Cloud platform architecture · governance · modernisation

Tony Zaarour

Cloud Platform Architect / Senior Platform Engineer with hands-on experience designing, governing, and modernising AWS platforms in regulated and enterprise environments.

Best fit: messy estates that need clearer guardrails, stronger operating boundaries, better automation, and less platform theatre.

Selected impact

What changes when I am useful

Governance

Improved compliance execution across a regulated multi-account AWS estate through guardrails, reporting, and control redesign.

Cost

Delivered material annual AWS savings through commitment optimisation, workload modernisation, and lifecycle control.

Modernisation

Re-architected resource-heavy workloads into event-driven ECS task patterns to improve isolation, scaling, and maintainability.

Reliability

Reduced critical website dropouts for Australian Museum from roughly 20 per day to zero.

Core strengths

Where I tend to add value fastest

AWS platform architecture and multi-account governance
Compliance, audit readiness, and security controls
Infrastructure as code and platform automation
Event-driven workload modernisation
CI/CD, observability, and operational tooling
Cost optimisation and utilisation management
Documentation, enablement, and operational handover
Practical architecture grounded in delivery reality

Experience

Recent roles

Squiz

Senior DevOps Engineer

May 2024 – Present
  • Own the internal AWS platform across a complex multi-account environment supporting shared operational workloads.
  • Act as the de facto platform architect for major initiatives across governance, compliance, workload modernisation, and cloud operations.
  • Built reporting, alerting, and guardrail capabilities to improve audit readiness and compliance execution.
  • Improved platform governance through control redesign and organisation-wide guardrails.
  • Modernised long-running workloads into event-driven ECS task patterns and reduced reliance on oversized always-on compute.
  • Managed commitment optimisation and cloud efficiency work that delivered material annual savings.
  • Led the AWS side of migration from data centre to AWS, including documentation and team enablement.

Versent

DevOps Engineer

Mar 2021 – Apr 2024
  • Delivered cloud infrastructure, automation, and operational improvements for enterprise client environments.
  • Built reusable deployment tooling, reporting modules, alarm automation, and private API monitoring capabilities.
  • Designed and implemented a serverless anti-virus solution using Trend Cloud One.
  • Led migration from legacy email infrastructure to AWS SES with stronger security and operational controls.
  • Built CI/CD pipelines using GitHub Actions and ECS runners with OIDC-based short-lived AWS access.

AXE Group

Junior DevSecOps Engineer

Jan 2020 – Feb 2021
  • Automated deployments, Linux configuration, and security-related operational tasks.
  • Maintained Ansible playbooks and environment management workflows.
  • Built Shell, Bash, and PowerShell tooling for deployment and operational support.

OpenMRS

Junior DevOps Engineer

Apr 2019 – Feb 2020
  • Supported infrastructure and platform operations for the OpenMRS open-source community.

Technology

Tools and platforms I work in

Cloud

AWS, AWS Organizations, Control Tower, IAM Identity Center / SSO

Infrastructure as code

Terraform, AWS CDK, CloudFormation

Containers and compute

ECS, Fargate, Lambda, Step Functions, EC2, SSM, Docker

CI/CD and automation

GitLab CI, GitHub Actions, AWS CodePipeline, Python, Bash, JavaScript, TypeScript

Security and observability

Security Hub, AWS Config, GuardDuty, Inspector, CloudWatch, Dynatrace, Sumo Logic, Cloudflare, AWS WAF, Vanta