Mohannad Emhemed

MOHANNAD EMHEMED

I am a

Cloud Infrastructure Engineer | Hybrid Connectivity | Automation & Security

Manchester, United Kingdom

mohannad.emhemed@gmail.com

+44 7737 103 208

About Me

AWS Golden Jacket holder, CNCF Kubestronaut, and Cloud Infrastructure & DevOps Engineer delivering governed multi-account platforms, resilient hybrid connectivity, and automated operations across AWS, Azure, and on-premises estates.

Recent work includes rolling out AWS IAM Identity Center with Microsoft Entra ID, scaling AWS Control Tower landing zones, automating tag compliance with Config and Step Functions, and securing traffic through Transit Gateway, Network Firewall, and Sentinel integrations to keep regulated workloads available and auditable.

Professional Experience

09/2024 – Present

Cloud Infrastructure Engineer

Northern Gas Networks - Leeds, England

  • Led design and implementation of AWS Control Tower Landing Zone across 12+ AWS accounts, integrating with existing AWS Organization to establish governance, OU structure, security baselines, guardrails, and account-provisioning standards
  • Architected and delivered a serverless IP blocking platform (Lambda, API Gateway, DynamoDB, CloudFront, SQS, SNS, Route 53, ACM) with dual authentication (Cognito + Entra ID), RBAC, and Slack/Teams notifications; replaced a manual ticket process and cut block-list update time from days to minutes
  • Delivered $40K+ in cost savings by diagnosing a recurring AWS Config Recorder issue and implementing cost anomaly detection, alerting, and ongoing FinOps optimisation
  • Designed multi-AZ/multi-region high availability with failover/failback and centralized network egress across 11+ VPCs and 7+ accounts using Transit Gateway and AWS Network Firewall, improving resilience and network traffic visibility
  • Replaced standing administrator access with audited just-in-time elevation using the AWS TEAM solution on IAM Identity Center: eligibility and approver policies, time-bound sessions, an on-call break-glass path, and real-time alerting on emergency use via CloudTrail, Lambda, and SNS
  • Strengthened regulatory compliance (PCI, ISO 27001, SOC 2) through workload segmentation and automated tag compliance across thousands of resources using AWS Config, Lambda, Step Functions, SSM Automation Documents, EventBridge, and SNS
  • Built and improved CI/CD pipelines (GitLab CI/CD, Terraform, AWS CodePipeline) for infrastructure delivery, spearheading migration from AWS CodeCommit to GitLab and CloudFormation to Terraform; supported application teams' Azure DevOps pipelines
  • Delivered enterprise SSO via AWS IAM Identity Center with Microsoft Entra ID (SAML 2.0/SCIM) for 74+ users, migrating from decentralized per-account IAM users to centralized identity governance
  • Engineered hybrid DNS architecture integrating Active Directory Domain Controllers with AWS Route 53, including VPC DHCP options configuration for seamless on-premises and cloud DNS resolution
  • Orchestrated migration of DNS domains from third-party registrars to AWS Route 53, consolidating DNS management and improving reliability
  • Designed and implemented centralized private connectivity using VPC Interface Endpoints across multiple VPCs, regions, and accounts, enhancing security and reducing data transfer costs
  • Managed and optimized Site-to-Site VPN and AWS Direct Connect connections, ensuring reliable hybrid cloud connectivity
  • Integrated Microsoft Sentinel with AWS for centralized SIEM/SOC monitoring, log aggregation, and security event management
  • Hardened estate security posture: migrated AWS WAF from Classic (v1) to v2, removed root user credentials from all accounts except the management account, upgraded ELB security policies, and managed Security Hub (CSPM) and Trusted Advisor
  • Operated managed and self-managed databases (RDS Aurora, PostgreSQL, DynamoDB, EC2-hosted): deployment, backup, replication, parameter tuning, and monitoring
  • Deployed and managed Azure Monitoring Agent (AMA) with Azure Arc, Analytics Workspace, and Data Collection Rules across AWS and on-premises infrastructure, and managed Azure environment lifecycle and cross-cloud access
  • Supported Microsoft 365 administration alongside specialist teams: Entra ID (access, RBAC, permissions), Exchange, SharePoint, Power Platform environments, and Purview data classification roles/permissions across several thousand users
  • Drove adoption of modern tooling and AI-augmented engineering (Amazon Q, Kiro, Microsoft 365 Copilot, Terraform, IaC best practices) across the infrastructure team through mentoring and knowledge-sharing
  • Won 1st place at the AWS Generative AI Unicorn Party GameDay (Manchester, 2025), representing Northern Gas Networks on an AI agents and Amazon Bedrock challenge
  • Participate in the production on-call rota for AWS and networking incident response and escalation
05/2023 – 09/2024

Cloud Infrastructure Engineer

ConnexAI - Manchester, England

  • Designed, deployed, and maintained highly available, fault-tolerant, and scalable cloud infrastructure solutions on AWS
  • Implemented and automated CI/CD pipelines using GitLab, Jenkins, Terraform, and CloudFormation for Infrastructure as Code (IaC)
  • Automated tasks using Python, Bash, and PowerShell across cloud infrastructure, network administration, and server management
  • Configured and managed Azure, GCP and AWS services: VPC, EC2, IAM, S3, EBS, EFS, API Gateway, Lambda, CloudFront, Cognito, CloudWatch, SQS, SNS, System Manager, Config, S2S VPN, WAF, Client VPN, VPC Peering, Private Link, Control Tower, AWS Organization, SSO, NAT Gateway, and Transit Gateway
  • Performed end-to-end AWS migrations, including planning, testing, and execution
  • Administered network devices (Cisco WAPs, Routers, Switches) and configured networking protocols (EtherChannel, VLANs, VTP, NTP, BGP, OSPF, STP, RSTP, QoS, HSRP, EIGRP)
  • Managed firewalls (Cisco ASA, Sophos, Juniper, Palo Alto, FortiGate) and configured NAT rules, VPN filtering, ACLs, and S2S VPN tunnels
  • Performed Linux server administration (Ubuntu, CentOS, SUSE, Red Hat), Radius server and containerization (Docker, Kubernetes)
  • Configured and managed VOIP/Telephony solutions (SIP, WebRTC, QoS, Voice VLAN)
02/2021 – 05/2023

IT Support Associate II

Amazon - Liverpool, United Kingdom

  • Led troubleshooting efforts and ensured seamless operation of network and server infrastructure, including various Linux, Mac and Windows operating systems
  • Proactively monitored and managed infrastructure devices, encompassing Cisco, Commodity, HPE, and Juniper technologies
  • Demonstrated commitment by responding to after-hours and weekend emergencies, upholding high system availability
  • Played key role in shaping technical strategies aligned with company mission and objectives
07/2016 - 11/2020

IT Consultant

Sendian - Tripoli, Libya

  • Estimated project costs and budgeted based on client needs, supporting various Linux, Mac and Windows operating systems
  • Ensured architectural compatibility and resolved issues effectively
03/2011 - 07/2016

IT Systems Administrator

Dar Africa - Tripoli, Libya

  • Established service level agreements and planned technology upgrades
  • Managed diverse environment with various Linux distros and Windows operating systems
  • Aligned technology with business growth

Key Projects & Achievements

EKS Reference Architecture (Personal Lab)

Built reusable Terraform modules to provision production-style EKS clusters with managed node groups, ALB Ingress Controller, IRSA for service accounts, and namespace isolation. Used eksctl for rapid prototyping and Terraform for full lifecycle management. Demonstrates Kubernetes operations, AWS networking, and IaC best practices. Backed by CKA, KCNA, and Docker DCA certifications.

IP/URL Block List Management Platform

Designed and deployed a fully serverless IP blocking management system replacing a manual ticket-based process. Built with Lambda, API Gateway, DynamoDB, S3, CloudFront, SQS, SNS, Route 53, and ACM. Dual authentication (AWS Cognito + Azure Entra ID) with role-based access; Cyber Security team manages blocking requests while the SD-WAN provider polls approved entries programmatically. Reduced block-list update time from days (manual tickets/emails) to minutes (automated API polling). Includes Slack/Teams/email notifications, load testing, and full IaC deployment automation.

AWS GameDay Winner (2025): AI Agents & Bedrock

Won 1st place at the AWS Generative AI Unicorn Party GameDay (Manchester, 2025) on an AI agents and Amazon Bedrock challenge. Built and integrated AI-driven solutions using Bedrock foundation models, agents, and AWS-native services under timed competition conditions.

Cost Optimization & Anomaly Detection

Identified and resolved recurring AWS Config Recorder issue caused by informational tags from Instance Scheduler generating excessive charges. Implemented comprehensive AWS Cost Anomaly Detection with multiple notification channels, ensuring early detection of unexpected costs. Delivered over $40K in cost savings through proactive monitoring and root cause analysis.

Tag Compliance & Governance

Architected automated tag compliance monitoring and remediation system across thousands of resources using AWS Config, Lambda, Step Functions, SSM Automation Documents, and EventBridge. Managed comprehensive tag policies across EC2, ENI, EBS, RDS, DynamoDB, FSx, and EFS, with SNS-based reporting for compliance violations.

Temporary Elevated Access Management

Replaced standing administrator access across AWS accounts with audited just-in-time elevation. Deployed the AWS TEAM solution on IAM Identity Center with Entra ID as identity source (SAML/SCIM): admin access became request-based, approved and time-bound through eligibility and approver policies, while day-to-day access stayed read-only. Retained an on-call break-glass path for genuine incidents, with every emergency elevation raising a real-time alert via CloudTrail, Lambda and SNS. Customised the notification workflow and privileged-account email resolution to fit our identity model.

AWS Control Tower Implementation

Led design and deployment of AWS Control Tower Landing Zone across 12+ AWS accounts, integrating with existing AWS Organization. Established standardized security baselines, guardrails, and account provisioning workflows for enterprise-scale governance.

Centralized Private Connectivity

Designed and implemented VPC Interface Endpoints architecture across multiple VPCs, regions, and AWS accounts. Enabled secure, private connectivity to AWS services while reducing data transfer costs and improving security posture.

Hybrid DNS Architecture

Engineered hybrid DNS solution integrating on-premises Active Directory Domain Controllers with AWS Route 53. Configured VPC DHCP options and AD instances for seamless DNS resolution across hybrid infrastructure.

Centralized Network Security

Led implementation of centralized network egress across 11+ VPCs and 7+ accounts using Transit Gateway and AWS Network Firewall. Enhanced security visibility, traffic inspection, and threat prevention across multi-account AWS environment.

Enterprise SSO Integration

Designed and implemented AWS SSO integration with Microsoft Entra ID for 74+ users using SAML 2.0 and SCIM protocols. Enabled automated user provisioning, centralized access management, and enhanced security compliance.

IaC Modernization

Spearheaded migration from AWS CodeCommit to GitLab and CloudFormation to Terraform. Modernized infrastructure-as-code practices, improved deployment workflows, and enhanced team collaboration.

RDS Update Notification System

Developed automated notification system for RDS instance updates using EventBridge, Lambda, and SNS. Enabled proactive database maintenance planning and reduced unplanned downtime.

Multi-Cloud SIEM Integration

Led Microsoft Sentinel integration with AWS for centralized log aggregation and security monitoring. Implemented SOC alerts and automated incident response across multi-cloud environment.

DNS Consolidation

Orchestrated migration of DNS domains from third-party registrars to AWS Route 53. Consolidated DNS management, improved reliability, and reduced operational complexity.

Hybrid Connectivity Management

Managed and optimized Site-to-Site VPN and AWS Direct Connect connections. Ensured reliable, high-performance connectivity between on-premises data centers and AWS cloud infrastructure.

Multi-Cloud Environment Management

Managed Azure environment lifecycle, securing access between AWS instances, on-premises infrastructure, and Sentinel. Handled service provisioning, access control, and cross-cloud integration.

AWS WAF Migration & Security Enhancement

Migrated AWS WAF from Classic (v1) to v2 following retirement. Removed root credentials from all accounts except management account. Managed Security Hub CSPM and Trusted Advisor for security and cost optimization.

Azure Monitoring Integration

Deployed Azure Monitoring Agent (AMA) on AWS instances and on-premises infrastructure. Integrated with Azure Arc, Analytics Workspace, and Data Collection Rules for unified monitoring across hybrid environment.

Technical Skills

Cloud Platforms

  • AWS (primary, 13x certified)
  • Microsoft Azure (VMs, App Service, Functions, Entra ID, Sentinel)
  • Google Cloud (GKE, Compute Engine, Cloud DNS)
  • Multi-cloud & Hybrid Architecture

Networking

  • VPC Design & Implementation
  • Direct Connect & VPN
  • Cisco Routing & Switching
  • BGP, OSPF, EIGRP, HSRP
  • Network Security

Infrastructure as Code

  • Terraform
  • CloudFormation
  • Ansible
  • Python (Boto3)
  • Bash & PowerShell

Security & Compliance

  • AWS Security Best Practices
  • IAM & Access Management
  • PCI, ISO 27001, SOC 2 Audits
  • Firewall Management
  • Security Monitoring

Systems Administration

  • Linux (Ubuntu, CentOS, SUSE, Red Hat)
  • Windows Server
  • Virtualization (VMware, Hyper-V)
  • Docker & Kubernetes

DevOps & Automation

  • CI/CD Pipelines
  • GitLab / GitHub
  • Jenkins
  • Automation & Scripting

Databases

  • RDS Aurora
  • PostgreSQL
  • DynamoDB
  • MySQL
  • Self-managed (EC2)

Monitoring & Observability

  • CloudWatch
  • Prometheus & Grafana
  • Cost Anomaly Detection
  • Application Monitoring

Certifications

AWS Solutions Architect Professional AWS DevOps Engineer Professional AWS Generative AI Developer Professional AWS Advanced Networking Specialty AWS Security Specialty AWS Machine Learning Specialty AWS ML Engineer Associate AWS Data Engineer Associate AWS Solutions Architect Associate AWS Developer Associate AWS SysOps Administrator AWS AI Practitioner AWS Cloud Practitioner CNCF Kubestronaut CKA CKAD CKS KCSA KCNA LFCS Cisco CCNP Enterprise Cisco Enterprise Core Cisco Enterprise Advanced Cisco Enterprise SD-WAN Cisco CCNA Cisco DevNet Associate Cisco CyberOps Associate Microsoft Azure AI Fundamentals Google Cloud Digital Leader Google Cloud Generative AI Leader ITIL 4 Foundation ITIL 4 Specialist Terraform Associate CompTIA A+ CompTIA Network+ CompTIA Security+ CompTIA Linux+ CompTIA Server+ CompTIA Cloud Essentials+ CompTIA Project+ CompTIA IT Operations Specialist CompTIA Linux Network Professional CompTIA Network Infrastructure Professional CompTIA Secure Infrastructure Specialist CompTIA Systems Support Specialist JNCIA-Junos JNCIA-SEC JNCIA-DevOps Aviatrix Multi-Cloud Network Associate Aviatrix Multi-Cloud Automation GitHub Foundations DCA Google & CompTIA Dual Credential Google IT Support

Certification Details

AWS Certifications (13x)

  • AWS Certified Solutions Architect - Professional
  • AWS Certified DevOps Engineer - Professional
  • AWS Certified Generative AI Developer - Professional
  • AWS Certified Advanced Networking - Specialty
  • AWS Certified Security - Specialty
  • AWS Certified Machine Learning - Specialty
  • AWS Certified Machine Learning Engineer - Associate
  • AWS Certified Data Engineer - Associate
  • AWS Certified Solutions Architect - Associate
  • AWS Certified Developer - Associate
  • AWS Certified SysOps Administrator - Associate
  • AWS Certified AI Practitioner
  • AWS Certified Cloud Practitioner

Linux Foundation & CNCF Certifications (6x) - CNCF Kubestronaut

  • Certified Kubernetes Administrator (CKA)
  • Certified Kubernetes Application Developer (CKAD)
  • Certified Kubernetes Security Specialist (CKS)
  • Kubernetes and Cloud Native Security Associate (KCSA)
  • Kubernetes and Cloud Native Associate (KCNA)
  • Linux Foundation Certified System Administrator (LFCS)

Cisco Certifications (7x)

  • Cisco Certified Network Professional Enterprise (CCNP)
  • Cisco Certified Specialist - Enterprise Core
  • Cisco Certified Specialist - Enterprise Advanced Infrastructure
  • Cisco Certified Specialist - Enterprise SD-WAN
  • Cisco Certified Network Associate (CCNA)
  • Cisco Certified DevNet Associate
  • Cisco Certified CyberOps Associate

Microsoft Azure Certifications (4x)

  • Microsoft Certified: Azure Fundamentals (AZ-900)
  • Microsoft Certified: Azure AI Fundamentals (AI-900)
  • Microsoft Certified: Azure Data Fundamentals (DP-900)
  • Microsoft Certified: Azure Security Fundamentals (SC-900)

Google Cloud Certifications (2x)

  • Google Cloud Digital Leader
  • Google Cloud Generative AI Leader

CompTIA Certifications (12x)

  • CompTIA A+
  • CompTIA Network+
  • CompTIA Security+
  • CompTIA Linux+
  • CompTIA Server+
  • CompTIA Cloud Essentials+
  • CompTIA Project+
  • CompTIA IT Operations Specialist (CIOS)
  • CompTIA Linux Network Professional (CLNP)
  • CompTIA Network Infrastructure Professional (CNIP)
  • CompTIA Secure Infrastructure Specialist (CSIS)
  • CompTIA Systems Support Specialist (CSSS)

Juniper Certifications (3x)

  • JNCIA-Junos (Junos)
  • JNCIA-SEC (Security)
  • JNCIA-DevOps (Automation and DevOps)

Other Certifications

  • ITIL 4 Foundation Certificate in IT Service Management
  • ITIL 4 Specialist: Create, Deliver and Support
  • HashiCorp Certified: Terraform Associate
  • Docker Certified Associate (DCA)
  • Aviatrix Multi-Cloud Network Associate
  • Aviatrix Multi-Cloud Network Automation Specialty
  • Google & CompTIA Dual Credential
  • GitHub Foundations
  • Google IT Support Professional Certificate

Education

BSc Automated Control Engineering

College of Computer Technology Tripoli (CCTT), Libya · 2015

Main subjects: Automatic Control Systems, PLCs (Programmable Logic Controllers), Industrial Automation, Electrical Engineering, Electronics, Computer Science, Advanced Mathematics, Industrial Organization

AS Information Technology

High Institute of Nahda Al Maaref, Libya · 2011

Publications & Writing

Technical articles and architectural deep-dives on cloud infrastructure, DevOps, and security.

For technical content, write-ups, and updates, find me on:

Get In Touch

Interested in working together? Let's connect.