Cloud · Infrastructure · Security · Automation

Senior Cloud Consultant | AWS & Google Cloud

Enterprise migrations, landing zones, disaster recovery, infrastructure automation, identity, networking and cloud security.

Portrait of Afzal Ahmed
  • 15+ yearsin IT, from systems and quality engineering to cloud delivery
  • AWS & Google Cloudprofessional-services delivery on both platforms
  • Discovery → Handoverdesign, build, validation, runbooks and knowledge transfer

Core expertise

How I work
  • Landing Zones

    Multi-account AWS and Google Cloud foundations with governance guardrails.

  • Migrations

    MGN migration waves, cutover planning, test launches and validation.

  • Disaster Recovery

    Elastic Disaster Recovery replication, failover and failback drills.

  • Infrastructure as Code

    Terraform and Python automation for repeatable, reviewable builds.

  • Identity & Access

    IAM Identity Center, Entra ID SAML and Okta federation.

  • Cloud Security

    Centralized logging, private PKI, KMS key protection and org policies.

  • Networking

    VPC design, VPN and routing, firewall vendor integration.

  • Windows & File Services

    Active Directory, FSx for Windows and WorkSpaces virtual desktops.

Selected projects

Sanitized case studies from client engagements. Confidential details omitted.

View all projects
AWS Migration · Landing Zone · DR

Enterprise AWS Modernization

Led a multi-account AWS foundation, migration work, file services, virtual desktops and disaster-recovery delivery.

My workLanding-zone design and build · IAM Identity Center · WorkSpaces POC · Migration wave support · DR drills

  • AWS
  • Control Tower
  • Organizations
  • EC2
  • MGN
  • FSx
AWS + Google Cloud Security · Identity

Multi-Cloud PKI Foundation

Led the Google Cloud PKI implementation and coordinated with the AWS engineer on a shared security foundation.

My workGoogle Cloud CA Service · Cloud KMS · IAM separation · Audit logging · Org policies · Terraform lab validation

  • AWS
  • Google Cloud
  • CA Service
  • Cloud KMS
  • IAM
  • Audit Logs
  • Org Policy
Google Cloud Identity · Networking

GCP Kubernetes and Infrastructure Automation

Delivered GKE and Terraform automation inside a restricted enterprise environment with no direct SSH access.

My workGKE design review · Terraform through IAP tunnels · GoCD pipeline review · Kafka and YugabyteDB sessions

  • Google Cloud
  • GKE
  • Terraform
  • IAP
  • GoCD
  • Kafka

Google Cloud Certified

Professional Cloud Architect

Earned — recorded expiry 1 September 2026 has passed; renewal not verified.

Google Cloud Certified

Professional Data Engineer

Earned — recorded expiry 7 October 2026.

Google Cloud Certified

Professional Cloud Developer

Earned — recorded expiry 22 November 2026.

About

I am a Calgary-based Senior Cloud Consultant with more than 15 years in IT. My background spans quality engineering, systems work, cloud operations and professional-services delivery. I now design and implement AWS and Google Cloud environments for migrations, landing zones, disaster recovery, security, identity, networking and infrastructure automation.

More about me
  • Recent work is primarily AWS: landing zones, MGN waves, DRS drills, FSx, WorkSpaces, identity, hybrid networking, assessments and handovers.
  • Substantial Google Cloud experience: landing zones, GKE, Terraform automation, security logging, IAM and VMware Engine.
  • Works directly with customer technical teams from discovery through implementation, runbooks and knowledge transfer.

Get in touch

Explore my cloud project experience, download my résumé, or get in touch about professional opportunities.