Professional Experience · Web3 & Cloud Infrastructure

5 Years Engineering Cloud & Platform at Aave Labs

Nearly five years of platform engineering at Aave Labs — powering the Aave lending protocol and production app, Lens Protocol's social graph, and Push.co's regulated crypto exchange.

5+Years at Aave Labs
40+Global clusters managed
SOC 2Certification achieved

Projects & Products

Three product areas across nearly five years of platform engineering at Aave Labs.

Social Graph · Onchain Infrastructure

Lens Protocol

Provisioned and operated cloud infrastructure supporting Lens Protocol's decentralized social graph — scalable backends, node operations, and production-grade deployment pipelines.

Web3GCPKubernetesSocial Protocol
Visit project

Crypto Exchange · Fiat On/Off-Ramp

Push.co

Engineered cloud and platform infrastructure for Push by Aave Labs — an FCA-registered crypto exchange enabling zero-fee, non-custodial conversion between euros and stablecoins, with regulated on- and off-ramping between bank accounts and wallets.

FintechFCAStablecoinsOn/Off-RampAWS
Visit project

DeFi · Protocol & Application Platform

Aave

Multi-region cloud platform for Aave's lending protocol (v3 through v4) and the production app at app.aave.com — infrastructure, databases, networking, and GitOps at scale.

DeFiMulti-regionTerraformGitOpsEKS
Visit project

Core Contributions

Cross-cutting platform engineering work that powered the entire Aave ecosystem.

Multi-Region Cloud Architecture

5+ years engineering production infrastructure on GCP and AWS across isolated staging and production environments.

  • 36+ reusable Terraform modules managed with Terragrunt
  • 8 GCP/AWS projects across 20+ isolated environments
  • 40+ global Kubernetes clusters across multiple regions
  • Multi-region networking with VPC peering and Global Accelerator

Corporate Security & IAM Overhaul

Overhauled cloud security and IAM architecture with strict blast-radius isolation across AWS and GCP.

  • Restructured AWS into multi-account topology per environment
  • Redesigned GCP Organization with Workspace groups for centralized RBAC
  • Led technical initiatives to achieve SOC 2 certification (12–16 months)
  • Zero-trust access with Twingate and secrets management best practices

CI/CD & GitOps Automation

Built automated deployment pipelines for continuous, reliable delivery across all environments.

  • GitHub Actions for CI pipelines and automated testing
  • ArgoCD for GitOps-driven continuous deployment
  • Helm-based Kubernetes package management
  • Karpenter for dynamic cluster autoscaling

Blockchain Infrastructure (Web3)

Provisioned, secured, and maintained blockchain node infrastructure across multiple networks — including multiple Aptos validators on GCP.

  • Operated several Aptos validators on GCP — provisioning, securing, and maintaining production validator infrastructure
  • Archive and full nodes across additional blockchain networks
  • IPFS node operations and maintenance
  • High-availability node monitoring with Datadog and Groundcover
  • Secure key management for validator operations

24/7 On-Call & Incident Response

Production ownership with round-the-clock availability and systematic incident management.

  • 24/7 on-call rotation for production-critical systems
  • Root cause analysis (RCA) and preventive measure implementation
  • Incident response for multi-region cloud and Web3 infrastructure
  • Runbook development and operational knowledge sharing

Technical Stack

Technologies and platforms used across Aave Labs infrastructure engineering.

Cloud Platforms

AWSGCPCloudflareCloudflare Workers

Infrastructure as Code

TerraformOpenTofuTerragruntAnsibleHelm

CI/CD & Orchestration

KubernetesKarpenterDockerGitHub ActionsArgoCD

Security & Observability

SOC 2IAMKMSACMTwingateDatadogGrafana

Databases & Messaging

PostgreSQLAurora Serverless v2AlloyDBRedisValkeyRabbitMQDynamoDB

AWS & GCP Services

EKSGKEAptosCloudRunS3CloudFrontRoute53BigQuerySNSDMSAmazon MQ
or