Hisham
Johari
7+ years across infrastructure management, cloud engineering, security compliance and premium technical support. Firm believer in life-long learning and continual exploration for new technology stacks.
Own infrastructure provisioning and security posture for a SaaS platform serving 800k+ users across three cloud regions.
- Designed and implemented multi-account AWS landing zone using Terraform modules, reducing provisioning time from 3 days to under 2 hours
- Hardened EC2 and EKS workloads against CIS Benchmark Level 2; resolved 14 critical findings in first quarter
- Built automated secret rotation pipeline using HashiCorp Vault, eliminating long-lived credentials across 40+ services
- Established on-call runbooks and SLO dashboards; MTTR dropped from 47 min to 11 min over 6 months
Hybrid role covering L2/L3 technical support and infrastructure maintenance for mid-market clients across finance and healthcare verticals.
- Managed VMware vSphere clusters and migrated two clients from on-prem to AWS, zero unplanned downtime
- Implemented centralized logging with ELK Stack; reduced ticket resolution time by 30% through faster root-cause analysis
- Authored Ansible playbooks for OS hardening, applied across 200+ servers with consistent, auditable baselines
- Served as primary escalation contact for Tier-2/3 incidents, maintaining <4h SLA on critical tickets
End-user support and network administration for a 250-seat corporate office environment.
- Maintained Active Directory, DNS, and DHCP infrastructure for on-premises Windows environment
- Handled hardware procurement, asset tracking, and workstation imaging via MDT
- Diagnosed and resolved an average of 35 support tickets per week across hardware, software, and connectivity issues
Open-source Terraform module that provisions an opinionated, CIS-compliant AWS account baseline — GuardDuty, Security Hub, Config rules, and SCPs in one apply.
Pre-built Grafana dashboards and Prometheus alert rules for common web service SLOs — latency, availability, error budget. Deployed via Helm chart.
Slack bot that ingests PagerDuty alerts, enriches them with recent deployment history and log anomalies, and posts a structured triage summary to the incident channel.
Markdown-driven runbook system where common remediation steps (disk cleanup, service restart, cert renewal) are backed by validated shell scripts with dry-run support.
Available for full-time roles, contract work, or just to talk infrastructure. Response time usually same day.