Harneet Grewal
Senior Cloud Engineer

Hi, I'm Harneet
I build & automate cloud at scale.

Senior Cloud Engineer with 10+ years building resilient infrastructure on AWS. Specializing in Terraform, ECS, CI/CD pipelines, and AI/ML platform engineering.

About Me

Senior Cloud Engineer

I'm a Senior Cloud Engineer with 10+ years of experience building and managing cloud infrastructure. I currently work at Finch AI, leading a team of engineers and architecting solutions across AWS for organizations in AI, finance, and healthcare.

My focus spans infrastructure as code with Terraform, container orchestration on ECS, CI/CD pipeline design, and AI/ML platform engineering with SageMaker. I believe in automation-first approaches and treating infrastructure as software.

I hold a B.Sc. in Software Development & Security from the University of Maryland and carry certifications in AWS, Kubernetes, and security — including an active DOD security clearance.

10+
Years Experience
6
Environments Managed
50+
Services Managed
99.99%
Uptime Achieved

Cloud & DevOps

Designing highly available infrastructure on AWS with Terraform, ECS, and CI/CD pipelines across multi-account environments.

AI/ML Platforms

Building and maintaining SageMaker-based ML platforms, enabling data science teams to train and deploy models at scale.

Security & Compliance

Implementing security controls, DOD compliance, AWS Config rules, and SCPs for regulated industries including healthcare and finance.

Skills & Expertise

Tools & Technologies

AWS
Terraform
Docker
Kubernetes
Ansible
GitHub Actions
Jenkins
Python
Linux
Git
Prometheus
Grafana
Helm
Datadog

Cloud Platforms

  • AWS (EC2, ECS, EKS, Lambda)
  • S3 / CloudFront / Route 53
  • RDS / DynamoDB / Aurora
  • VPC / ELB / API Gateway
  • IAM / KMS / Secrets Manager
  • AWS Organizations / Control Tower
  • SageMaker / Bedrock

Infrastructure as Code

  • Terraform
  • AWS CDK
  • AWS CloudFormation
  • Ansible
  • Packer

Containers & Orchestration

  • Docker
  • Kubernetes
  • Amazon ECS / Fargate
  • Amazon EKS
  • Docker Compose

CI/CD & Automation

  • AWS CodePipeline / CodeBuild
  • GitHub Actions
  • GitLab CI
  • Jenkins
  • ArgoCD

Monitoring & Observability

  • CloudWatch / CloudTrail
  • Datadog
  • Prometheus / Grafana
  • ELK Stack
  • PagerDuty

Languages & Scripting

  • Python
  • Bash / Shell
  • PowerShell
  • TypeScript
  • YAML / JSON / HCL

Certifications & Credentials

AIF

AWS AI Practitioner

SAA

AWS Solutions Architect – Associate

KCNA

Kubernetes & Cloud Native Associate

Sec+

CompTIA Security+ CE

🔒 DOD Security Clearance

Experience

Where I've Worked

Senior Cloud Engineer

Finch AI

2019 – Present
  • Converted manually created infrastructure partially built with CloudFormation into Terraform for 6 environments, including 5 containerized services deployed on ECS along with supporting resources like pipelines.
  • Built pipelines with IaC frameworks (AWS CDK, Terraform) to automate container image building, testing, and deployment used by six microservices, enhancing reliability and eliminating manual processes.
  • Consolidated 20 CodeCommit repositories, pipelines, and CodeBuild projects across various AWS accounts into a single pipeline for streamlined cross-account deployment.
  • Migrated 200+ Bitbucket repositories to GitLab, then to CodeCommit for cost optimization using Python and Bash scripts via platform APIs.
  • Remediated Qualys findings across AWS infrastructure and Linux OS by scripting changes via Python, Bash, and Terraform modules in 5 AWS accounts — including 150+ CodeBuild project upgrades and 400 Lambda function migrations to best practices.
  • Setup Jenkins pipeline to build Docker images, later migrated to AWS-native CI/CD, eliminating maintenance overhead and improving integration with AWS services.

Tech Lead / AI Platform Engineer

Cognitive Care (Consulting)

2022
  • Led a team of 5 engineers.
  • Implemented a highly available VPC and VPN, enhancing security posture by enforcing password policy, MFA, and IAM role adoption.
  • Researched and recommended Amazon SageMaker as the optimal ML solution based on data scientist requirements, driving adoption of advanced AI/ML tools.
  • Architected and deployed AWS Organizations to ensure each environment operated within its own AWS account for security and streamlined management.
  • Set up secure development environments on EC2 for six data scientists within a private subnet accessible exclusively via VPN, using Ansible.
  • Deployed and configured SageMaker notebook instances with custom environments including specialized packages and R for data science needs.
  • Integrated AWS Single Sign-On (SSO) to simplify SageMaker access and user onboarding.

DevOps Engineer

The Common Application

2018 – 2019
  • Developed 10 custom compliance rules in Python using AWS Config and Lambda to improve security compliance, deployed via CloudFormation templates.
  • Automated golden image creation and server patching with Ansible, Packer, and CodeBuild, saving 20+ hours per month for the team.
  • Migrated from OpenVPN-AS (paid) to OpenVPN free version to save licensing costs and eliminate legal obligations.
  • Monitored production environments and troubleshot issues reported by CloudWatch, Sumologic, and Idera alerts.

Systems Engineer

Softconcept Inc. (VCE / BUMED / DOD)

2016 – 2018
  • Oversaw three projects throughout their SDLC, developing and executing UAT plans to ensure features met Vision Center of Excellence (VCE/DOD) standards.
  • Patched 10 Linux and 4 Windows operating systems hosted on Microsoft Hyper-V along with Cisco network stack every quarter to maintain security posture.
  • Tracked assets for acquisition programs, obtained renewals and quotes from vendors, and alerted acquisition specialists on upcoming procurement.
  • Created and administered SharePoint sites for 4–8 teams for collaboration with developers, testers, and clients.

NOC Technical Engineer

FactSet Research Systems

2013 – 2016
  • Monitored, identified, and resolved issues for 60,000+ application users and 8,000 internal employees.
  • Remotely assisted users with connectivity and account issues; monitored networks to maintain uptime, low latency, and zero packet loss.
  • Made and ran Ethernet and fiber cables, assembled datacenter equipment including servers, routers, and switches to expand capacity.
  • Reset Windows passwords and provided BitLocker pins via Active Directory for internal users.

Education

Academic Background

B.Sc. Software Development & Security

University of Maryland Global Campus

College Park, MD

Projects

What I've Built

Multi-Environment Terraform Platform

Converted manually created infrastructure partially built with CloudFormation into Terraform for 6 environments. Includes 5 containerized ECS services with supporting resources and pipelines.

TerraformAWS CDKECSMulti-AccountCI/CD

Cross-Account CI/CD Consolidation

Consolidated 20 CodeCommit repositories, pipelines, and CodeBuild projects across multiple AWS accounts into a single pipeline for streamlined cross-account deployment from the management account.

CodePipelineCodeBuildCodeCommitMulti-AccountTerraform

SageMaker ML Platform

Architected and deployed SageMaker notebook instances with custom environments including specialized packages and R for data science needs. Integrated AWS SSO for streamlined data scientist onboarding and access management.

SageMakerAWS SSOAI/MLPythonR

AWS Organizations & Multi-Account Strategy

Designed and deployed AWS Organizations to ensure each environment operated within its own AWS account for security isolation and streamlined management. Led a team of 5 engineers to implement the architecture.

AWS OrganizationsMulti-AccountIAMSecurityLeadership

Secure VPC & VPN Infrastructure

Implemented a highly available VPC and VPN, enhancing security posture by enforcing password policy, MFA, and IAM role adoption. Set up secure EC2 dev environments in private subnets for 6 data scientists accessible exclusively via VPN using Ansible.

VPCVPNAnsibleEC2MFAIAM

200+ Repository Migration

Migrated 200+ Bitbucket repositories to GitLab, then to AWS CodeCommit for cost optimization. Built automated migration tooling using Python and Bash scripts leveraging platform APIs.

CodeCommitGitLabBitbucketPythonBash

Security Remediation at Scale

Remediated Qualys findings across 5 AWS accounts by scripting fixes via Python, Bash, and Terraform modules. Upgraded 150+ CodeBuild projects to latest base images and migrated 400 Lambda functions to best practices.

QualysLambdaCodeBuildTerraformPython

AWS Config Compliance Engine

Developed 10 custom compliance rules in Python using AWS Config and Lambda to enforce security standards. Automated golden image creation and patching with Ansible, Packer, and CodeBuild, saving 20+ hours/month.

AWS ConfigLambdaAnsiblePackerCloudFormation

Contact

Let's Connect

I'm always open to discussing cloud architecture, new opportunities, or interesting projects. Feel free to reach out!

Say Hello

📍 Alexandria, VA