Experience

Lyra Health

Engineering Manager, DevOps Engineering • 2024 — Present

  • Leads a platform engineering team responsible for cloud infrastructure, IaC, developer tooling, and secure file transfer across Lyra's AWS-based production environment.
  • Architected and is delivering an internal governed AI platform — a tool-agnostic catalog of reusable agents, skills, instructions, integrations, and domain knowledge that behaves consistently across Codex and Claude Code. Establishes shared organizational standards for quality, safety, ownership, and evaluation so teams preserve specialized ways of working while sharing a common substrate. Piloted within DevOps; expanding into the Data and Engineering organizations.
  • Defined the operating model for AI artifacts as organizational assets — creation, ownership, versioning, quality tracking, and evaluation — so engineers move across domains without rebuilding their AI workflow from scratch.
  • Drove 95% automation of infrastructure provisioning workflows, eliminating manual toil and reducing deployment lead times by 60%.
  • Led a full DevOps transformation to an automated Scrumban operating model, planned and implemented end to end using Claude Code — replaced sprint commitments and story-point velocity with standardized intake, automated routing, and flow metrics, cutting median cycle time 31% and recurring ceremony overhead 79% (roughly 400 team hours annualized).
  • Established cross-team network governance standards — consistent security group policy, traffic controls, and automated compliance across all microservices.
  • Delivered $140K in annual cloud cost savings through rightsizing, reserved instance planning, and automated cleanup pipelines.
  • Treats engineering process as a product: identify friction in how the team builds and ships, then iterate on improvements.

Lead DevOps Engineer • 2023 — 2024

  • Designed and implemented AWS Transit Gateway & Network Firewall architecture spanning 40+ VPCs, standardizing inter-service connectivity while enforcing consistent network segmentation, saving $140K in annual costs.
  • Led architecture and delivery of zero trust network access rollout using Banyan Security / SonicWall Cloud Secure Edge, replacing legacy VPN for 800–3,000+ employees and 1,000+ internal services.
  • Architected and deployed log ingestion pipelines (CloudFront, Route 53 Resolver Query, Transit Gateway Flow, VPC Flow) into Athena, enabling full network observability for security and reliability use cases.
  • Built eBPF-based network observability tooling to surface L3/L4 traffic visibility across the microservices fleet.
  • Drove intent-based / just-in-time access control adoption using Opal and Okta, abstracting entitlement management from individual engineers.

Senior DevOps Engineer • 2022 — 2023

  • Designed VPC Flow Log ingestion pipeline into Splunk for full L3/L4 network observability.
  • Automated network policy enforcement using Terraform and AWS Config Rules, ensuring continuous security group compliance.
  • Reduced AWS network egress costs by 35% through Traffic Mirroring analysis and targeted architecture changes.

Morgan Stanley

Cloud Network Architect • 2022

  • Architected hybrid cloud network connectivity patterns including Transit Gateway, Direct Connect, and PrivateLink at financial-grade reliability standards.
  • Led evaluation and design of network automation tooling to replace manual firewall provisioning, reducing change lead times from days to minutes.
  • Architected AWS Landing Zone with Transit Gateway hub-and-spoke topology, standardizing VPC connectivity patterns across 60+ accounts.

Eaton Vance (acq. by Morgan Stanley)

Cloud Architect & Network Automation Engineer • 2017 — 2021

  • Built and managed global network infrastructure spanning 80 offices across 20 countries, including SD-WAN rollout and BGP routing redesign.
  • Designed and implemented zero-touch network automation platform using Ansible and Python — eliminating manual CLI-driven change processes entirely and enabling zero-touch provisioning for branch deployments.
  • Architected AWS landing zone with Transit Gateway hub-and-spoke topology across 15+ accounts.
  • Delivered IPv6 dual-stack rollout across core network infrastructure, improving scalability and alignment with cloud-native addressing requirements.
  • Led full IaC migration of network configurations to Terraform, version-controlling all network state and enabling GitOps-style change management.
  • Automated DNS provisioning using Ansible + Infoblox integration, reducing ticket resolution time from days to minutes.

SS&C Technologies

Network Engineer, Global Infrastructure • 2014 — 2017

  • Managed global WAN and LAN across 30+ sites supporting 10,000+ employees.
  • Built Python-driven firewall policy automation, reducing provisioning errors by 80%.
  • Led BGP and OSPF redesign to improve convergence and resilience across the core network.

SS&C Tradeware

Network Engineer • 2013 — 2015

  • Managed network infrastructure for trading platform environments with strict latency and uptime requirements.
  • Implemented monitoring and alerting pipelines for network performance and availability.

Technologies

Network Architecture & Automation

Zero-touch provisioning, intent-based networking, BGP, OSPF, SD-WAN, AWS VPC / Transit Gateway / Direct Connect / PrivateLink, IPv6, NAT64, network segmentation, firewall policy automation, L3/L4 traffic management

Infrastructure as Code

Terraform / OpenTofu, Ansible, CloudFormation, GitOps workflows, semantic versioning, modular IaC design

Observability & Security

eBPF (network flow capture, L3/L4 visibility), VPC & Transit Gateway Flow Logs, Splunk, CloudWatch, AWS Network Manager, Okta, Banyan Security / SonicWall Cloud Secure Edge / Appgate, Opal

Developer Tooling & Platform

Kubernetes, Docker, GitHub Actions, CI/CD pipelines, internal developer platforms, golden path tooling

Languages

Python, Bash, HCL

AI & Developer Productivity

Claude Code, OpenAI Codex, Augment Code, Microsoft Copilot; AWS Bedrock, Amazon SageMaker; Model Context Protocol (MCP), agent and skill definition, catalog design, evaluation harnesses, adoption and health metrics

Certification

Terraform Associate

Hashicorp • 2020

Programming with Python

Codecademy • 2018

CCNA Routing & Switching

Cisco • 2015

Education

Columbia University

B.S., Electrical Engineering — Concentration in Network Engineering • 2012 — 2014

Providence College

B.A., Pre-Engineering (3-2 Combined Program) • 2009 — 2012