Tom Haggath
Cloud Support Engineer Ii @Amazon Web Services (AWS)
Signup · Get unlimited contacts
WORK HISTORY
Cloud Support Engineer Ii @Amazon Web Services (AWS)
Manchester, GB
Lead investigation and containment of AWS security incidents across public-sector environments, reconstructing activity using CloudTrail, GuardDuty, VPC Flow Logs, IAM data, and SIEM telemetry to validate impact and guide remediation decisions.• Deploy and operationalize AWS Security Hub and Macie in regulated environments, aligning controls to NIST standards and strengthening audit outcomes.• Identify telemetry and logging gaps during investigations and partner with engineering teams to standardize CloudTrail, CloudWatch Logs, and Config coverage, improving incident readiness and evidence retention.• Design and implement Python-based automation to enrich GuardDuty findings with contextual IAM and account metadata, reducing manual triage effort and accelerating investigation workflows.• Execute containment actions including IAM policy tightening, credential/session revocation guidance, encryption hardening (KMS), and configuration drift remediation, which prevents further unauthorized access and restores compliance with security standards• Author and evolve incident response runbooks for IAM misuse, detection workflows, and logging investigations, enabling consistent response under pressure and reducing escalation dependency.• Built AI-assisted operational automation with embedded data-protection guardrails, reducing process time by 45% while maintaining sensitive data controls
EDUCATION
Andover College
BTEC Level 3 Extended Diploma in IT, Information Technology
Avon Valley College
GCSEs
Bournemouth University
BSc (Hons), Digital Forensics and Security
SKILLS
ABOUT TOM HAGGATH
I’m an Operations Engineer at AWS Managed Services who has focused heavily on cloud security engineering in practice. I work/have worked on incident response, detection triage, and security controls for enterprise AWS environments, using telemetry from CloudTrail and CloudWatch and services like GuardDuty and Security Hub to validate activity and drive containment and remediation. I also build runbooks and escalation paths so teams can respond consistently, while using Python automation to enrich alerts, reduce manual triage, and improve response times. I’ve supported NIST-aligned security outcomes in regulated customer environments and I’m comfortable partnering with engineering and operations teams to close control gaps and reduce repeat incidents. Open to relocation to Chicago, IL and surrounding areas.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.