Viz.ai
DevSecOps Engineer
Aug 2025 – Present | Viz.ai
-
• Built and rolled out a company-wide JIT access platform across RDS, S3, DynamoDB, Redash, and OpenSearch. Replaced standing privileges with time-bound, audited access and an Emergency Access tier.
• Implemented IAM authentication for production DB logins; implemented a real break-glass user, rotated master credentials, and locked them from developer teams.
• Implemented a company-wide WAF with geolocation restrictions, L7 DDoS protection, and threat intelligence; rolled out in count mode and tuned over two weeks across QA and Production.
• Rotated 321 GCP/customer access keys, reduced AWS Lambda deprecated-runtime functions 32 → 0, and cut the Wiz findings backlog by 75%.
• Enforced Amazon Bedrock Guardrails across AWS accounts; moved Mobile and QA behind the company network with VPN-authenticated GitHub Actions, avoiding ~$350/month in macOS CI cost.
• Decommissioned a legacy healthcare tenant, purged the related external attack surface, and stripped standing S3/DynamoDB permissions from SSO roles.