Catriel Goodman

Tech Lead, Cloud & Platform Engineering

Cloud and platform engineer — multi-tenant AWS, identity, and the automation that keeps it all standing up.

Israel · catriel12@gmail.com · +972 53 358 8567 · LinkedIn

MyselfThe CPU

Curiosity is the thing I'd point at first. I like problems, and the messier they are the more interested I get. Give me something I don't know how to do yet and I'll happily go figure it out and learn whatever I need on the way — that's the part of this work I'd do for free.

I'm tech-loving by nature. New things pull me in, and I'm usually the early adopter in the room, poking at something months before anyone asks me to.

I don't fear the deep water. If there's an important system nobody wants to own, I'll take it, and I'll still be looking after it long after launch. That's been true at every place I've worked.

And I like helping. When I see someone struggling with something, I'll stop and work out how to make it easier for them. A lot of what I've ended up building started exactly that way.

ExperienceThe Memory Bank

Every role I've had has gone roughly the same way: I start out fixing things, and I end up owning them. Navy networks, then enterprise IT, then cloud platforms — at each stop I got handed more of the stuff that simply has to keep working.

Tech Lead, Cloud & Platform Engineering

  • Lead a team of developers and Cloud Ops engineers building and operating distributed backend systems on AWS, owning production infrastructure end to end.
  • Own AWS Organizations governance and multi-account strategy across 100+ AWS accounts.
  • Architect identity and authorization infrastructure: federated identity across Azure AD and Cognito, tenant and access isolation, and fine-grained authorization.
  • Design and build distributed, event-driven systems — multi-tenant platform services, internal APIs, and asynchronous processing pipelines.
  • Develop, maintain, and support the cloud tooling and systems behind the company's cloud needs across FinOps, SecOps, DevOps, and IAM, including a CI/CD-integrated Terraform architecture reused across accounts and environments.

DevOps Engineer

  • Designed and operated production AWS environments for enterprise clients, focused on availability, security, and cost efficiency.
  • Built Git-based CI/CD pipelines and ran container orchestration on ECS and EKS.
  • Led cloud security hardening and cost optimization initiatives.
  • Developed Python automation tooling integrating directly with AWS APIs.

IT Admin

  • Managed company SaaS platforms and identity management across Azure AD and Office 365.
  • Ran physical security systems and network/virtualization hardware and software — Aruba, VMware, Fortinet.

Electronic Warfare Operator · IT & Networking Administrator

  • Electronic warfare operator and technician. A combat position: active operations, long and awkward hours, and a high-stakes environment where being wrong carried a real cost.
  • IT and networking administrator. NOC certified for all critical Navy infrastructure, running 24/7 support for mission-critical issues and managing tickets and technical support through CRM. Also handled network architecture planning from sketches through installation documents, configured and installed Cisco equipment in both user and datacenter environments, supported every network device in the Navy, and worked alongside the Microsoft, storage, server, and cyber security teams.

ProjectsThe Logic Array

Named systems, in production, with people depending on them. Most of this is platform infrastructure at Mobileye.

Work

Nexus

Built from scratch. Large-scale external-facing edge infrastructure with custom Cognito auth methods for complex tenant emulation. Serves 20+ production applications for 20+ external customers and 1,000+ users, at millions of requests per day. Handles tenant isolation, API key management, and identity federation across Azure AD and Cognito.

  • CloudFront
  • Lambda@Edge
  • VPC Origins
  • Cognito
  • API Gateway
  • DynamoDB
  • WAF

Backoffice

Another platform built from scratch, this one designed around platform engineering and CloudOps operations. It decouples complex infrastructure work from the IaC layer, which makes tenant provisioning, configuration, and application integration setup dramatically faster.

  • Python
  • Lambda
  • DynamoDB
  • Terraform
  • Cedar / Verified Permissions

Cloud SSO

Custom tooling bridging an on-prem HashiCorp Vault deployment with AWS. Grants fine-grained access across 100+ AWS accounts via OIDC-based Vault login and IAM roles with custom credential providers.

  • Go
  • Python
  • HashiCorp Vault
  • OIDC
  • AWS IAM

Nexi

Runs on Bedrock AgentCore with Bedrock Knowledge Bases, a data cleanup and sync ETL pipeline, and Guardrails for input/output validation to prevent misuse.

  • Bedrock AgentCore
  • Bedrock Knowledge Bases
  • Guardrails
  • Python

SecOps auto-remediation framework

Modular Python framework triggering auto-remediation playbooks directly off security violation events from the Wiz platform — closing the loop between findings and infrastructure fixes.

  • Python
  • Wiz
  • Step Functions
  • Terraform
  • Lambda

Personal

Still deciding what belongs here. Coming soon.

Skills & CertificationsThe Instruction Set

What the above was built with.

Languages

  • Python
  • Go
  • Bash
  • PowerShell

Cloud

  • AWS Organizations
  • IAM
  • Lambda
  • ECS
  • EKS
  • API Gateway
  • DynamoDB
  • S3
  • RDS
  • CloudFront
  • Lambda@Edge
  • WAF
  • VPC
  • EC2
  • CloudWatch
  • SQS
  • SNS
  • EventBridge
  • Step Functions
  • Athena
  • Glue
  • Bedrock
  • Azure AD

Infrastructure as Code

  • Terraform
  • AWS SAM
  • CloudFormation
  • Reusable multi-environment architecture

CI/CD

  • GitHub Actions
  • GitLab CI
  • Jenkins
  • Git-based pipelines
  • Build & release automation

Containers

  • Docker
  • ECS
  • EKS
  • Kubernetes

Identity & Security

  • Cognito
  • Azure AD
  • IAM
  • SSO
  • OIDC
  • Cedar / AWS Verified Permissions
  • HashiCorp Vault
  • AWS secrets engines
  • Custom credential providers
  • Wiz auto-remediation
  • AWS WAF

Architecture

  • Distributed systems
  • Event-driven & pub/sub
  • Microservices
  • Multi-tenant SaaS
  • REST API design

AI tooling

  • Bedrock AgentCore
  • Bedrock Knowledge Bases
  • Guardrails
  • Strands
  • Agno
  • Cursor
  • Claude
  • Claude Code

Systems & Networking

  • Linux
  • Windows
  • Windows Server
  • Active Directory
  • Cisco networking
  • Fortinet firewall

Certifications

  • AWS Certified Solutions Architect – Associate
  • Cisco CCNA

OnewheelThe Motor Driver

A Onewheel is one fat go-kart tyre with a motor inside it and a footpad on each side. You lean forward and it goes. Nothing to hold onto, nothing to steer with — which is most of the appeal.

I ride, but I mostly tinker. I build VESC-based boards — swapping controllers, tuning ride feel, and fixing things I probably broke myself — and honestly that's half the hobby for me.

The other half is the people. The Onewheel community in Israel is small and pleasantly obsessive, and group rides with them are some of the best evenings I have.

Gallery coming soon.

PhotographyThe Image Sensor

Photography is a hobby. I've taken an interest in nature photography, and in film making and VFX, mostly 2D compositing.

Gallery coming soon.

3D & AIThe GPU

Also a hobby. I dabble in 3D software, 3D printing and design, and I play with AI tools, for 3D and in general. It's part of the tinkering.

ContactThe I/O Port

One port on the board. Three pins on it.