Building HIPAA-compliant AWS Landing Zones at scale.
13+ years securing, modernizing, and automating clinical infrastructure.
Multi-cloud architecture with deep specialization in healthcare compliance, IaC, and enterprise-scale migrations.
Real-world infrastructure and AI solutions built across healthcare, cloud cost management, and serverless platforms.
Open-source Model Context Protocol server that turns Claude, GitHub Copilot, Cursor, or any of 7 MCP-compatible AI clients into a multi-cloud cost analyst across AWS, Azure, GCP, and OCI. Compares compute, storage, object storage, managed Postgres, and egress pricing — and surfaces OCI's 10 TB free egress tier (~12× cheaper than hyperscalers at 50 TB/month). 14 tools including a v0.6 FinOps decision suite — migration assessment with payback math, RI / Savings Plan / CUD break-even, 3-year TCO with growth modeling, and egress arbitrage — that produce real recommendations in one tool call. One-line install auto-configures every detected AI client. Listed on the Official MCP Registry, Glama, and PyPI.
Full-stack SaaS application using AWS Bedrock and Rekognition for real-time video analysis of tennis technique. Cognito authentication, React frontend, serverless backend — production-grade architecture built as a personal passion project.
Led end-to-end AWS Landing Zone Accelerator (LZA) migration for an enterprise health system — on-premises VMware workloads to fully compliant AWS cloud. Implemented HIPAA guardrails, blue/green deployments, and cost management from day one.
Production Terraform monorepo codifying the AWS landing zone and per-application infrastructure for a phased healthcare migration — clinical and enterprise applications moved in sequenced waves, in a PHI-scoped environment under patient-safety-grade change control. 40+ deployable stacks built on a compact set of reusable first-party modules, deployed across multiple AWS accounts.
The engineering core is module consolidation: a single dynamic ec2_unified module serves both Linux and Windows workloads with AMI/volume presets, IMDSv2 enforced, EBS encryption, and compliance tagging on by default — alongside standardized Multi-AZ RDS SQL Server with AD-join and KMS, SSM-driven domain-join automation, and centralized tag governance.
Safety came from the state and provider design: per-wave, per-app remote state keys isolate blast radius to a single stack, and a Terraform check block asserts the authenticated account ID matches the intended target before any plan or apply — making a cross-account misfire structurally impossible rather than merely unlikely. Migration pattern was classified per application (replication-based lift vs. vendor-installed fresh build), with DMS, MGN, and RDS runbooks validated offline before execution, cross-region AWS Backup DR plans, and Trivy scanning in the supply chain.
The application portfolio spanned clinical, diagnostic, and facilities systems, each with its own vendor support constraints and migration pattern. Client identity, environment details, and application inventory withheld under engagement confidentiality.
A vendor-neutral reference architecture for governed network automation in regulated environments — Ansible, Rundeck, Git, and a source of truth, wired so that audit evidence is a byproduct of normal operation rather than a pre-assessment scramble. Includes a full control mapping to the HIPAA Security Rule, SOC 2 Trust Services Criteria, and HITRUST CSF, plus AWS and Azure Well-Architected alignment, an 8-layer defense-in-depth model, a phased maturity path, and runnable Ansible, Jinja2, and CI examples.
A migration reference architecture for moving a regulated healthcare estate from on-premises to Azure — compute, storage, databases, and disaster recovery — written as a service-by-service translation from AWS. Covers Azure Migrate vs. Site Recovery tool selection, dependency-derived wave sequencing, the storage decision that carries the most risk (imaging sized on IOPS, not capacity), the three SQL targets rather than the usual two, hub-spoke landing zone topology with Policy inheritance, and the platform differences that cost AWS practitioners time.
A reference architecture and playbook — target-state design and decision points, not a case study of a specific engagement.
Led 85+ enterprise client migrations across AWS-to-AWS account moves and AWS-to-OCI cross-cloud transitions. Combined Terraform, PowerShell, and Bash with GitHub Actions pipelines to automate inventory, dependency mapping, and minimum-downtime cutovers — heavy emphasis on regulated and healthcare workloads.
Conversational AI chatbot powered by AWS SageMaker that answers natural-language questions about cloud spend. Integrates Cost Explorer APIs, giving engineers real-time cost intelligence without leaving their workflow.
Personal tool that maps equivalent services across AWS and Azure and generates side-by-side cost comparisons — built as a home project to learn multi-cloud cost modeling and FinOps fundamentals.
Personal serverless REST API built with FastAPI on Lambda, fronted by API Gateway — Terraform-managed with a GitHub Actions CI/CD pipeline. Built as a home project to explore serverless API patterns and IaC practices.
Experimental workspace for LLM fine-tuning, prompt engineering, and RAG pipeline development. Includes evaluation harnesses, cost-aware inference patterns, and healthcare-domain prompt templates.
Azure Landing Zone built in Terraform modules — management groups, policies, hub-spoke networking, and identity configuration. Built while studying the Microsoft Cloud Adoption Framework + Landing Zone reference architecture; mirrors AWS LZ patterns for consistent multi-cloud governance.
Reusable Terraform module that spins up a CloudFront distribution with S3 origin, WAF, custom headers, and configurable cache behaviors — built as a personal IaC composition exercise.
Production API Gateway with custom domain, Lambda authorizers, usage plans, and WAF integration. Terraform-managed with blue/green deployment support and full observability via CloudWatch.
Infrastructure-as-Code for Microsoft Fabric workspace provisioning — automating data lake, Lakehouse, and pipeline resources across healthcare analytics environments with governance controls.
A live walkthrough of the multi-account architecture I architect for healthcare clients. Click any service to learn more.
13+ years progressively owning larger-scale infrastructure — from hospital sysadmin to enterprise cloud architect.
Verified credentials across AWS, Azure, and FinOps — with two AWS professional-tier exams actively in progress.
Amazon Web Services · Sep 2025–Sep 2028
Amazon Web Services · Jan 2026
Amazon Web Services
Amazon Web Services
5 questions. Find out where your organization stands — and what it takes to reach the next level.
Live data from GitHub — real repos, real contributions.
Live operational health of the major cloud platforms Ali architects on.
Status fetched live from each provider's public API · Click any card for the full health dashboard
Looking for Senior Cloud Architect, Principal Engineer, or Healthcare Cloud Lead roles. Also open to advisory and consulting engagements.
AI Assistant