Cloud Engineering
STRONG FITVPC, EC2, IAM, RDS, DynamoDB, Lambda, ALB and Auto Scaling used across 8 AWS builds with documented outcomes, from a multi-AZ migration to a CloudFormation pipeline.

I’m Arif Rahman, graduating June 2027 and looking for a graduate tech role in the United Kingdom. Below are 14 projects I’ve built and written up: multi-AZ AWS migrations, Terraform and CloudFormation, Docker, security frameworks and an ML pipeline. Each one links to its code and evidence.
Multi-tier AWS migration with AD, ALB, ASG and automated bootstrapping
A six-phase build of a three-tier AWS environment for a fictional fintech: isolated VPC across two availability zones, four chained security groups, a bastion host and Simple AD, RDS, DynamoDB, EFS and S3, and an auto-scaled backend bootstrapped from user-data. Every phase is evidenced with console screenshots.
Multi-AZ
High availability
Audit-ready
Compliance posture
Auto-scaled
API tier
Academic and personal projects are labelled as such. Every card links to the case study and, where the work is on GitHub, to the code.
Cloud infrastructure, security and serverless work built on AWS.
Hardened layered security for a Smart City Operations Platform
For smart-city operators responsible for sensitive citizen, personnel and IoT data, this framework replaces public exposure and ad-hoc controls with an auditable security model. In the project assessment, two Critical risks scored 9 were reduced to Low, while a three-node database design improved planned service resilience.
Stroke prediction and credit-card customer segmentation, end to end
For clinical screening and financial analytics teams, this pipeline turns imbalanced, unstructured datasets into decision-ready risk and customer insights. In benchmark testing, tuning lifted stroke recall from 0% in the misleading high-accuracy baseline to 80%, while segmentation produced four actionable customer groups.
Two-site enterprise network with HSRP redundancy, VLANs and IPSec site-to-site VPN
For a growing two-site business, this design removes single points of failure, fragmented addressing and insecure inter-site traffic. It provides capacity for 50% headcount growth without re-addressing, uses gateway redundancy to minimise downtime, and passed 18 end-to-end validation tests.
Multi-tier AWS migration with AD, ALB, ASG and automated bootstrapping
For a regulated digital-services team, this architecture replaces manually managed, single-instance infrastructure with a secure and scalable AWS operating model. Multi-AZ services and a 2–4 instance Auto Scaling range improve continuity and resource utilisation, while central identity and reusable bootstrapping reduce repeat configuration effort and access risk.
Turning a raw 8,807-row S3 dataset into an interactive BI dashboard
For content and commercial analysts, this dashboard removes the need to download raw files or write one-off queries before answering routine catalogue questions. It converted 8,807 records into six decision-ready visuals in roughly two hours, creating a faster and repeatable path from source data to insight.
A conversational banking bot: intents, custom slots and verified balance checks
For retail banking service teams and customers, this prototype shifts repetitive greeting and balance enquiries toward secure self-service. It demonstrates automated handling across two core intents, captures account context, and introduces date-of-birth verification before sensitive information is returned.
Customer-managed keys, encryption at rest and proving unauthorised access fails
For teams managing sensitive or regulated records, this control gives the organisation direct authority over who can decrypt its database rather than relying only on provider-owned keys. The test proved unauthorised reads were blocked and limited approved access to five explicit cryptographic actions, reducing data-exposure and audit risk.
VPC, subnets and an Apache web server as code, deployed by a CI pipeline
For a hospitality platform that needs repeatable environments, this replaces console clicking with a version-controlled CloudFormation template that a GitHub Actions workflow deploys on demand. Every change is reviewable in a pull request and re-running the pipeline updates the stack in place, so environments stop drifting and rollbacks are a git revert away.
AWS Core
VPC · EC2 · ALB · ASG · S3 · RDS · DynamoDB
Containers
Docker · Compose · ECR · Kubernetes basics
IaC & Automation
Terraform · CloudFormation · Bash · CI/CD
Security & Identity
IAM · Simple AD · Security Groups · ISO 27001
Networking
Cisco · Routing · VPN · Subnetting
Data & ML
Python · Pandas · Scikit-Learn · Modelling
Every rating below cites the project evidence behind it — academic and personal projects are labelled as such throughout.
VPC, EC2, IAM, RDS, DynamoDB, Lambda, ALB and Auto Scaling used across 8 AWS builds with documented outcomes, from a multi-AZ migration to a CloudFormation pipeline.
ISO/IEC 27005 risk assessment on CivicNexus — 2 Critical risks (scored 9) treated down to Low across 4 hardened layers; KMS envelope encryption on DynamoDB.
Two-site enterprise network (TechBridge) with HSRP redundancy, VLAN segmentation and IPSec VPN — passed 18 end-to-end validation tests.
4 containerisation projects: multi-container Flask + Redis app, Docker Compose multi-service stack, and a full ECR private registry pipeline.
Starling Digital multi-tier migration with automated bootstrapping and a 2–4 instance Auto Scaling range, plus WordPress and cloud-init EC2 builds written in Terraform.
GitHub Actions pipeline deploying a CloudFormation stack (Plan-Letting v1); Kubernetes basics in progress and the current primary learning focus alongside deeper Terraform module design.
AWS Cloud Practitioner and AWS Generative AI Practitioner earned; AWS Solutions Architect — Associate (SAA-C03) in progress.
Bottom-line verdictBottom line: the evidence points to a strong fit for cloud engineering, DevOps and platform roles. The strengths are grounded in named projects with measured outcomes — not self-assessment — and the development areas (Kubernetes, production CI/CD at scale) are exactly what I'm working on now. Academic and personal projects are labelled as such throughout.
Paste a job description below and this page will scan it against my documented skills and projects — right here in your browser.
AWS Solutions Architect — Associate (SAA-C03)In progress
Amazon Web Services
Curiosity drives the architecture; Red Bull just keeps my lights on.
I have an obsessive curiosity problem — in the best way. When an itch for a problem needs scratching, I do not look for shortcuts. I go from the ground up, whatever it takes, until I genuinely understand the thing. That is how I taught myself Terraform, how I rebuilt a multi-AZ AWS migration, and how I ended up reading AWS release notes for fun.
Away from the screen I am just as hands-on: wrestling and grappling martial arts, following every Formula 1 race weekend, and genuinely enjoying meeting, speaking and socialising with people. I am high-energy and outgoing — but I back it up with a relentless technical drive. I will talk your ear off about cloud security, then spend the next six hours quietly fixing the IAM policy until it is bulletproof.
What I value most about cloud engineering is turning a business requirement into a dependable system. The measure of success is the outcome: less manual effort, lower risk, better continuity and an architecture a team can understand, operate and grow.
Every project is documented with architecture decisions and verification evidence. Happy to walk through any of them on a call.
Get in touch