template providing enhanced S3 monitoring with content-based
routing for workflows
- Developed regex-enabled S3
operations Universal Template
- Architected workflow, trigger,
and task cloning Universal Template
- Built renaming Universal
Template based on native Stonebranch lists
- Architected agent management and
task/workflow/trigger creator templates
Mentoring,
Prototyping & Knowledge Transfer
- Mentored
development/infrastructure team members over multiple years (1–2
sessions/week with homework) across Python, Java, TypeScript, AWS CDK, and
Stonebranch
- Provided prototypes and
custom-developed solutions to teams struggling with manual processes,
ensuring accuracy and expediting workflows
- Delivered starter CDK frameworks
and majority of functionality for DUO MFA and Amazon Connect integration
services
- Many tools and services now
adopted beyond the original cloud context for on-premises use
- Prior to departure, created a
comprehensive asset catalog (CSV with details, Confluence links,
repository links) and delivered dozens of recorded knowledge transfer
sessions with teams and individuals to ensure continuity
Security &
Identity Integration
- Architected DUO MFA integration
service
- Architected Amazon Connect
integration service
- Architected/deployed custom PKI-hosted
service subscribing to Domain Controllers and publishing to ElastiCache
for downstream consumers
- Developed utility for
streamlined secure access to ROOT, SubCA, and Boot AD EC2 instances across
PKI infrastructure
Technology Stack
|
Domain
|
Technologies
|
|
Cloud
|
AWS CDK, ECS, ElastiCache, Athena, Glue, QuickSight,
CloudWatch, Prometheus, Grafana, S3, Control Tower, CloudFront
|
|
Languages
|
TypeScript, Python, Java, C# (.NET 8), PowerShell
|
|
Data
|
PostgreSQL, DB2 (legacy), Redis, Azure Log Analytics, Azure
Sentinel
|
|
Testing
|
JMeter (custom extensions), Selenium (auto-generated), custom
.NET harnesses
|
|
Automation
|
Stonebranch (SSO, Universal Templates, CDK), AWS CDK
|
|
Observability
|
CloudWatch, Prometheus, Grafana, custom SQL telemetry, Azure
Sentinel
|
|
Identity
|
AWS Directory Service, DUO, PKI, Active Directory
|