cloud-architect

Ankit Siwach

Senior Cloud Solutions Architect

$

Designing and governing multi-cloud estates across AWS, Azure, and GCP — building AI-assisted automation that keeps things secure at scale.

Experience
13+ yrs
Accounts
1000+
Savings
$1.5M+
Clouds

Who I Am

I'm a cloud architect who cares about doing things at scale — the right way. Over 13 years, I've moved from hands-on systems engineering to designing governance frameworks that let hundreds of teams ship safely across AWS, Azure, and GCP.

At Epsilon, I set the standards for how 1,000+ AWS accounts operate: landing zones, identity, guardrails, networking. I also build AI-powered tools — like an IAM chatbot on Amazon Bedrock that turns plain English into governed IAM policies, and automation that cut security remediation from 30 minutes to under a minute.

I believe the best cloud architecture is invisible — teams should move fast without thinking about compliance, because the platform handles it. That's what I build.

location: Bangalore, India
role: Sr. Cloud Solutions Architect @ Epsilon
education: B.E. Electronics & Communication

Career Journey

Senior Cloud Solutions Architect

Epsilon · Bangalore

2024 — Present
  • Set landing zone and guardrail standards across a 1,000+ account AWS estate, Azure Management Group hierarchy, and GCP org/deny policies — one governance model across all three clouds.
  • Architected AI-assisted IAM Identity Center permission-set provisioning on Amazon Bedrock with multi-layer human approval, Access Analyzer validation, and full audit trail.
  • Developed an IAM policy chatbot (FastAPI + Bedrock) that generates governed policies from plain language or JSON, with Knowledge Base lookups for estate queries.
  • Designed Wiz-integrated IAM remediation automation — cut remediation from 15–30 min to under 1 min per account.
  • Architected HashiCorp Vault on EKS and EC2/ASG with Terraform; proved resilience through node-loss, patching, and backup/restore DR tests.
  • Designed hub-and-spoke connectivity with VPC Lattice, Route 53 Profiles, and shared private hosted zones.
  • Rolled out GuardDuty EKS runtime monitoring with automated response controls for PCI-DSS workloads.
  • Designed org-level Amazon Bedrock guardrail enforcement that denies model invocation outside approved paths.

Lead Cloud Automation Engineer

Epsilon · Bangalore

2021 — 2024
  • Migrated 600+ AWS accounts into an AWS Control Tower landing zone; established security baselines and account lifecycle processes.
  • Architected self-service AWS account vending and decommissioning — provisioning went from days to hours.
  • Drove FinOps and volume-migration work saving $1M+ in cloud spend via CloudHealth and Apptio.

Senior Automation Engineer

Epsilon · Bangalore

2019 — 2021
  • Migrated workloads into Azure with reusable Terraform modules covering network, identity, and backup.
  • Automated cleanup of unused AWS resources (EIP, EBS, ELB) with Python and Stacklet policies.

Cloud System Engineer

Jeeves Info Systems

2017 — 2019
  • Automated AWS infrastructure deployment and optimization workflows, including chatbot-driven lifecycle management.

Senior Cloud Engineer

Brillio Technologies

2016 — 2017
  • Architected AWS platforms and CI/CD automation for customer cloud migrations.

L2 Analyst

IBM India Pvt Ltd

2013 — 2016
  • Ran provisioning, patching, and access governance across hybrid on-premises and cloud estates.

Architecture & Builds

Bedrock + IAM

AI-Assisted IAM Provisioning

IAM Identity Center permission-set provisioning on Amazon Bedrock. Multi-layer human approval, Access Analyzer validation, and a complete audit trail.

Amazon BedrockIAM Identity CenterAccess AnalyzerPython
GenAI

IAM Policy Chatbot

FastAPI + Bedrock chatbot generating governed IAM policies from plain language or JSON. Knowledge Base lookups for estate-specific queries.

FastAPIBedrockKnowledge BasesGenAI
Security

Wiz IAM Remediation

Wiz CSPM integration with IAM remediation workflows. Cut per-account remediation from 15–30 minutes to under a minute.

WizIAMAutomationPython
Multi-Cloud

Multi-Cloud Landing Zones

One governance model across 1,000+ AWS accounts, Azure Management Groups, and GCP org/deny policies. Migrated 600+ accounts into Control Tower.

Control TowerAzureGCPGovernance
Secrets

HashiCorp Vault on EKS

Vault on Amazon EKS and EC2/ASG with Terraform. Proved production resilience through node-loss, patching, and backup/restore DR tests.

HashiCorp VaultEKSTerraformDR
Networking

Hub-and-Spoke Connectivity

VPC Lattice + Route 53 Profiles with shared private hosted zones. Isolated VPC access to observability without Transit Gateway.

VPC LatticeRoute 53Networking

Tech Stack

Cloud Platforms

AWS Azure GCP

Architecture & Migration

Landing Zone Design AWS Organizations Control Tower Multi-Account Strategy Cloud Migration Reference Architectures ADRs

Governance & Security

SCPs Permissions Boundaries IAM Identity Center IAM Access Analyzer GuardDuty Wiz (CSPM) KMS PCI-DSS Least Privilege

AI & GenAI

Amazon Bedrock Knowledge Bases Guardrails Amazon Q IAM Policy Chatbot GenAI Access Controls

Automation & IaC

Terraform CloudFormation StackSets Python FastAPI Ansible Lambda SQS EventBridge

Networking

VPC Design Hub-and-Spoke VPC Lattice Route 53 ALB / NLB DNS

Platform & Containers

Amazon EKS HashiCorp Vault Elasticsearch Kibana Elastic Fleet

CI/CD & Observability

GitHub Bitbucket Jenkins GoCD CloudWatch CloudTrail Athena FinOps

Validated Expertise

Certified Security — Specialty

Solutions Architect — Associate

SysOps Administrator — Associate

Microsoft Azure Fundamentals

Aviatrix Certified Engineer

Let's Connect

Whether it's about cloud architecture, a project collaboration, or just a conversation — I'd love to hear from you.