Ankush Patil - Cloud Architect | AWS & Azure Solutions Architect
Cloud Architect. I design, migrate and secure production workloads on AWS and Azure - and I build them assuming someone will try to break them. I led an enterprise migration from on-premises to a containerized AWS platform, and hardened cloud accounts for one of Canada's largest insurers by shifting security into the delivery pipeline. A 2026 season that ended in gold (Skills Ontario) and silver (Skills Canada Nationals) in cloud computing. Open to Cloud Architect roles across Canada and India, on-site or remote. Ankush Patil is an AWS-certified Cloud Architect open to Cloud Architect, Solutions Architect, Cloud Security Engineer, DevOps / Platform roles across Canada and India, on-site or remote.
Skills
- AWS · Azure · ECS Fargate · Amazon EKS · CloudFront · Route 53 · WAF
- Terraform · AWS CDK · CloudFormation · GitHub Actions CI/CD
- IAM least-privilege · KMS · policy-as-code · encryption · cost governance
- RDS Aurora · ElastiCache · Azure SQL · Cosmos DB · S3
- Amazon Connect · Lex · Polly · Transcribe · Bedrock
- Python · PowerShell · Bash · SQL
Experience
Cloud Security Engineer - Intact (2025)
Hybrid. Intact - Canada's largest property & casualty insurer · cloud security engineering. Hardening AWS accounts and shifting security into the delivery pipelines application teams use to provision infrastructure.
- Embedded with the cloud security team to harden AWS accounts and shift security into the pipelines application teams used to provision infrastructure.
- Built secure-by-default Terraform baselines enforcing network segmentation, least-privilege IAM and mandatory KMS encryption, so teams provisioned compliant environments without hand-rolled, drift-prone configurations.
- Added automated policy checks and security scanning to GitHub Actions pipelines, blocking non-compliant changes - open security groups, unencrypted storage, wildcard IAM - before they reached production.
- Remediated open security-scan findings by scoping over-permissive IAM to least-privilege and closing encryption and public-access gaps on S3 and RDS, clearing the backlog ahead of an internal compliance review.
Tools: Terraform, IAM least-privilege, KMS, GitHub Actions, Policy-as-code, AWS security.
Cloud Architect - Persistent Systems (2022 - 2024)
Pune · On-site. Persistent Systems - global IT services & digital engineering firm. End-to-end migration of an enterprise retail platform from on-premises to a containerized, highly available AWS architecture.
- Led the end-to-end migration of an enterprise retail client's monolithic on-premises application to AWS - owning the target architecture, migration plan and production cutover after the platform buckled under seasonal traffic.
- Re-platformed onto ECS Fargate behind an Application Load Balancer, fronted with CloudFront and AWS WAF, and migrated the database to RDS Aurora via AWS DMS with a rehearsed, near-zero-downtime weekend cutover.
- Automated the full stack - networking, compute, data and IAM - with reusable Terraform modules and GitHub Actions CI/CD, taking releases from multi-week cycles to on-demand deployments in under an hour.
- Designed multi-AZ high availability with auto-scaling, automated backups and a DR strategy to defined RTO/RPO targets, monitored through CloudWatch dashboards and alarms.
- Reduced monthly cloud cost by right-sizing compute and planning reserved capacity, hardening the account with IAM least-privilege and KMS encryption as standard.
Tools: AWS migration, ECS Fargate, RDS Aurora, Terraform, CI/CD, Multi-AZ HA, DR.
Education
- B.Tech, Computer Engineering - SVKM's Institute of Technology (2018-22)
- PG Cybersecurity - Georgian College (2024-25)
- Cloud Architecture & Administration - Seneca Polytechnic (2025-26)
Certifications
- Solutions Architect - Associate (2026)
- AI Practitioner (2026)
- Cloud Practitioner (2026)
- Google Cybersecurity Professional Certificate (2023)
- 28 CrowdStrike certifications · 7 domains (2025)
Selected work
house-of-north
A live AWS e-commerce platform built for House of North - storefront on ECS Fargate behind CloudFront + WAF, an Aurora data tier, KMS throughout, and every environment reproducible through Terraform. Includes an automated Amazon Connect voice flow (Lex, Polly, Transcribe) that deflects routine support contacts. Stack: ECS Fargate, Aurora, CloudFront, WAF, KMS, Terraform, Amazon Connect.
build-roulette
A side project documenting 5 Engineering Decision Records - the options weighed, trade-offs and final call behind each core design choice. Live at buildroulette.dev. Stack: Engineering Decision Records, Content platform.
eks-irsa
Amazon EKS with IAM Roles for Service Accounts: pod-level cloud identity instead of node-wide credentials. Helm releases, HPA under load. Stack: Amazon EKS, IRSA, Helm, HPA.
azure-hybrid
On-prem joined to Azure over P2S VPN, governed via Azure Arc; Azure SQL + Cosmos DB on zone-redundant storage with Recovery Services backup. Stack: P2S VPN, Azure Arc, Azure SQL, Cosmos DB, ZRS, Recovery Services.
Awards
- Gold - Skills Ontario 2026 (Cloud Computing, post-secondary)
- Silver - Skills Canada Nationals 2026 (Cloud Computing, representing Ontario)
Contact
- Email: ankushgp@icloud.com
- GitHub: github.com/AnkushPatil45
- LinkedIn: linkedin.com/in/ankush-p