YaznZamel
I design and build secure, highly available systems on AWS and Azure — writing the automation and services behind them in code, and the pipelines that carry them to production.
Reliability is a discipline, not an accident.
01 / 06Software infrastructure engineer who designs and builds technical solutions on AWS and Azure — delivered both inside engineering organizations and directly for external clients in a professional services setting. I ship secure, highly available systems for production workloads and write the automation and services behind them in code with Terraform, AWS CDK, and Python.
I build the release pipelines that carry those systems to production, and I'm strong in observability and monitoring with Prometheus, OpenSearch, and ELK — with a consistent record of improving reliability, reducing operational cost, and shortening incident response times. I work comfortably across engineering teams, client stakeholders, and third-party vendors to turn requirements into working solutions.
Core stack
- AWS
- Azure
- Kubernetes
- Terraform
- AWS CDK
- Python
- Prometheus
- OpenSearch
Citizenship
Canadian & Jordanian
Education
Princess Sumaya University for Technology
B.Sc. Software Engineering- 100%→1%
- Deployment impact radius
- 5 min
- Deployment MTTR
- $700K
- Annual Azure spend cut (23%)
- 74%
- Fewer false-positive alerts
- 50%
- Logging cost reduction
- 28,000
- User accounts secured
Where the work shipped
02 / 06Amazon
DevOps Engineer
Deployment & Delivery
- Architected and led a one-box canary deployment strategy using AWS CDK and CodePipeline, replacing a high-risk monolithic all-at-once release model
- Reduced potential incident impact radius from 100% of users to 1% on initial rollout, eliminated customer-impacting deployment incidents, and brought deployment MTTR down to 5 minutes
Security & Identity
- Designed a zero-trust access model for a 30TB production OpenSearch cluster, resolving a critical vulnerability that allowed anonymous corporate access
- Designed and integrated an OIDC authentication solution (AWS Cognito + ALB), restoring secure, auditable log access for 30+ engineers and cutting troubleshooting time by ~40%
- Architected a secure Lambda-proxy solution closing a critical vulnerability that exposed 28,000 sensitive user accounts through an unauthenticated internal testing framework
- Enforced IAM-based authentication that unblocked 120+ test cases for the Spay and Gpay programmes, saving 290+ manual QA hours per regression cycle
Observability & Cost
- Designed a centralised, multi-account hub-and-spoke logging architecture on OpenSearch, SQS, and Filebeat to ingest and normalise ALB, CloudTrail, and EC2 logs
- Achieved a 50% reduction in logging operational cost through optimised capacity planning
- Replaced noisy ML alarms with calibrated static CloudWatch alarms after a critical SSL-related outage, defining a data-informed observability framework for Tier-1 services
- Cut critical issue detection time from hours to 5 minutes and reduced false-positive alert tickets by 74% (38 → 10) in a single cycle
PwC
DevOps Engineer, Associate
Client Delivery & Stakeholders
- Led a mutual-TLS authentication implementation directly with Cloudflare solution architects, establishing a new reusable security pattern for internal teams
- Delivered cloud engineering for internal firm platforms and external client engagements — gathering requirements, presenting architecture options, and handing over documented, supportable environments
Cloud & Modernisation
- Led the migration of legacy EC2-based applications to containerised workloads on AWS ECS, delivering material cost reduction and improved resource utilisation
- Architected and managed hybrid-cloud deployments on AWS Outposts, enabling low-latency processing for on-premises applications integrated with AWS services
AI Platform & Infrastructure as Code
- Built and managed scalable infrastructure for AI model deployment and lifecycle management, including GPU-optimised AKS clusters (NVadsA10 v5) for high-traffic production
- Architected a secure multi-tenant GenAI platform on Azure, integrating a full stack of production services
- Developed and standardised reusable Terraform modules for automated Azure provisioning, giving delivery teams consistency and a faster path to scale
CI/CD, Security & Cost
- Owned the full CI/CD lifecycle on Azure DevOps Server across dev, staging, and production, managing custom Windows/Linux build runners, integrating Azure Key Vault, and embedding SAST (SonarQube) and DAST (OWASP ZAP)
- Drove a $700K annual reduction in Azure spend — a 23% saving
- Deployed a full observability stack (Prometheus, Loki, Grafana) with PromQL, Node Exporter, and custom JSON log parsers, building dashboards correlating system health, logs, and model performance
Things I built & shipped
03 / 06PharmEaseAI-Powered Pharmacy Locator & Virtual Pharmacist
A scalable backend platform combining pharmacy management with an AI-powered virtual pharmacist for real-time health consultations.
- Scalable backend API with FastAPI for CRUD operations
- Geolocation-based pharmacy search using the Haversine formula
- GenAI chatbot with LangChain + Pinecone + ChatGPT-4 streaming
- MongoDB with embedded and referenced schemas
- Containerised with Docker, deployed to AWS
CloudMapperCloud Migration GenAI Assistant
An AI-driven chatbot that assists engineers with cloud migration and service mapping queries using documentation-backed answers.
- AI chatbot for cloud migration queries
- Automated scraping of 100+ cloud docs, embedded in ChromaDB
- LangChain for query interpretation and response orchestration
- Streamlit web UI with FastAPI backend
Credentials, earned
04 / 06- SAPSolutions Architect ProfessionalAWS
- DVADeveloper AssociateAWS
- SAASolutions Architect AssociateAWS
- Linux+CompTIA Linux+Linux
- LFCSLinux Foundation Certified System AdministratorLinux
- CKADCertified Kubernetes Application DeveloperK8s
- KCNAKubernetes and Cloud Native AssociateK8s
The résumé, in full
05 / 06Let's build something dependable
I'm always open to discussing infrastructure work, platform engineering, or a hard reliability problem worth solving.