Catriel Goodman

Tech Lead, Cloud & Platform Engineering

Cloud and platform engineer — multi-tenant AWS, identity, and the automation that keeps it all standing up.

Israel · catriel12@gmail.com · LinkedIn

AboutThe Summit

Engineer with a strong ownership mindset — takes a problem from a blank slate through to a system others rely on, and stays accountable for it long after launch.

ExperienceThe Works

Five years from IT administration into leading a cloud platform team — the throughline being systems other people depend on and nobody else wanted to own.

Tech Lead, Cloud & Platform Engineering

  • Lead a team of developers and Cloud Ops engineers building and operating distributed backend systems on AWS, owning production infrastructure end to end.
  • Own AWS Organizations governance and multi-account strategy across 100+ AWS accounts.
  • Architect identity and authorization infrastructure: federated identity across Azure AD and Cognito, tenant and access isolation, and Cedar-based fine-grained authorization with AWS Verified Permissions.
  • Design event-driven architecture — SQS fan-out with subscriber management, EventBridge-scheduled pipelines, and asynchronous processing across the backend.
  • Maintain a CI/CD-integrated Terraform architecture reused across accounts and environments, with Git-based pipeline automation driving every deployment.
  • Direct planning, estimation, and delivery across the platform's supporting services — Sofia, Quota, Cloud Hub, and ShareMe.

DevOps Engineer

  • Designed and operated production AWS environments for enterprise clients, focused on availability, security, and cost efficiency.
  • Built Git-based CI/CD pipelines and ran container orchestration on ECS and EKS.
  • Led cloud security hardening and cost optimization initiatives.
  • Developed Python automation tooling integrating directly with AWS APIs.

IT Admin

  • Managed company SaaS platforms and identity management across Azure AD and Office 365.
  • Ran physical security systems and network/virtualization hardware and software — Aruba, VMware, Fortinet.

ProjectsThe Foundry

Named systems, in production, with people depending on them. Most of this is platform infrastructure at Mobileye.

Nexus

Built from scratch. Large-scale external-facing edge infrastructure with custom Cognito auth methods for complex tenant emulation. Serves 20+ production applications for 20+ external customers and 1,000+ users, at millions of requests per day. Handles tenant isolation, API key management, and identity federation across Azure AD and Cognito.

  • CloudFront
  • Lambda@Edge
  • VPC Origins
  • Cognito
  • API Gateway
  • DynamoDB
  • WAF

Backoffice

Manages the platform Nexus serves: edits AWS WAF ACLs to update tenant IPs and domains, and enables, disables, and edits deployed applications and features across every tenant. Multi-persona access model backed by Cedar fine-grained authorization.

  • Python
  • Lambda
  • DynamoDB
  • WAF
  • Cedar / Verified Permissions

cloud-sso

Custom tooling bridging an on-prem HashiCorp Vault deployment with AWS. Grants fine-grained access across 100+ AWS accounts via OIDC-based Vault login and IAM roles with custom credential providers.

  • Go
  • Python
  • HashiCorp Vault
  • OIDC
  • AWS IAM

Nexi

Runs on Bedrock AgentCore with Bedrock Knowledge Bases, a data cleanup and sync ETL pipeline, and Guardrails for input/output validation to prevent misuse.

  • Bedrock AgentCore
  • Bedrock Knowledge Bases
  • Guardrails
  • Python

SecOps auto-remediation framework

Modular Python framework triggering auto-remediation playbooks directly off security violation events from the Wiz platform — closing the loop between findings and infrastructure fixes.

  • Python
  • Wiz
  • Terraform
  • Lambda

Multi-tenant notification system

SQS-based fan-out with subscriber management, serving the Nexus tenant estate.

  • SQS
  • EventBridge
  • Lambda
  • DynamoDB

Skills & CertificationsThe Grid

What the above was built with.

Languages

  • Python
  • Go
  • Bash
  • PowerShell

Cloud

  • AWS Organizations
  • IAM
  • Lambda
  • ECS
  • EKS
  • API Gateway
  • DynamoDB
  • S3
  • RDS
  • CloudFront
  • Lambda@Edge
  • WAF
  • VPC
  • EC2
  • CloudWatch
  • SQS
  • SNS
  • EventBridge
  • Step Functions
  • Athena
  • Glue
  • Bedrock
  • Azure AD

Infrastructure as Code

  • Terraform
  • Reusable multi-environment architecture

CI/CD

  • GitHub Actions
  • Git-based pipelines
  • Build & release automation

Containers

  • Docker
  • ECS
  • EKS
  • Kubernetes

Identity & Security

  • Cognito
  • Azure AD
  • IAM
  • SSO
  • OIDC
  • Cedar / AWS Verified Permissions
  • HashiCorp Vault
  • AWS secrets engines
  • Custom credential providers
  • Wiz auto-remediation
  • AWS WAF

Architecture

  • Distributed systems
  • Event-driven & pub/sub
  • Microservices
  • Multi-tenant SaaS
  • REST API design

AI tooling

  • Bedrock AgentCore
  • Bedrock Knowledge Bases
  • Guardrails
  • Strands
  • Cursor
  • Claude
  • Claude Code

Systems

  • Linux

Certifications

  • AWS Certified Solutions Architect – Associate
  • Cisco CCNA

OnewheelThe Trailhead

Placeholder — this section is waiting on copy.

Placeholder — copy pending. Tracked in docs/CONTENT.md.

PhotographyThe Overlook

Placeholder — this section is waiting on copy and a gallery decision.

Placeholder — copy pending. Tracked in docs/CONTENT.md.

3D & AIThe Render Garden

Placeholder — the natural home for the making-of story for this site: the GenAI-to-Blender pipeline, what worked, and what didn't.

Placeholder — copy pending. Tracked in docs/CONTENT.md.

ContactThe Harbor

The island has one dock.