Back to Projects
SC Dept. of Health & Human ServicesFeb 2018 – Present

AWS Cloud Security for Healthcare

Senior Cloud Security Architect and DevOps Technical Lead managing the full AWS ecosystem including security, monitoring, development tools, and AI-powered services for state healthcare systems serving millions of citizens.

AWSOktaNISTIAMDevSecOps

!The Challenge

The state healthcare system relied on legacy ADFS infrastructure with fragmented identity management across multiple applications. Security posture was inconsistent, and the system lacked compliance with NIST and MARS-E frameworks required for handling protected health information (PHI). Development teams needed modern tooling and AI-assisted workflows to accelerate delivery while maintaining security.

The Solution

Designed and implemented a comprehensive AWS cloud security architecture with Zero Trust principles. Led the migration from ADFS to Okta for centralized identity management. Implemented full-spectrum AWS security and monitoring services. Adopted AWS developer tools including Kiro, Amazon Q, and AWS Connect for enhanced productivity and customer engagement. Established Policy-as-Code with Terraform Sentinel for infrastructure compliance automation.

Key Results

40% improvement in authentication efficiency after ADFS to Okta migration
70% AWS cost reduction — brought monthly spend from $1M+ down to $200K–$300K
Leading 14-member DevOps team as Technical Lead
30% overall security posture improvement measured via Security Hub scores
Full NIST Cybersecurity Framework and MARS-E compliance achieved
Zero Trust architecture adopted across cloud and on-prem environments
Reduced mean time to detect (MTTD) security incidents by 60%
Automated compliance reporting — reduced audit prep from weeks to hours
Developer productivity increased with Amazon Q and Kiro AI-assisted development
Customer engagement streamlined via AWS Connect contact center

Technologies Used

AWS Security HubGuardDutyAWS WAFAWS ShieldAWS Firewall ManagerAmazon InspectorAWS MacieIAM Identity CenterAWS KMSAWS Secrets ManagerAWS Certificate ManagerAWS CloudHSMAmazon DetectiveAWS Audit ManagerCloudWatchCloudTrailAWS ConfigAWS X-RayAmazon EventBridgeAWS Health DashboardAWS Trusted AdvisorAWS CodePipelineAWS CodeBuildAWS CodeDeployAWS CodeCommitAmazon ECRAWS CDKAWS CloudFormationKiroAmazon QAmazon BedrockAWS ConnectAmazon SESAmazon SNSAWS EKSAWS ECSAWS LambdaAmazon VPCAWS Transit GatewayTerraformOktaZero TrustNIST CSFMARS-E

Interested in similar security solutions?

Get in Touch