Available for new opportunities

George
Koufie

Cloud Infrastructure Engineer

I design, build, and automate AWS cloud infrastructure — Terraform, CI/CD pipelines, event-driven automation, and security tooling — bringing a security-first, automation-driven approach to complex infrastructure problems.

3+
Years Exp.
10
Certifications
7
Projects Built

Projects That Shipped

01
Networking & Infrastructure as Code
Hybrid Cloud Network Architecture

A cloud-native version of secure facility-to-facility tunneling I've done professionally — a multi-VPC network joined through a Transit Gateway hub with a real Site-to-Site IPsec VPN. Getting from a clean deploy to working traffic took fixing 9 real bugs, including two byte-identical IAM trust policies behaving differently — diagnosed via CloudTrail's raw denial event. Verified end-to-end: 0% packet loss on the first attempt after a full destroy/reapply.

Terraform Transit Gateway Site-to-Site VPN GitHub Actions
View Project →
02
Serverless / Event-Driven
Serverless Link Shortener API

A fully serverless link shortener that costs $0 at rest — nothing runs between requests. The obvious approach (check if a code exists, then write it) has a race condition under concurrent requests; solved it with DynamoDB's atomic conditional write instead, plus a Lambda IAM role scoped to exactly three actions on one table.

AWS Lambda API Gateway DynamoDB
View Project →
03
DevSecOps
DevSecOps CI/CD Pipeline

A 6-stage GitHub Actions pipeline (lint → test → Semgrep SAST → Trivy container scan → ECR → EKS) that enforces a hard quality gate: critical vulnerabilities block the deploy instead of reaching production. Shifts security left so scanning happens before a bad image ever reaches Kubernetes, not after.

GitHub Actions Docker Trivy Semgrep Kubernetes
View Project →
04
Security Automation
AWS Security Baseline Audit Tool

A Python CLI covering 12 security checks across IAM, S3, EC2, CloudTrail, and RDS — built to understand how tools like Prowler work internally, not to replace them. Every check is tested against mocked AWS calls (31 tests, no real account needed), yet pointed at my own real AWS account it found genuine problems on the first run: security groups with SSH/RDP open to the internet, no active multi-region CloudTrail trail, and a 415-day-old access key.

Python boto3
View Project →
05
AI-Assisted Engineering
AI-Augmented Cloud Development

Used Claude Code as an AI engineering assistant to accelerate solution design, implementation, debugging, documentation, and infrastructure troubleshooting across multiple AWS projects — validating all generated code before deployment.

Claude Code AWS
View Project →
06
Infrastructure as Code
Enterprise AWS Landing Zone (NovaRetail)

NovaRetail's developers were manually provisioning AWS resources — inconsistent networking, weak governance, public-exposure risk, no audit visibility. Built a Terraform Landing Zone (3-tier VPC, centralized CloudTrail logging, GuardDuty, Security Hub, KMS-encrypted logs, least-privilege audit role) plus Python audit scripts for security groups, S3, and cost — reducing environment setup from hours to minutes while standardizing security controls.

Terraform GitHub Actions Python
View Project →
07
Security Automation
Event-Driven Security Guardrail

Extends my Security Baseline Audit tool from on-demand scanning into continuous enforcement: EventBridge catches risky changes (open security groups, public S3 buckets) in real time and Lambda remediates them automatically. First deploy looked correct but silently did nothing — CloudTrail's always-on Event History doesn't feed EventBridge, only an actual Trail resource does. Verified both directions: in-scope resources get auto-remediated, and IAM denies remediation on anything out of scope, confirmed by testing an untagged security group and finding the open rule still there.

EventBridge Lambda CloudTrail DynamoDB Terraform
View Project →

Building cloud systems that never sleep

I'm a Cloud Infrastructure Engineer with 3 years of professional IT/systems administration experience, including hands-on project work designing, building, and automating AWS cloud infrastructure. I'm AWS Certified Solutions Architect – Associate and Microsoft Certified Azure Administrator, with a B.S. in Cloud Computing.

I work with Terraform, Python, GitHub Actions, Docker, Kubernetes, and IAM to build reproducible AWS infrastructure, CI/CD pipelines, event-driven automation, and security tooling — applying systematic root-cause analysis to complex infrastructure issues. I'm also the founder of CloudCapeCoast and an AWS Community Builder for Networking & Content Delivery.

Get in touch →
name:       "George Koufie"
role:       "Cloud Infrastructure Eng."
location:   "Jacksonville, NC"
status:     open_to_work
clouds:     ["AWS", "Azure"]
certs:      ["AWS-SAA", "AWS-CCP", "AZ-104"]
founder:    "CloudCapeCoast"
coffee:     true
 

My Toolbox

☁ Cloud Platforms
AWS VPC AWS EC2 AWS S3 AWS Lambda API Gateway DynamoDB EventBridge AWS IAM Transit Gateway Site-to-Site VPN ECS Fargate Aurora AWS EKS CloudWatch CloudTrail Systems Manager
⚙ Infrastructure as Code
Terraform Modular Design Remote State CI-Driven Plan/Apply
🐳 CI/CD & Containers
GitHub Actions Jenkins Docker Kubernetes SonarQube Trivy Semgrep
🔒 Networking & Security
Hub-and-Spoke VPC Site-to-Site VPN/IPsec Security Groups NACLs IAM Least-Privilege OIDC Federation
💻 Linux & Scripting
Linux Administration iptables systemd journalctl tcpdump Bash Python
🤖 AI-Augmented Development
Claude Code Agentic Deployment Prompt Engineering

Education & Certifications

Education
May 2025
B.S. Cloud Computing
Western Governors University — Salt Lake City, UT
May 2023
A.S. Information Technology
James Sprunt Community College — Kenansville, NC
Nov 2026
AWS re/Start Training
Per Scholas — Jacksonville, NC
Certifications
AWS Certified Solutions Architect – Associate AWS Certified Cloud Practitioner Microsoft Certified: Azure Administrator (AZ-104) Microsoft Certified: Azure Fundamentals (AZ-900) CompTIA Cloud+ CompTIA Security+ CompTIA Network+ CompTIA A+ CompTIA Project+ LPI Linux Essentials
Download Full Resume PDF — Updated 2026

Let's Build Something Together

Have an infrastructure challenge, an open role, or want to collaborate? I'd love to hear from you.