Tan Mehedi
Cybersecurity Architect Lead|AWS SME | Zero Trust & AI Security Strategy | AWS Certified Solutions Architect | Cloud Security, DevSecOps Leader |Specialty in AWS, CloudOps, Cloud Security, AWS Platform Security, AI & ML
- Role
- Sr Solutions Architect Sr Devops Engineer Principal Cloud Infrastructure Engineer at Blue Cross NC
- Location
- Marietta, GA, US
- LinkedIn followers
- 500 followers
About Tan Mehedi
As a seasoned AWS Cloud Security Engineering professional with 15+ years of experience designing, deploying, and securing scalable AWS, Multi-Cloud solutions across large enterprise environments, I have automated cloud security governance for 400+ AWS accounts, reducing significant manual audit overhead. I specialize inSkills: Cloud & Infrastructure:AWS Security Architecture (GuardDuty, Security Hub, KMS)Core Services (Control Tower, IAM, EC2, ECS, S3, SNS, SES, xLB, Route53,VPC,TGW, DGW, DX)Security AutomationAWS Organizations & Service Control Policies (SCPs)Software Defined Networking (SDN)Identity & Governance:Zero Trust Architecture (ZTA)Identity & Access Management (IAM)OIDC, OAuth 2.0, & SAMLNIST CSF CIS / ISO 27001 / SOC2FedRAMP & DORA ComplianceSecurity Policy-as-Code (OPA/AWS Config)Advanced Security & Leadership:AI/ML Security Modeling (Bedrock/SageMaker)Threat Modeling (STRIDE/PASTA)DevSecOps & CI/CD Pipeline SecurityAutomated Incident ResponseStakeholder Management & Security LeadershipVulnerability Management & Remediation>> Career HighlightsLeading multiple large cloud engineering teamsOptimized and managed complex enterprise IT ecosystems Achieved annual cost savings and reduced waste of approximately $10 million through strategic initiatives (off-hours, downsizing, autoscaling, etc.) Passed multiple local, state, and federal government audits of IT environments and data securityImplemented AWS Control Tower across the organization, eliminating the need for external consultants and resulting in multi-million-dollar cost savings.Deployed a centralized IDS/IPS solution using Palo Alto Firewalls, significantly enhancing security while saving millions in third-party implementation costs.Core Expertise:Cloud Architecture at Scale: Designing resilient, multi-account AWS environments using Guardrails-as-Code (Cloudformation/Terraform/Python) and automated remediation.Zero Trust & Identity: Leading enterprise-wide pivots to Identity-First security (SSO,OIDC, SAML, OAuth 2.0) and microsegmentation.Modern DevSecOps: Embedding security into the CI/CD pipeline for ECS,EKS,Serverless workloads \"Compliance-at-Scale.\"AI Security Governance: Architecting secure pipelines for Generative AI and LLM deployments (AWS Bedrock/SageMaker) while mitigating emerging threats like prompt injection and data poisoning.>AWS Control Tower Implementation>Cybersecurity & SecOps: AWS SecurityHub, GuardDuty, PRISMA, QRadar, Palo Alto Networks, F5 Firewalls>Security Standards: CIS, MARS-E, HIPAA/PHI
Experience
Sr Solutions Architect Sr Devops Engineer Principal Cloud Infrastructure Engineer
Oct 2018 — Present · Raleigh-Durham, NC, US
Advanced cloud delivery: This includes securing cloud infrastructure, optimizing costs, ensuring enterprise-grade information security, and enforcing access controls.My expertise spans diverse cloud environments, including AWS and Hybrid Cloud solutions. My daily responsibilities focus on cloud security, cloud solution delivery, cost-saving initiatives, and acting as a Subject Matter Expert (SME) in AWS. Amazon SageMaker: Proficient in developing, training, and deploying machine learning models; skilled in fine-tuning pre-trained generative models, including distributed training and optimization of large language models (LLMs).AI/ML Workflow Automation: Skilled in orchestrating complex AI/ML pipelines with Amazon Step Functions and AWS Glue for efficient data preprocessing.Generative AI Frameworks: Experienced in utilizing popular AI frameworks such as TensorFlow, PyTorch, and Hugging Face, optimized specifically for AWS infrastructure to deliver advanced AI-driven solutions.Identity & Access Management (IAM): Multi-factor authentication, privileged access management (PAM), Active Directory, LDAP, SAML, OAuth, OpenID, Federation.Endpoint & Data Protection: DLP, EDR, antivirus, secure web gateways, policy development, insider threat detection.Security Operations: SIEM/SOAR, log analysis, incident response, vulnerability management, penetration testing, threat hunting.Key Competencies & Skills:>> Cloud & DevOps Skills:AWS Architecture,AWS CloudFormation,AWS Control Tower,IAM,Amazon EC2,Amazon S3,Amazon RDS,ELB,AWS VPC / NetworkingKubernetes,Docker,CI/CD Pipelines,Jenkins,Git / GitHub / GitLab,Infrastructure as Code (IaC),Serverless Architecture,DevOps>> Security & SecOps SkillsCloud SecurityAWS SecurityHubAWS GuardDutySIEM Tools (QRadar / Splunk / Prisma Cloud)Security Compliance (CIS, HIPAA, MARS-E, NIST)>> Data, AI, and Enterprise Tech SkillsAmazon SageMaker / AI & MLAmazon BedrockData Engineering (Glue, Athena, SFTP)
Education
Michigan State University
Computer Engineering
2000 — 2002
Georgia State University
Bachelor's degree, Computer Science
2002 — 2006
Skills
- Software Development
- Asp.net Mvc
- Leadership
- Json
- Css
- Comptia Network+
- Strategy
- Jquery
- Web Applications
- Asp.net
- Wpf
- Networking
- Objective-C
- IT Service Management
- Entrepreneurship
- Management
- Information Technology
- Java
- Joomla
- Cloud Computing
- Ajax
- Comptia
- Network Administration
- Mysql
- Web Development
- Software as a Service (Saas)
- Business Development
- Computer Engineering
- Mvc
- Strategic Planning
- New Business Development
- Html
- Microsoft Sql Server
- Javascript
- Html 5
- C#
- Php
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.