Manhattan Beach, CA 90266 | kirk (at) icapsolutions.com
Professional Summary
Cloud infrastructure engineer and DevSecOps specialist with 15+ years architecting and automating AWS and GCP environments, part of a 20+ year technology career spanning systems engineering to cloud-native infrastructure. Track record leading infrastructure-as-code initiatives, cutting cloud spend, and hardening security posture across regulated financial-services and high-growth startup environments. Integrates AI-assisted tooling (Claude, Warp) into infrastructure workflows to accelerate delivery without sacrificing governance.
Core Skills
- Cloud Platforms: AWS, Google Cloud Platform (GCP)
- Containerization & Orchestration: Docker, Kubernetes (GKE, EKS, OpenShift)
- CI/CD: Jenkins, GitHub Actions, AWS CodePipeline, Spinnaker
- Infrastructure as Code: Terraform, Ansible, Helm
- Observability: Grafana, CloudWatch, New Relic, AKHQ/Kpow
- Data & Messaging: Apache Airflow, Apache Kafka, Snowflake integrations
- Security & IAM: HashiCorp Vault, IAM, Cloud Armor, RBAC
- Networking: VPC, DNS, Load Balancers, VPN, Firewalls, SFTP
- Languages: Python, Bash
- AI-Assisted Tooling: Claude AI, Warp CLI
Work History
FanFix – (January 2025 – Present)
DevSecOps Engineer
- Lead DevSecOps engineer, solely responsible for GCP infrastructure-as-code across environments organized into discrete Terraform layers with PR-gated, auditable deployment workflows.
- Use AI-powered CLI tools (Warp, Claude) to accelerate troubleshooting and delivery across a multi-repo microservices architecture while maintaining a high commit cadence.
- Architected an enterprise Apache Airflow orchestration platform (Terraform modules, Kubernetes manifests, service accounts for Snowflake, Sendgrid, Posthog, Sendbird), enabling org-wide automated ETL pipelines.
- Led migration from legacy Kafdrop to production-grade AKHQ (SASL auth, gateway routes, health checks) with zero downtime, reducing monitoring licensing costs.
- Built a Terraform-managed Grafana dashboards repository with GitHub Actions CI/CD, shifting monitoring from manual creation to version-controlled, PR-driven infrastructure.
- Audited and remediated 100+ GCS buckets to uniform bucket-level IAM; redesigned PostgreSQL access layer with role-based access controls across environments.
Technologies: GCP, GKE, Terraform, Helm, Airflow, Kafka, AKHQ, Cloud SQL, GCS, IAM, Cloud Armor, GitHub Actions, Grafana, Python, Bash
JPMorgan Chase (formerly First Republic Bank) – (March 2023 – January 2025)
Senior Cloud Engineer
- Hired directly from IBM as a full-time employee for First Republic Bank, later acquired by Chase; developed and maintained proprietary CI/CD pipelines while leading a team of support specialists.
- Built and managed Terraform blueprints for application deployment across Spinnaker, Kubernetes (OpenShift/EKS), JFrog Artifactory, HashiCorp Vault, and CloudBees Jenkins.
- Served as team lead supporting hundreds of engineers deploying applications across diverse environments.
Technologies: Kubernetes (OpenShift, EKS), JFrog Artifactory, HashiCorp Vault, CloudBees Jenkins, AWS Aurora PostgreSQL, Spinnaker, Terraform, Python, Bash
IBM (formerly TAOS) – (January 2021 – February 2023)
Consultant, Cloud Engineer
- Consultant contracted to First Republic Bank as part of the enterprise architecture team, delivering cloud infrastructure and support for hundreds of engineers.
- Built and maintained a Python-based CI/CD CLI/API tool (Jenkins, Kubernetes, Vault, Artifactory, AWS RDS) to automate the SDLC across platforms and languages.
- Redesigned client onboarding into a self-serve utility; established infrastructure observability with New Relic and CloudWatch.
- Certified: Google Cloud Platform Professional Architect.
Technologies: RedHat OpenShift (OCP), Artifactory, HashiCorp Vault, CloudBees Jenkins, AWS EKS, AWS Aurora PostgreSQL
TrueData – (September 2017 – December 2020)
Senior DevOps Engineer
- Owned company-wide AWS infrastructure and cloud budget; cut monthly cloud spend 30% via S3 lifecycle policies, API Gateway throttling, EC2 right-sizing, and Redshift tuning.
- Replaced a cost-prohibitive API gateway layer with a serverless Kinesis/Firehose pipeline, improving performance and security while lowering cost end-to-end (SDK → S3/DB).
- Designed a compliant VPN architecture (OpenVPN + MFA, multi-VPC peering, endpoint and subnet segmentation, strict security groups).
- Introduced Terraform/Ansible and ECS Fargate CI/CD, retiring legacy nodes for managed serverless infrastructure; led containerization of core products.
Technologies: CloudFront, CloudFormation, Terraform, Ansible, Docker, ECS/Fargate, CodePipeline/CodeBuild/CodeDeploy, Lambda, Kinesis/Firehose, RDS, DynamoDB, VPC, IAM, Python, Bash
SalesJobs – (2006 – 2017)
CTO / Senior DevOps Engineer
- CTO for 11 years; owned strategy, architecture, and full technology operations for a job-search platform running two dozen+ Unix servers.
- Migrated legacy on-prem architecture (Apache/mod_perl, MySQL master/slave, DJBDNS, Qmail MTA) to AWS (EC2, RDS, CodeDeploy, CodePipeline, S3), rebuilding as a modern CI/CD-driven service.
- Managed engineering staff, vendors, and budget while delivering all technical projects on time and on budget.
Additional Experience (prior to 2006): Systems and software engineering roles spanning EDI application development (FairIsaac), Linux/Perl-based distributed systems (Independent Systems Engineer, Nebula Software, Rotor Inc.), and enterprise network/telephony engineering (TRW). Details available on request.
Education & Certifications
B.S., Electrical Engineering — California State University, Long Beach
Certifications: GCP Professional Architect | MCSE (Microsoft Certified Systems Engineer) | Oracle RDBMS
Prior Clearance: EBI Secret Clearance (inactive)
Additional Resumes From This Cloud Infrastructure Engineer
This resume highlights Kirk’s hands-on cloud infrastructure engineer and DevSecOps background. Two additional versions are available for leadership-track roles: