SSuraj Sah
01What I Do

What I own, end to end.

Four areas of accountability — from platform architecture to audit-ready compliance.

01

Cloud & Platform Architecture

Multi-cloud architecture across AWS, Azure and GCP — landing zones, network design, and internal platforms that let teams ship without fighting infrastructure.

AWS · Azure · GCP · EKS / GKE / AKS · Infrastructure architecture · Platform engineering

02

Kubernetes & Cloud Native

Production Kubernetes from scratch and at scale — cluster architecture, service mesh, autoscaling, backup strategy and day-2 reliability operations.

Kubernetes · Helm · ArgoCD · GitOps · Istio · Karpenter · Velero · Reliability

03

Infrastructure Automation

Everything as code — Terraform-managed cloud estates, version-controlled environments, and CI/CD pipelines with security gates built in, not bolted on.

Terraform · Terraform Cloud · GitHub Actions · CI/CD · Ansible · Environment automation

04

Security & Compliance

SOC 2 Type II and PCI DSS programs end to end — controls, continuous monitoring, endpoint posture and compliance automation that survives audits without heroics.

SOC 2 · PCI DSS · CIS Benchmarks · Wazuh · Trivy · OWASP ZAP · GuardDuty · Macie · FleetDM

02How I Think

Infrastructure should disappear into the platform.

Reliable infrastructure should enable developers rather than become something they constantly manage. The measure of a good platform is how little a team has to think about it — a pull request goes in, and a secure, observable, production-grade deployment comes out.

Everything between those two points — pipelines, policy, provisioning, rollout, monitoring — is the platform’s job. That’s what I build.

The path a pull request takes

1

Developer opens a pull request

2

CI runs — build, tests, security scans

3

Merge — ArgoCD syncs the change

4

Rollout to Kubernetes

5

Observed — metrics, alerts, compliance checks

6

Running in production on AWS / Azure / GCP

Full Capability Breakdown

Cloud

  • AWS
  • Azure
  • GCP

Containers

  • Kubernetes
  • EKS
  • GKE
  • AKS
  • Helm
  • Istio
  • Karpenter

Infrastructure as Code

  • Terraform
  • Ansible

Delivery

  • GitHub Actions
  • ArgoCD
  • GitOps
  • Drone CI

Observability

  • Prometheus
  • Grafana
  • Kiali
  • EFK Stack
  • New Relic
  • Opsgenie

Security & Compliance

  • Wazuh
  • FleetDM
  • Trivy
  • OWASP ZAP
  • AWS GuardDuty
  • AWS Macie
  • SonarQube
  • SOC 2
  • PCI DSS
  • CIS Benchmarks

Have an infrastructure problem that fits this?

See it applied in real case studies