Rivia
Selected work

Platforms Rivia has built, hardened, and handed over.

Defense, regulated finance, higher education, and commercial SaaS. Across AWS, Azure, and GCP.

Fulcrum Defense

IL2-IL5 DevSecOps platform

Role

Principal DevSecOps & Platform Engineer

Environment

Defense Unicorns (IL2-IL5)AWS EKSAWS ECRFlux GitOps HelmTerraform / TerragruntGitHub Actions

Challenge

Fulcrum Defense needed a secure, repeatable delivery platform across defense (IL2-IL5) and commercial environments, with strong DevSecOps practices and security scanning baked into the release process.

Solution

  • Guided the platform through IL2-IL5 readiness using Defense Unicorns infrastructure and defense-aligned delivery workflows.
  • Designed and built AWS EKS infrastructure with ECR, Helm-based deployments, and Flux GitOps for environment-driven releases.
  • Implemented GitHub-driven Terraform/Terragrunt pipelines and integrated security tools to scan source, dependencies, IaC, and container images.

Outcome

  • Delivered a unified DevSecOps platform for regulated and commercial deployment.
  • Reduced release risk by embedding security checks and automation into the delivery path.

DADANADA Finance Limited

AWS & SDLC modernization

Role

Principal Cloud & DevSecOps Architect

Environment

AWS multi-account landing zoneEKSTerraform / Terragrunt GitHub Actions / GitLab CIArgoCDPrometheus / Grafana / Loki Kafka / RabbitMQRedisRDS / AuroraSonarQubeKeycloak

Challenge

A FINTRAC-regulated, PCI-DSS-certified remittance and FX platform needed a modern, governed AWS foundation, multi-region resilience, a microservices architecture, and stronger engineering quality across its SDLC.

Solution

  • Built a Control Tower-style AWS landing zone with centralized logging, IAM/SSO, and PCI/CIS-aligned policies.
  • Hardened EKS, migrated CI/CD to GitHub/GitLab with GitOps and scanning, and implemented observability and native AWS security services.
  • Designed a domain-driven microservices architecture, compliant ledger and reconciliation, BFF patterns, and API governance.
  • Introduced code-quality gates, end-to-end tests, SDLC standards, and comprehensive runbooks and workshops.

Outcome

  • Transformed the platform into a governed, resilient AWS estate ready for high-volume financial operations.
  • Raised engineering quality and reliability while giving teams clear patterns for future modernization.

AWS-hosted storefront

SOC 2 Type I readiness

Role

Security & Compliance Advisor

Environment

AWSSOC 2 Type ISecurity controlsRisk & remediation tracking

Challenge

An AWS-hosted storefront needed to successfully complete a SOC 2 Type I audit, with improvements required across cloud security posture, documentation, and operational controls.

Solution

  • Assessed AWS architecture and controls against SOC 2 criteria, identified gaps, and defined remediation plans.
  • Hardened access, logging, monitoring, change management, and incident handling; produced policies, procedures, and evidence packages.
  • Guided the client through auditor interactions and clarified control design and implementation.

Outcome

  • Successfully supported the platform through a SOC 2 Type I audit.
  • Strengthened AWS security posture and formalized key operational practices.

Salfati Group

Azure DevOps & governance uplift

Role

Azure DevOps & Cloud Governance Architect

Environment

Azure (multi-subscription)TerraformAzure DevOps / GitHub Actions Entra IDAzure Monitor / Log AnalyticsApplication Insights GrafanaAzure SQLAzure Policy

Challenge

Salfati Group needed a zero-downtime, fully codified, FCC-aligned Azure environment governed via GitOps, with modern identity, disaster recovery, observability, and security hardening.

Solution

  • Inventoried and classified all Azure resources; built CMDB-style inventory and current-state architecture diagrams.
  • Brought the estate under Terraform management using import-first patterns and reusable modules; established GitOps workflows and Terraform pipelines.
  • Designed DR scenarios, uplifted SQL and data security, modernized identity with Entra ID and zero-trust principles, and strengthened governance with management groups, policies, tagging, and monitoring.
  • Delivered comprehensive documentation and runbooks and ran knowledge-transfer sessions for internal teams.

Outcome

  • Transformed Azure into a fully codified, GitOps-driven platform with clear environment separation and resilience.
  • Raised security, governance, and operational maturity while keeping production online.

Cloud Dialogues

Melbourne University analytics migration

Role

Senior AWS Platform & Data Ingestion Engineer

Environment

On-prem Kubernetes to AWS EKSS3 / SQS / DynamoDBFluxKustomize Argo WorkflowsGitLab CI / GitHub ActionsGrafana LGTMOpenTelemetry

Challenge

The university needed to migrate a data-heavy analytics platform from on-prem Kubernetes to AWS, decouple ingestion pipelines, adopt GitOps on EKS, and establish end-to-end observability across environments.

Solution

  • Refactored six ingestion collectors into S3-first pipelines with deterministic keys, SQS-driven processing, checkpointing, and replay patterns.
  • Deployed workloads to EKS using Flux and Kustomize; structured GitOps repos and overlays for multiple regions and environments.
  • Implemented Argo WorkflowTemplates and CronWorkflows, and a Grafana LGTM-based observability stack with OTLP traces.

Outcome

  • Successfully migrated the platform to AWS EKS with decoupled, replayable ingestion.
  • Gave the team strong GitOps and observability foundations across non-production and production.

Nullafi

Shield ICAP platform, multi-cloud Terraform

Role

Terraform & DevSecOps Engineer

Environment

Nullafi Shield (ICAP)AWSGCPAzureTerraform Docker / KubernetesCI/CD pipelinesWeb proxies

Challenge

Nullafi needed a secure, automated, multi-cloud deployment model for Nullafi Shield, its ICAP-based data security platform, with tight integration to web proxies and strong DevSecOps practices.

Solution

  • Automated deployment, scaling, and maintenance of Nullafi Shield using Terraform across AWS, GCP, and Azure.
  • Designed multi-cloud networking, security controls, and container orchestration for ICAP workloads.
  • Integrated Shield with web proxies and contributed to CI/CD and infrastructure automation to support rapid, secure iterations.

Outcome

  • Delivered a Terraform-driven, multi-cloud infrastructure for Nullafi's zero-trust data security platform.
  • Improved reliability and security posture while enabling faster product evolution.

Tax Network USA

AI-assisted tax research & case support

Role

AI & Platform Engineer

Environment

AWSAmazon BedrockVector databaseScheduled ingestion MCP serverLocal LLM agentsInternal knowledge base

Challenge

Tax Network USA needed faster, more reliable access to current IRS guidance and internal case knowledge, while protecting sensitive data and supporting tax professionals in complex case assessment.

Solution

  • Built a scheduled RAG pipeline to scrape IRS documentation, index it in a vector database, and expose it via Amazon Bedrock.
  • Developed prompt orchestration and an MCP server to standardize retrieval and response workflows with guardrails and source grounding.
  • Implemented cost- and security-conscious ingestion, retrieval, and observability patterns, and built local-model agents to combine case documents and internal knowledge for case workers.

Outcome

  • Reduced manual research effort and improved access to up-to-date tax guidance.
  • Provided tax case workers with an AI-assisted workflow for analysis and decision support, on a secure and scalable foundation.

Have something like this in front of you?

Book a 30-minute call. Rivia will scope your cloud, show you what the platform finds, and tell you plainly what the work would involve.