AWS platforms that hold up under audit

I'm Mohammad Abu Mattar, an AWS-certified DevOps engineer. Multi-account AWS for fintech: 15+ accounts, 20+ production microservices, 96% security posture.

8+Years experience
7Roles
11Projects shipped
45Certs & badges
banner
About Me

About Me

I look after 15+ AWS accounts and 20+ production microservices for fintech, under PCI-DSS. Day to day that means Terraform, GitOps with ArgoCD, and the compliance work most people would rather skip: IAM boundaries, evidence that survives an audit, controls that hold when someone is in a hurry. Production security posture currently sits at 96%.

Work Experience

Cloud & DevOps Manager

Motory · Full-timeMar 2026 - PresentAl Hamra, Jeddah · Amman, Jordan

I run the cloud strategy and platform engineering for Motory, a large automotive marketplace. I manage a multi-cloud environment across AWS, Huawei Cloud, and Hetzner, staying about 70% hands-on with the architecture and code. I lead a DevOps team responsible for the reliability, scalability, and security of our production microservices serving 1M+ active users. I also drive our CI/CD practices, cost optimization efforts, and compliance initiatives in a high-availability, multi-region setup.

Contributions & Responsibilities

  • Infrastructure as Code: Moved everything from manual console clicks to 100% Terraform. I set up GitOps using ArgoCD and Helm to keep our deployments consistent and auditable.
  • Modernization: Led the shift from a monolith to microservices for 1M+ users. I wrote a multi-runtime Helm chart that standardized how we handle scaling, probes, and networking across all services.
  • Custom Tooling: Built a custom Kubernetes operator in Go to solve a specific provisioning problem that standard controllers couldn't handle. It plugs into the existing Helm and ArgoCD delivery flow, so the resources it manages deploy the same way everything else does.

Assistant Manager DevOps Engineer

Jordan Ahli Bank · Full-timeOct 2024 - Feb 2026Amman, Jordan

I was platform owner for the bank's AWS estate. Regulated banking means every change needs an audit trail and a rollback that works, so most of the job was making the correct path the easy one and then proving it to auditors.

Contributions & Responsibilities

  • Platform ownership: Ran 15+ AWS accounts and 20+ production microservices, against the availability and disaster-recovery targets a bank actually gets held to.
  • Terraform & GitOps: Standardized deployments on Terraform, with ArgoCD and Atlantis so changes landed through review instead of the console. Handled autoscaling and right-sizing for production workloads.
  • Security posture: Got to 96% across every account using IAM Identity Center, AWS Organizations, and PCI-DSS controls backed by CloudTrail, AWS Config, and Security Hub.

DevOps Engineer

cirrusgo (AWS Partner) · Full-timeMar 2023 - Sep 2024Amman, Jordan

cirrusgo is an AWS partner working with businesses across the MENA region.

I was the engineer on hybrid AWS builds for 8+ enterprise clients, several of them fintech. Most of them arrived with an on-premises estate they were not going to abandon, so the work was making AWS and their existing racks behave like one platform without upsetting whichever regulator they answered to.

Contributions & Responsibilities

  • Solution architecture: Designed the end-to-end builds (microservices, event-driven, serverless) and brought cloud costs down 25-40% through right-sizing, reserved instances, and switching off what nobody was using.
  • IaC foundations: Set up the Terraform and Terragrunt layer and the multi-account, multi-environment structure on AWS Organizations, then wrote the documentation that went with it.
  • Container platforms: Ran containerized workloads on ECS, Fargate, and EKS across dev, UAT, and prod, deployed through GitOps with hardened images.

Education & Certifications

AWS Certified Developer – Associate

Amazon Web Services (AWS)Issued Feb 2024 · Expires Feb 2027

Covers developing, deploying, and debugging applications on AWS, plus core AWS services and the application lifecycle.

AWS Certified Cloud Practitioner

Amazon Web Services (AWS)Issued Oct 2023 · Expires Feb 2027

Foundational AWS knowledge: core services, pricing, security, and architecture.

AWS Academy Graduate - AWS Academy Cloud Foundations

Amazon Web Services (AWS)Issued Nov 2022

Intro-level AWS coursework covering compute, networking, databases, and storage.

Projects & Tools

Open-source work I maintain outside the day job: hardened container images, Helm charts, and developer tooling. Built because I needed them, published because someone else might.

QuenchWorks, 0-CVE Hardened Images & Helm Charts

A from-scratch, security-first replacement for the Bitnami catalog: container images and Helm charts built entirely from source on Wolfi, hardened under a strict 0-CVE build gate, cryptographically signed, and pinned by digest. Free, independent, and fully self-hostable.

apkomelangeWolfiHelm+6

sysdesign, System Design Knowledge for AI Agents

A Claude Code plugin that wires tradeoff-first system design knowledge into your AI agent: one skill, eleven commands, and fourteen self-contained reference files. Explain a concept, compare options, pressure-test an architecture, estimate capacity, or prep an interview, with every tradeoff stated, not hand-waved. Original prose, MIT-licensed, works fully offline.

Claude CodeMarkdownPythonMermaid

Mathematics - Formula Reference

A clean, searchable web reference for mathematical formulas across algebra, geometry, trigonometry, and calculus. It cuts the clutter most references bury you in, rendering formulas with server-side KaTeX on focused topic pages with no accounts, tracking, or ads.

AstroJSTypeScriptTailwind CSSReact+2

What I actually work with

These are the tools I reach for most weeks, not a list of everything I have opened once. Heaviest on AWS, Terraform and Kubernetes, because that is what running a regulated platform asks for.

Cloud & Infrastructure

AWS is the daily driver: EC2, EKS, ECS and Fargate, S3, RDS, IAM, VPC, Organizations, IAM Identity Center, Lambda, CloudFormation, CloudWatch. I use Well-Architected mostly for its security and cost pillars. Azure and OCI I can find my way around, and not much more than that.

Containers & Orchestration

ECS, Fargate and EKS in production, Docker everywhere, ArgoCD for GitOps. Most of the real work here is unglamorous: right-sizing requests and limits, keeping images small, and getting the same manifests to behave in dev, UAT and prod.

CI/CD & Automation

GitHub Actions, AWS CodePipeline and CodeBuild, Jenkins, GitLab CI. I wire up blue-green and canary rollouts, put tests and scanning in front of every promotion from dev to UAT to prod, and write the glue in whichever of Python, Bash, PowerShell or TypeScript the team already reads.

Security & DevSecOps

I map infrastructure to PCI-DSS, CIS Benchmark and NIST, then automate the evidence so nobody is screenshotting consoles the week before an audit. Trivy in the pipeline, Vault and Secrets Manager for secrets, least-privilege IAM, CloudTrail, AWS Config and Security Hub. Production sits at 96% posture.

Monitoring & Observability

Prometheus, Grafana, CloudWatch and the ELK stack. Dashboards people actually open, logs centralised enough to be searchable mid-incident, and alerts tuned so a page means something is wrong.

Databases & Development

PostgreSQL, MySQL, MongoDB, DynamoDB and S3 sitting behind the microservices, mostly access patterns and tuning. On the application side I have shipped Spring Boot, Node.js and React in fintech.

273 things I wrote down so I would stop re-learning them

Notes from running AWS platforms in regulated fintech. Mostly the commands I kept forgetting and the concepts I kept having to work out again from scratch. Some of it is here because a colleague asked and I did not have a good answer ready.

What I can help with

Multi-account AWS, CI/CD pipelines, and infrastructure as code, built for teams that answer to an auditor

01Cloud & DevOps Consulting

Cloud & DevOps Consulting

I set up and run multi-account AWS for fintech and other regulated shops. Usually that starts with Organizations and IAM Identity Center, then hybrid connectivity, then the bill. Cost work has come out between 25% and 40% without loosening any controls.

  • Multi-account setups on AWS Organizations and IAM Identity Center
  • Terraform and CloudFormation for everything that would otherwise be a console click
  • PCI-DSS controls with the evidence automated, currently at 96% posture
  • Kubernetes and Docker in production, right-sized rather than over-provisioned
  • Cost work that has come out 25% to 40% cheaper
02Custom CI/CD Pipelines

Custom CI/CD Pipelines

I build release pipelines for places where a bad deploy is an audit finding and not just an outage. Tests and image scanning run in the pipeline, releases go out blue-green or canary, and the rollback is something a tired on-call engineer can actually run.

  • GitOps with ArgoCD, so the repo is the source of truth
  • Blue-green and canary releases with a rollback that actually works
  • Built on AWS CodePipeline, GitHub Actions, or Jenkins, whichever you already run
  • Tests and image scanning in front of every promotion
  • Promotion from dev to UAT to prod without manual copying
03Infrastructure as Code (IaC)

Infrastructure as Code (IaC)

I write the Terraform and Terragrunt layer other people build on: reusable modules, a documented layout for accounts and environments, and the small automation libraries that stop five teams solving the same problem five different ways.

  • Terraform and Terragrunt, with Atlantis so changes land through review
  • An account and environment layout that is written down
  • Reusable modules, plus Python and JavaScript helpers for the awkward parts
  • Provisioning and autoscaling handled without a ticket
  • PCI-DSS and CIS Benchmark checks that run on their own
cta-image

Need a hand with any of this?

Multi-account AWS, CI/CD, PCI-DSS prep, a bill that grew when nobody was looking: if it is on the list above, I have dealt with it in production. Tell me what is broken or too expensive and I will give you a straight answer on whether I can help.

Let's talk