Ankush Patil - Cloud Engineer in Toronto, Ontario, Canada
Cloud Engineer, Toronto. I design and secure cloud infrastructure the way I was trained to - assuming someone will try to break it. Behind that: a software-engineering background, security-operations experience at one of Canada's largest insurers, and a 2026 season that ended in gold (Skills Ontario) and silver (Skills Canada Nationals) in cloud computing. Authorized to work in Canada. Ankush Patil is an AWS-certified Cloud Engineer open to Cloud Engineer, Cloud Security Engineer, Solutions Architect, DevOps / Platform roles in Toronto and remote across Canada.
Skills
- AWS · ECS Fargate · EKS/IRSA · CloudFront · WAF · KMS
- Terraform · CI/CD (GitHub Actions)
- CrowdStrike Falcon · CyberArk Application Control · Splunk SIEM · least privilege
- Azure Arc · P2S VPN · Azure SQL · Cosmos DB · ZRS
- Python · PowerShell · SQL
Experience
Cyber Security Analyst - Intact (Co-op) (2025)
Toronto, ON · Hybrid. Intact - Canada's largest property & casualty insurer · enterprise security operations. Endpoint application control, sensor hygiene, and data-protection support in a hybrid enterprise SOC.
- CyberArk Application Control: analyzed and categorized 100,000+ Windows and 30,000+ macOS applications (allow / block / validate) to shape least-privilege policies governing which software can run and install on endpoints.
- Improved CrowdStrike endpoint hygiene across a 50,000+ device estate - surfaced unmanaged assets (no sensor installed) and outdated sensor versions, restoring protected, current coverage.
- Remediated MFA enforcement gaps across ~500 user accounts and delivered monthly compliance reporting to IT leadership.
- Provided operational support to the Data Protection team, helping keep endpoint protection comprehensive.
- Researched and co-presented a Lunch & Learn on AI-driven social engineering, sharing practical insight on an emerging threat across the security org.
- Deepening expertise via CrowdStrike University and Varonis training; pursuing the CrowdStrike Falcon Administrator certification.
Tools: CyberArk Application Control, CrowdStrike Falcon, Endpoint hygiene, MFA, Data protection, Least privilege.
Software Engineer - Persistent Systems (2022 - 2023)
Pune · On-site. Persistent Systems - global IT services & digital engineering firm. Security-focused engineering across enterprise infrastructure - monitoring, automation, and database hardening.
- Monitored authentication, system, and network logs in Splunk SIEM to detect brute-force attempts and anomalous access patterns across distributed infrastructure.
- Automated network-exposure scanning with Python and PowerShell, flagging unauthorized open ports and generating daily security-posture reports for infrastructure teams.
- Hardened the data layer with SQL Server TDE and role-based access control (RBAC), enforcing least-privilege data access.
- Supported incident response - isolating affected servers via firewall rules, analyzing traffic in Wireshark, and driving post-incident security improvements.
Tools: Splunk SIEM, Python, PowerShell, SQL Server TDE, RBAC, Wireshark.
Education
- B.Tech, Computer Engineering - SVKM's Institute of Technology (2022)
- PG Cybersecurity - Georgian College (2024-25)
- Cloud Architecture & Administration - Seneca Polytechnic (2025-26)
Certifications
- Solutions Architect - Associate (2026)
- AI Practitioner (2026)
- Cloud Practitioner (2026)
- Google Cybersecurity Professional Certificate (2026)
- 28 CrowdStrike certifications · 7 domains (2026)
Selected work
house-of-north
Production-grade AWS e-commerce infrastructure built for House of North - multi-AZ ECS Fargate behind CloudFront + WAF, Aurora and ElastiCache in private subnets, KMS throughout, GitHub Actions CI/CD, all in Terraform. Stack: ECS Fargate, Aurora, ElastiCache, WAF, KMS, CloudFront, Terraform.
build-roulette
A side project about Engineering Decision Records - documenting why systems end up shaped the way they are. Live at buildroulette.dev. Stack: Engineering Decision Records, Content platform.
eks-irsa
Amazon EKS with IAM Roles for Service Accounts: pod-level cloud identity instead of node-wide credentials. Helm releases, HPA under load. Stack: Amazon EKS, IRSA, Helm, HPA.
azure-hybrid
On-prem joined to Azure over P2S VPN, governed via Azure Arc; Azure SQL + Cosmos DB on zone-redundant storage with Recovery Services backup. Stack: P2S VPN, Azure Arc, Azure SQL, Cosmos DB, ZRS, Recovery Services.
Awards
- Gold - Skills Ontario 2026 (Cloud Computing, post-secondary)
- Silver - Skills Canada Nationals 2026 (Cloud Computing, representing Ontario)
Contact
- Email: ankushgp@icloud.com
- GitHub: github.com/AnkushPatil45
- LinkedIn: linkedin.com/in/ankush-p