Michael Uchytil
Cloud Security Engineer
Cloud Engineer specializing in securing application workflows. Experienced in integrating and troubleshooting SAML and OIDC federation flows in multi-cloud and AD environments, developing and implementing robust Identity and Access Management policies, and PKI infrastructure certificate and key management solutions. Focus on developing effective Bash and Python automation and where appropriate, Machine Learning tools and techniques.
Education and Certifications
Bachelor of Science and Business Administration Computer Information Systems - Thomas Edison State University
Work Experience
Cloud Support Engineer - Security
Amazon Web Services, Inc (05/2024 - Present)
- Troubleshoot and configure secure IAM policies. (IAM Policies, S3 Bucket Policies, Organization SCP and RCP)
- Troubleshoot and develop sample AWS SDK usage in Python, JavaScript (JS), and AWS CLI.
- Troubleshoot and guide web and API endpoint security using SSL public and private certificates, SSL offloading, firewalls, and JWT tokens. (ACM, ACM-PCA, WAF, Cognito, API-Gateway, ELB, Nginx, CloudHSM)
- Troubleshoot and guide monitoring, analysis, and eesponse to network traffic and API calls. (VPC Flow Logs, CloudWatch, CloudTrail, Lambda, SNS, S3, Athena SQL Queries)
- Provide on-call escalation for data encryption technologies. (Key Management Service (KMS), CloudHSM)
- Troubleshoot and guide implementation of monitoring and compliance tools. (Config, CloudTrail, Slunk, SNS)
- Troubleshoot and guide SAML and OIDC identity authentication and federation. (IAM, Cognito, ADFS, OKTA, Auth0)
- Troubleshoot and develop sample IaC templates. (CloudFormation, Terraform, AWS CDK)
- Train and mentor junior engineers. (Give live presentations, Develop Labs, 1:1 Mentoring, Write Articles)
- Monitor and improve environments using up-to-date industry practices. ( tl;dr sec, AWS Blog, Azure Blog)
IT Support Engineer
Amazon, Inc (05/2020 - 05/2024)
- Improved efficiency of Change Management reviews by developing a JavaScript extension automating quality checks.
- Deployed, maintained, and supported server, router, switch, wireless access point life cycle for 14 regional buildings.
- Delivered dockerized full-stack camera app leveraging agile methodology integrating customer feedback
- Improved readability and functionality of internal wiki UI leveraging Bootstrap, HTML, and CSS.
- Contributed 30 knowledge articles detailing deployment and troubleshooting steps.
System Administrator
MarsLife Technologies (Home Lab) (08/2020 - Present)
- Manage CI/CD process to update website hosted in AWS using Git, Github Actions, and Terraform.
- Manage multi-node Proxmox cluster to host services and ensure high availability SDN with multi-wan failover.
- Extend on-prem services leveraging Azure Entra Connect syncing ADFS and OCI virtual machines.
Seminarian
Diocese of Green Bay (08/2016 - 01/2020)
- Studied and Applied Logic, Philosophy, Philosophy, Organizational Leadership, and Public Speaking, with a particular emphasis on community outreach and engagement. Responsible for researching and presenting papers, leading small groups, organizing and giving speaking tour to 1000+ students at eight locations.