Cloud Security & Infrastructure Engineer

Tymur
Chmeruk.

15+ years owning enterprise infrastructure security across AWS, financial, and hybrid cloud environments - NIST · FISMA · PCI-DSS.

15+

Years Experience

F100

Enterprise Clients

3+

Compliance Frameworks

Eligible

Clearance Status
Approach
01 // Secure by Default

Security is architecture, not afterthought.

Controls are embedded at the infrastructure layer - in IaC, in CI/CD policy gates, in network segmentation. Not bolted on post-deployment.

02 // Telemetry First

If you can't measure it, you can't protect it.

Operational visibility is a security control. Deep telemetry, custom alerting, and structured observability are non-negotiable in every environment I own. Telemetry must be useful, owned, and economically sane - not just collected because a vendor agent made it easy.

03 // Compliance as a Floor

Frameworks are the minimum, not the goal.

NIST, FISMA, and PCI-DSS define the baseline. Strong security posture exceeds them - through Zero Trust design, least privilege enforcement, and continuous hardening.

Observability Cost Reduction

Observability Cost Reduction

Datadog is expensive when every log, metric, trace, and health check is treated as premium telemetry.

I help infrastructure teams separate critical observability from low-value noise - keeping Datadog for APM, SLOs, incidents, traces, and application visibility while moving static infrastructure, noisy logs, and bulk metrics to Zabbix, Grafana, Prometheus, Loki, OpenSearch, or object storage.

Read the Datadog cost reduction guide
Core Philosophy

Not all telemetry is created equal.

The cleanest cost optimization is not replacing every tool. It is routing the right signal to the right system: Datadog for critical application visibility, Zabbix/Grafana for infrastructure, and lower-cost storage for bulk telemetry.

Work
Jan 2023 – Present

Lead Cloud Infrastructure & Security Engineer

Independent Consulting & Contract Engagements // Silver Spring, MD

  • Cut mean-time-to-detect by 40% — replaced threshold noise with actionable SolarWinds and Zabbix alerting logic across hybrid AWS environments.
  • Eliminated configuration drift across multiple AWS accounts by standardizing Terraform + GitHub Actions as the IaC baseline, enforcing secure-by-default infrastructure from the first deploy.
  • Shifted policy enforcement left — Checkov integrated into CI/CD pipelines blocks non-compliant infrastructure before it reaches production, removing security review as a post-deployment bottleneck.
  • Owns full vulnerability remediation lifecycle from Tenable Nessus detection through SCCM patch execution, maintaining continuous NIST SP 800-53 Rev 5 alignment across enterprise environments.
  • Provides hybrid cloud security architecture and compliance advisory for clients operating under FISMA and NIST frameworks.
Jun 2015 – Dec 2022

Cloud Operations & Security Manager

Magento, an Adobe Company (B2B Contractor) // Global

  • Sustained 99.9%+ uptime across Adobe Commerce infrastructure for Fortune 100 US retail clients — owned 24/7 operational security and reliability including peak traffic events.
  • Neutralized Layer 7 DDoS threats across PCI-DSS-scoped commerce infrastructure — architected Fastly CDN and WAF stack that absorbed attack traffic without commerce platform impact.
  • Owned AWS ALB and network traffic architecture for enterprise-scale order processing — tuned configurations to sustain peak load without performance degradation.
  • Served as org-wide SolarWinds Orion SME — designed monitoring architecture, alerting logic, and dashboards used by global operations teams; delivered capacity planning data directly to leadership.
  • Drove ITIL-aligned change management and SLA compliance via ServiceNow across 7+ years of global infrastructure operations.
Aug 2010 – May 2015

Enterprise Infrastructure Security Engineer

EPAM Systems (Contractor for Barclays Bank) // Global

  • Operated within Barclays Bank's global investment banking division — zero-tolerance security standards, strict financial compliance, and no margin for infrastructure failure.
  • Hardened Cisco Catalyst and Nexus network infrastructure protecting trading systems — ACLs, VLAN segmentation, and port security controls across production financial infrastructure.
  • Administered enterprise-scale Active Directory, IAM, and Group Policy across global distributed environments — least-privilege access and Zero Trust controls enforced at the directory layer.
Stack
Cloud Platforms

AWS (VPC, EC2, ALB, IAM, CloudTrail, GovCloud) · Azure · Google Cloud Platform

Compliance & Governance

NIST SP 800-53 Rev 5 · RMF · FedRAMP · FISMA · PCI-DSS · ATO Support · DISA STIG · CMMC Level 2 · Zero Trust Architecture

Infrastructure as Code / DevSecOps

Terraform · GitHub Actions · CI/CD Automation · Checkov · Secure-by-Default Infrastructure

Identity & Access Management

IAM · RBAC · Active Directory · Group Policy · Least Privilege Access · OAuth 2.0 · SAML

Monitoring / SIEM / Telemetry

SolarWinds Orion · Zabbix · Splunk · NetFlow Analysis · Operational Telemetry · Alerting

Cloud & Network Security

Fastly WAF · Layer 7 DDoS Mitigation · Network Segmentation · Cisco ACLs · Secure Hybrid Connectivity

Containers & Platforms

Docker · Kubernetes

Programming & Automation

Python · Bash · PowerShell

Enterprise Security Tools

Tenable Nessus · SCCM · ServiceNow

Writing

Infrastructure Intelligence

Architect Your Scale.

Senior infrastructure and security architect based in the Baltimore–Washington Metro Area. Available for federal and commercial engagements.

tcinfra.dev © 2026 T. CHMERUK. Built with ASTRO & AWS IaC.